Adware

Adware.Hotbar.2 malicious file

Malware Removal

The Adware.Hotbar.2 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hotbar.2 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Attempted to write directly to a physical drive

How to determine Adware.Hotbar.2?


File Info:

name: A7A3D8EDD974716867AF.mlw
path: /opt/CAPEv2/storage/binaries/aa5a32d3e0e56cd1fa428ad2dc074082b7bb70ed138a2fbd99fc20c4369459e1
crc32: 235D4F1F
md5: a7a3d8edd974716867af45fb69bc4ba0
sha1: 44a562476340498c9cfc32929875384d06edef71
sha256: aa5a32d3e0e56cd1fa428ad2dc074082b7bb70ed138a2fbd99fc20c4369459e1
sha512: 498dffc2aa4ea3bbbba8fc776c5b6bba559094453bf0d0dccc7147bd8ebee16f7963222feec22cdc0d4e508d8ef58eafad139404bb243c61448b6cc3cf7c734a
ssdeep: 6144:5Lr5atHtCAIdgVPFPVsRoDr4RshX6Nwyl3HtwVTR:95atTLP12R7iewgdwVTR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18944133BCB010AD5C40175B584029DFA2D3AF443EED98AA67FD1989F3C737A2BB45909
sha3_384: e5a16c3cef0949c8d57ce2948e82c26c5cf9dc590aa4d45e0b649add90e2a003ee9c0ba31baec49b8205e15f3707b9f0
ep_bytes: 60be006045008dbe00b0faff57eb0b90
timestamp: 2012-01-06 16:27:49

Version Info:

FileDescription: Setup
FileVersion: 3.0.41.0
ProductVersion: 3.0.41.0
Translation: 0x0409 0x04b0

Adware.Hotbar.2 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.ScreenSaver.lr65
AVGWin32:Zango-AQ [PUP]
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Adware.Hotbar.2
FireEyeGeneric.mg.a7a3d8edd9747168
CAT-QuickHealPUA.Appbundler.Gen
SkyhighAdware-HotBar.d
McAfeeAdware-HotBar.d
Cylanceunsafe
ZillyaAdware.AgentCRT.Win32.48
SangforPUA.Win32.Sign.a
AlibabaAdWare:Win32/ScreenSaver.659361c2
K7GWAdware ( 004bd9291 )
K7AntiVirusAdware ( 00314f2c1 )
VirITPUP.Win32.AppBundler.A
SymantecPUA.Gen.2
ESET-NOD32a variant of Win32/Adware.HotBar.L
CynetMalicious (score: 99)
APEXMalicious
AvastWin32:Zango-AQ [PUP]
ClamAVWin.Adware.Screensaver-1
Kasperskynot-a-virus:AdWare.Win32.ScreenSaver.e
BitDefenderGen:Variant.Adware.Hotbar.2
NANO-AntivirusTrojan.Win32.cwpj.dvtojy
SUPERAntiSpywareAdware.ConvertAd/Variant
TencentMalware.Win32.Gencirc.10bdc660
EmsisoftGen:Variant.Adware.Hotbar.2 (B)
F-SecureTrojan.TR/Banach.A
DrWebAdware.Hotbar.700
TrendMicroTROJ_GEN.R002C0CBH24
Trapminemalicious.moderate.ml.score
SophosClickPotato Installer (PUA)
JiangminAdWare/ScreenSaver.jh
WebrootW32.Adware.Gen
VaristW32/HotBar.O.gen!Eldorado
AviraTR/Banach.A
MAXmalware (ai score=100)
Antiy-AVLGrayWare[AdWare]/Win32.ScreenSaver
Kingsoftmalware.kb.b.978
MicrosoftAdware:Win32/Hotbar
XcitiumApplicUnwnt.Win32.AdWare.ScreenSaver.DI@4t0hrx
ArcabitTrojan.Adware.Hotbar.2
ViRobotAdware.HotBar.266928.GN
ZoneAlarmnot-a-virus:AdWare.Win32.ScreenSaver.e
GDataGen:Variant.Adware.Hotbar.2
GoogleDetected
AhnLab-V3Adware/Win32.ScreenSaver.R19525
Acronissuspicious
VBA32BScope.Adware.ScreenSaver
ALYacGen:Variant.Adware.Hotbar.2
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0CBH24
RisingTrojan.Win32.Generic.12AFD5C7 (C64:YzY0OivEVHD/13bV)
YandexTrojan.GenAsa!ZoRco6P4FCQ
IkarusTrojan.SuspectCRC
MaxSecureAdware.AdWare.WIN32.ScreenSaver.e_214905
FortinetRiskware/HotBar
DeepInstinctMALICIOUS

How to remove Adware.Hotbar.2?

Adware.Hotbar.2 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment