Adware

Adware.Hotbar.22 (file analysis)

Malware Removal

The Adware.Hotbar.22 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hotbar.22 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Adware.Hotbar.22?


File Info:

name: 795B43AFAA798F82D39D.mlw
path: /opt/CAPEv2/storage/binaries/b8487fbc74c035a498c471033a09a190b29d9f57927492f55913702fa1cc853a
crc32: 7B74A431
md5: 795b43afaa798f82d39d3bf257414dca
sha1: 8a5e13b702e645f97df09d8561dd7f9a43783295
sha256: b8487fbc74c035a498c471033a09a190b29d9f57927492f55913702fa1cc853a
sha512: d0bbcd1aff7d65f21d6e33591a992a126c8f88c4eb7feaa16c6c40c22f1ecea529519f190a14f0d0fdd052bfbc79f4a76765d4231808966abb2268edc5fcb9bf
ssdeep: 6144:TOSVsm4SPLC5D8D+EpAHT5tFwTDF5bJ8X7PqjNXl7aBDh7PX:TOSVsu+N8D+yDF5b6LPqVlml
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BB48D213BD6E076E17315B1DFC6DBB6A8EAF9315821050BBBD007690E39D82DE31B19
sha3_384: 8f5eb77702586dead889cab7ca3def328ff10f0d1802e973c5a32bf56b88a0a130c5c76f8bbe899f1cf5b7d983d81e27
ep_bytes: e844a70000e978feffff8bff558bec8d
timestamp: 2011-04-07 04:18:28

Version Info:

FileDescription: Installer
FileVersion: 2.0.269.0
ProductVersion: 2.0.269.0
Translation: 0x0409 0x30ed

Adware.Hotbar.22 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Adware.Hotbar.22
ClamAVWin.Trojan.Adinstall-2
SkyhighBehavesLike.Win32.AdwareHotBar.gh
McAfeeAdware-HotBar.j
MalwarebytesHotBar.Adware.BrowserHijacker.DDS
VIPREGen:Variant.Adware.Hotbar.22
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.702e64
ArcabitTrojan.Adware.Hotbar.22
BaiduWin32.Trojan.HotBar.a
VirITAdware.Win32.Zango.AOB
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Adware.HotBar.H
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:WebToolbar.Win32.Zango.aob
BitDefenderGen:Variant.Adware.Hotbar.22
NANO-AntivirusTrojan.Win32.HotBar.cstbzo
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:ClickPotato-B [PUP]
TencentMalware.Win32.Gencirc.10b39029
SophosHotbar (PUA)
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader2.29533
ZillyaAdware.HotBar.Win32.477
EmsisoftGen:Variant.Adware.Hotbar.22 (B)
IkarusTrojan.SuspectCRC
JiangminAdWare/ScreenSaver.ds
WebrootW32.Adware.Hotbar
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLRiskWare[WebToolbar]/Win32.Zango
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
MicrosoftAdware:Win32/ClickPotato
ZoneAlarmnot-a-virus:WebToolbar.Win32.Zango.aob
GDataGen:Variant.Adware.Hotbar.22
VaristW32/HotBar.L.gen!Eldorado
Acronissuspicious
ALYacGen:Variant.Adware.Hotbar.22
VBA32BScope.Adware.ScreenSaver
Cylanceunsafe
TrendMicro-HouseCallTROJ_WEBTOOLBAR_000001c.TOMA
RisingAdware.Hotbar!1.6AAD (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecurePoly.Adware.ScreenSaver
FortinetRiskware/Zango
AVGWin32:ClickPotato-B [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Adware.Hotbar.22?

Adware.Hotbar.22 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment