Adware

Adware.Hotbar.8 information

Malware Removal

The Adware.Hotbar.8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Hotbar.8 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Enumerates physical drives
  • Attempted to write directly to a physical drive
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Adware.Hotbar.8?


File Info:

name: D35199E29959C323B0CA.mlw
path: /opt/CAPEv2/storage/binaries/6f56ee4c547cf9d33452e73da425a76d86706f46a4a62f08a713f9f7a0406b40
crc32: 56CEDEFE
md5: d35199e29959c323b0cafc82227ca70b
sha1: f369a94a9b6e9057ac15ecf2038d14a9ce483e60
sha256: 6f56ee4c547cf9d33452e73da425a76d86706f46a4a62f08a713f9f7a0406b40
sha512: f7e4b40e3a7fb97df3e4db9817658b905802dbd6c683ea424561f77001d4a7f7c1e6f5bf720b720d8b6d37a697eb99cdb84939b88c75098e77f4c5768cb0c1e8
ssdeep: 12288:QhXFjJpL0EgYSP7hu5kC6Kj1qnbOUOA17X3h:eqiSP70xknSUOA17Hh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CEC47C42AEE6C1F5C24510778DDAD71A75E29E79173028C3BBE41E6DA9309E3F93D208
sha3_384: a0ac09c20f83c0a7ed9593a9a8f7d3277524226fb25cbaf3fbec6b3bc023ee9b9bee4811aa5035b2a20404f9fda4bf36
ep_bytes: e823ae0000e978feffff8bff558bec56
timestamp: 2011-07-21 01:04:37

Version Info:

FileDescription: Installer
FileVersion: 2.0.360.0
ProductVersion: 2.0.360.0
Translation: 0x0409 0x30ed

Adware.Hotbar.8 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.ScreenSaver.lpNE
MicroWorld-eScanGen:Variant.Adware.Hotbar.8
ClamAVWin.Trojan.Adinstall-2
FireEyeGeneric.mg.d35199e29959c323
CAT-QuickHealAdware.HotBar
SkyhighBehavesLike.Win32.AdwareHotBar.hh
ALYacGen:Variant.Adware.Hotbar.8
Cylanceunsafe
ZillyaAdware.ScreenSaver.Win32.126
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaAdWare:Win32/ScreenSaver.2a2a42b9
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.a9b6e9
BaiduWin32.Trojan.HotBar.a
VirITAdware.Win32.Hotbar.VV
SymantecAdware.Clkpotato!gen3
ESET-NOD32a variant of Win32/Adware.HotBar.K
APEXMalicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:AdWare.Win32.ScreenSaver.i
BitDefenderGen:Variant.Adware.Hotbar.8
NANO-AntivirusTrojan.Win32.Hotbar.dvxvlv
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10b0b125
TACHYONTrojan-Clicker/W32.HotBar.552120.B
SophosHotbar (PUA)
F-SecureTrojan.TR/Patched.Gen
DrWebAdware.Hotbar.1010
VIPREGen:Variant.Adware.Hotbar.8
TrendMicroTROJ_AGENT_008427.TOMB
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Adware.Hotbar.8 (B)
IkarusTrojan.SuspectCRC
GDataGen:Variant.Adware.Hotbar.8
JiangminTrojan/JboxGeneric.lo
WebrootW32.Adware.Hotbar
GoogleDetected
AviraTR/Patched.Gen
Antiy-AVLGrayWare[AdWare]/Win32.ScreenSaver
Kingsoftmalware.kb.a.1000
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Adware.Hotbar.8
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmnot-a-virus:AdWare.Win32.ScreenSaver.i
MicrosoftAdware:Win32/Hotbar
VaristW32/HotBar.L.gen!Eldorado
AhnLab-V3Adware/Win.Hotbar.R514849
McAfeeAdware-HotBar.j
MAXmalware (ai score=99)
VBA32BScope.Adware.ScreenSaver
MalwarebytesHotBar.Adware.BrowserHijacker.DDS
TrendMicro-HouseCallTROJ_AGENT_008427.TOMB
RisingAdware.Hotbar!1.6AAD (CLASSIC)
YandexTrojan.GenAsa!HCeanZmiKos
SentinelOneStatic AI – Malicious PE
MaxSecurePoly.Adware.ScreenSaver
FortinetRiskware/Zango
AVGWin32:Adware-gen [Adw]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Adware.Hotbar.8?

Adware.Hotbar.8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment