Malware

AdWare.Win32.HofoSoft removal

Malware Removal

The AdWare.Win32.HofoSoft is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What AdWare.Win32.HofoSoft virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
qq283492708.f3322.net
api.hofosoft.com
hofosoft.cn
3600hk.no-ip.org

How to determine AdWare.Win32.HofoSoft?


File Info:

crc32: 7CD34DB9
md5: 017638e1d39be6ccc485764ba787a8cf
name: cmt.exe
sha1: cb5ac26328b3da651e042d6c0e829ad3d64b979d
sha256: 7d81322d86b6aa62b617b6b023e2504cf31d08a3b31c8b4ad77691bd54061c07
sha512: 7a951c6faa1dbbb2c4f1d663466ea0f8a72e78ceaca40f4aa99fb982649c22c77e79a713af719956c00f6a724d9d422f14617b64b6233cf5ae8330509a90ee41
ssdeep: 196608:7QSdcYboyz4qd3jtL2pmsIoflz+PtSjv4cPI3qBO3SpbwDRLdNjU6wR:7QSKHyz403JLmdl8SfAd3Sbw1RhU6y
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2012
InternalName: adbrowser
FileVersion: 1, 0, 0, 9
CompanyName: Net.Soft Studio
PrivateBuild: 20120830.01
LegalTrademarks:
Comments:
ProductName: adbrowser
SpecialBuild:
ProductVersion: 1, 0, 0, 9
FileDescription: P2Px7ec8x7ed3x8005x8f85x52a9x6a21x5757
OriginalFilename: adbrowser.EXE
Translation: 0x0804 0x04b0

AdWare.Win32.HofoSoft also known as:

BkavW32.AIDetectVM.malware5
MicroWorld-eScanGen:Trojan.Malware.@l3@aaMFFoeb
CAT-QuickHealTrojan.Agent.20341
ALYacGen:Trojan.Malware.@l3@aaMFFoeb
CylanceUnsafe
ZillyaTrojan.Black.Win32.47197
AegisLabTrojan.Win32.Agent.lJwa
SangforMalware
K7AntiVirusTrojan ( 0040f7ad1 )
BitDefenderGen:Trojan.Malware.@l3@aaMFFoeb
K7GWTrojan ( 0040f7ad1 )
Cybereasonmalicious.1d39be
ArcabitTrojan.Malware.E8ABDA
TrendMicroTROJ_GEN.R002C0DGI20
BaiduWin32.Trojan.Farfli.bg
CyrenW32/S-6ad53990!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.CMX
APEXMalicious
AvastWin32:GenMalicious-JHS [Trj]
ClamAVWin.Trojan.Zegost-7007928-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.HofoSoft.gen
AlibabaBackdoor:Win32/Zegost.a2be3fbf
NANO-AntivirusTrojan.Win32.Agent.elhpas
RisingBackdoor.Farfli!1.B6C5 (CLOUD)
Ad-AwareGen:Trojan.Malware.@l3@aaMFFoeb
EmsisoftGen:Trojan.Malware.@l3@aaMFFoeb (B)
ComodoTrojWare.Win32.Kryptik.BPVQ@56xtf6
F-SecureBackdoor.BDS/Zegost.Gen
DrWebTrojan.DownLoader22.4913
FortinetW32/Farfli.DZ!tr
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.017638e1d39be6cc
SophosMal/Generic-S
IkarusBackdoor.Win32.Zegost
F-ProtW32/S-6ad53990!Eldorado
JiangminTrojan.Generic.aeyth
WebrootW32.Trojan.Gen
AviraBDS/Zegost.Gen
eGambitUnsafe.AI_Score_96%
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.AGeneric
Endgamemalicious (high confidence)
MicrosoftBackdoor:Win32/Zegost.AD
ZoneAlarmHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.R97658
Acronissuspicious
McAfeeGenericRXDF-LU!017638E1D39B
VBA32BScope.Backdoor.Spy
MalwarebytesBackdoor.Farfli
PandaTrj/Genetic.gen
ZonerTrojan.Win32.52717
TrendMicro-HouseCallTROJ_GEN.R002C0DGI20
TencentMalware.Win32.Gencirc.10b753c9
YandexTrojan.Agent!qzuHQUHYfdI
SentinelOneDFI – Suspicious PE
GDataGen:Trojan.Malware.@l3@aaMFFoeb
BitDefenderThetaGen:NN.ZexaF.34136.@l3@aaMFFoeb
AVGWin32:GenMalicious-JHS [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Virus.Adware.6e5

How to remove AdWare.Win32.HofoSoft?

AdWare.Win32.HofoSoft removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment