PUA

Should I remove “Hotbar (PUA)”?

Malware Removal

The Hotbar (PUA) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Hotbar (PUA) virus can do?

  • At least one process apparently crashed during execution
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Hotbar (PUA)?


File Info:

name: E8F05F85C5BF6774C69A.mlw
path: /opt/CAPEv2/storage/binaries/22d328d22a0206265f4eb637b1a821b8c6d48dac2e3644e05150c54fd15ee444
crc32: 540DE9FA
md5: e8f05f85c5bf6774c69aabd855650ce6
sha1: b2542af29bb072618286209f6ce7b3449790e18c
sha256: 22d328d22a0206265f4eb637b1a821b8c6d48dac2e3644e05150c54fd15ee444
sha512: 6a42e73a5fc9e0b19135de9c68200aac8332709b4ce6d85cef3ad83a3dd343de8f92ecc49b223edf0c6172fd7c6595e03ac7361e7fd2a4a386a86b0fc2746a55
ssdeep: 98304:iGnlBsP2fsLgr+x4/US1irppcC8/CkKYvV:LlmPLMqx4/UQir7cC86VEV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ABE533B1FFA7C8A3C0846E30449E827AD57CDB011F36F39597B89C682042752792E69E
sha3_384: 6aed8631d5f5846f4e3608320abea708528c1aa87bab64397a4c8d9e6be950ed974809898141f6dc72030981cb70449f
ep_bytes: e89b27000050e8a72201000000000090
timestamp: 2005-10-07 09:05:22

Version Info:

0: [No Data]

Hotbar (PUA) also known as:

CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Generic.8
K7AntiVirusTrojan ( 004951d71 )
K7GWTrojan ( 004951d71 )
Cybereasonmalicious.29bb07
CyrenW32/OnlineGames.CK.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zlob-13229
AlibabaTrojan:Win32/Vapsup.74d1d280
NANO-AntivirusTrojan.Win32.Renum.cymvyd
RisingTrojan.Generic@ML.80 (RDML:9RWoxj+MjJTsts7WMRW5zQ)
TrendMicroTROJ_GEN.R002C0OKN21
McAfee-GW-EditionGeneric.gi
SophosHotbar (PUA)
AviraHEUR/AGEN.1131021
Antiy-AVLTrojan/Generic.ASMalwS.8CF067
KingsoftWin32.Troj.Renum.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
McAfeeArtemis!E8F05F85C5BF
MAXmalware (ai score=100)
VBA32TrojanDropper.Renum
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0OKN21
TencentWin32.Trojan.Dropper.Anzc
YandexTrojan.GenAsa!LMZp285fBdY
FortinetW32/Generic.CMZHVFC!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Hotbar (PUA)?

Hotbar (PUA) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment