Adware

Win32/Adware.HotBar.U removal guide

Malware Removal

The Win32/Adware.HotBar.U is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Adware.HotBar.U virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Adware.HotBar.U?


File Info:

name: 8DA7EF3AAA70A76AD1C4.mlw
path: /opt/CAPEv2/storage/binaries/ffed765c58819844dbbb00a3c2849c98bbf66c285de7ae8bced14001aaa309c7
crc32: 4EECA271
md5: 8da7ef3aaa70a76ad1c4b69ff69fca00
sha1: d4df851260a56625d993ba901c90a416da268c41
sha256: ffed765c58819844dbbb00a3c2849c98bbf66c285de7ae8bced14001aaa309c7
sha512: 050de23c1c99bd9fdb8274eeb854aaa22b853d8eb211281855d40e9875ad5dd19ec5421676e6564933f783eb46ec395b8e8db3dd1cbaf2ad72fa61695560ad7d
ssdeep: 12288:nwECaUglPnFsk7P0UahDyDT1dBRXjIjpQu4SsMxE:nwEC70qkgUahDuTRpu4DMx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153F47D2237E4E032E2724B346F6BC2A55676BC719870894FB7D43F3D1F706829A25B16
sha3_384: 0233a50af07f099f678fff3e71b2c23d23be9137448ddbc132544626d9ed84828bcc94b6435402d16f7424043d0f7c51
ep_bytes: e8e1850000e989feffff8bff558bec51
timestamp: 2013-02-22 20:26:08

Version Info:

0: [No Data]

Win32/Adware.HotBar.U also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.ScreenSaver.2!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.GenericKDZ.95963
ClamAVWin.Adware.Hotbar-9754440-0
FireEyeGeneric.mg.8da7ef3aaa70a76a
CAT-QuickHealPua.Generic.22410
SkyhighBehavesLike.Win32.Generic.bh
McAfeePUP-XFM-OY
Cylanceunsafe
ZillyaAdware.ScreenSaver.Win32.2189
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaAdWare:Win32/HotBar.5d17f793
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.260a56
VirITTrojan.Win32.Click2.DGON
SymantecPUA.Gen
tehtrisGeneric.Malware
ESET-NOD32Win32/Adware.HotBar.U
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:not-a-virus:AdWare.Win32.ScreenSaver.gen
BitDefenderTrojan.GenericKDZ.95963
NANO-AntivirusTrojan.Win32.Graftor.ccynms
AvastWin32:Downloader-SZW [PUP]
TencentTrojan.Win32.Downloader.abn
EmsisoftTrojan.GenericKDZ.95963 (B)
BaiduWin32.Adware.Agent.b
F-SecureAdware.ADWARE/Hotbar.aoi
DrWebTrojan.Click2.57161
VIPRETrojan.GenericKDZ.95963
TrendMicroPossible_HOTBAR.UNP
Trapminemalicious.moderate.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.SuspectCRC
GDataTrojan.GenericKDZ.95963
JiangminAdWare/ScreenSaver.qi
WebrootW32.Adware.Gen
VaristW32/ClickPotato.A.gen!Eldorado
AviraADWARE/Hotbar.aoi
Antiy-AVLGrayWare[AdWare]/Win32.GOffer
Kingsoftmalware.kb.b.975
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Generic.D176DB
ZoneAlarmHEUR:not-a-virus:AdWare.Win32.ScreenSaver.gen
MicrosoftProgram:Win32/Ymacco.AAFF
GoogleDetected
ALYacTrojan.GenericKDZ.95963
MAXmalware (ai score=60)
VBA32AdWare.ScreenSaver
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallPossible_HOTBAR.UNP
RisingAdware.Hotbar!1.6AAD (CLASSIC)
YandexPUA.GOffer!0F8NK/awzxc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4407260.susgen
FortinetAdware/Hotbar
AVGWin32:Downloader-SZW [PUP]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Win32/Adware.HotBar.U?

Win32/Adware.HotBar.U removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment