Hotbar is an adware dropper which drops adware component on the system and generates extra pop-up ads while browsing Internet. This installs itself as a tool bar and it will develop into a vector to download many malware that will do activate the routines in background. While browsing it downloads different viruses when used to search using its search bar.
Locating Hotbar on System:
Classes root folder is where it affects, anything that starts with Hb file is a result of Hotbar Adware.
Locating Hotbar on System:
- It installs its components in program files folder with name Hbtools, shopper reports, Hb tools. and adds dll files with same names.
- It will run processes in back ground with the names "Hotbar," "SBHost," "Toolbar" or "HostOE" these are aliases for Adware.Win.32 Hotbar in processes.
Classes root folder is where it affects, anything that starts with Hb file is a result of Hotbar Adware.
- HKEY_CLASSES_ROOT\HbtCoreSrv.LfgAx
- HKEY_CLASSES_ROOT\HbtHostIE.Bho
- HKEY_CLASSES_ROOT\HbtHostIE.Bho.1
- HKEY_CLASSES_ROOT\HbtHostOL.HbtMailAnim
- HKEY_CLASSES_ROOT\HbtHostOL.HbtMailAnim.1
- HKEY_CLASSES_ROOT\HbtHostOL.HbtWebmailSend
- HKEY_CLASSES_ROOT\HbtHostOL.HbtWebmailSend.1
- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\
Explorer Bars\{2178C864-B8BC-41AE-A1FB-EB6A32F87EB1} - HKEY_CURRENT_USER\Software\ShopperReports
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\
Addins\HbtHostOL.HbtMailAnim - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\
Toolbar "{74CC49F7-EB32-4A08-B204-948962A6E3DB}" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "HbTools" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "qfrxdkbq" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "WeatherOnTray" - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{2A8A997F-BB9F-48F6-AA2B-2762D50F9289} - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects\{74CC49F7-EB32-4A08-B204-
948962A6E3DB} - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\HbToolsOutlookTools - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Uninstall\HbToolsWebTools - HKEY_CLASSES_ROOT\ShprRprts.IEButton
- HKEY_CLASSES_ROOT\ShprRprts.IEButton.1
- HKEY_CLASSES_ROOT\ShprRprts.IEButtonA
- HKEY_CLASSES_ROOT\ShprRprts.IEButtonA.1
- HKEY_CLASSES_ROOT\ShprRprts.SmrtShprCtl
- It creates entries in Interface folder, RptsPSClient, ShprRprts, Typelib.
- We need to go to Run folder in HKLM\Software\Microsoft\windows\Current Version\Run and delete the files Hotbar folder and weather on tray in which hot bar folder.
- We need to delete all the folders that starts with Hb from the registry.