Home Malware Programs Adware Hicosmea

Hicosmea

Posted: May 25, 2015

Threat Metric

Ranking: 16,535
Threat Level: 2/10
Infected PCs: 16,816
First Seen: May 25, 2015
Last Seen: January 16, 2025
OS(es) Affected: Windows


The Hicosmea software from Nuvision Global Limited may travel with fake updates to Google Chrome and Mozilla Firefox and may contain programs like Backupdutylite and BatBrowse. Security experts classify the Hicosmea software as an adware that is coded for the sole purpose of earning affiliate revenue for its creators. The Hicosmea adware may use executable DLLs to modify the way your browser works and make sure that the infected user will see only ads by its partners. The Hicosmea adware may block the safe ads on e-commerce portals like eBay and Amazon, and you could be redirected to untrusted alternatives. Additionally, the Hicosmea adware may invite you to install rogue security apps like File Integrity Checker and Green AV by claiming they are safe and will improve your security. Security experts remind users not to trust the ads by Hicosmea. The Hicosmea adware may use banners, pop-up windows, discounts, and coupons to attract your attention and earn revenue. The Hicosmea adware will not appear on your 'Programs and Features' module of the 'Control Panel' and may append the 'Hidden' feature to its executable. The Hicosmea adware may slow down your browser and insert sponsored search results to Yahoo, Google, and Bing that may link to compromised websites. In many cases, adware such as Hicosmea may direct users to input their login information onto phishing pages to earn additional revenue, and its activities may expose you to online identity theft. Needless to say, you might want to eradicate the Hicosmea adware by using a trustworthy anti-malware application that can boost your defenses against future infection.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Local\uninstallce.exe File name: uninstallce.exe
Size: 3.07 KB (3072 bytes)
MD5: 12da1f6bf5ca85e6ea7b67826a2ad0f2
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\uninstallce.exe
Group: Malware file
Last Updated: October 6, 2021
%TEMP%\4794c7bf-fe42-40aa-a623-8b795d1bb93c\bundle_nuvisiondataremarketer.exe File name: bundle_nuvisiondataremarketer.exe
Size: 118.64 KB (118649 bytes)
MD5: efe7cbfca9074a83f5b51ec386bba0a3
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\4794c7bf-fe42-40aa-a623-8b795d1bb93c
Group: Malware file
Last Updated: February 13, 2016
C:\Users\<username>\Desktop\Datos\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8NFXZ4D\Bundle_NuvisionDataRemarketer[1].exe File name: Bundle_NuvisionDataRemarketer[1].exe
Size: 103.8 KB (103803 bytes)
MD5: 8bb90bd847354bff43a399e10bf446ab
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Datos\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8NFXZ4D\Bundle_NuvisionDataRemarketer[1].exe
Group: Malware file
Last Updated: March 24, 2024

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%LOCALAPPDATA%\ufRouteMatrix.exe%LOCALAPPDATA%\uninstallBR.exe%LOCALAPPDATA%\uninstallce.exe%LOCALAPPDATA%\uninstallro.exe%LOCALAPPDATA%\uninstallssl.exe%USERPROFILE%\Local Settings\Application Data\uninstallce.exeHKEY..\..\..\..{RegistryKeys}Software\molecnySoftware\{57a15861-1d40-4f56-1796-2c97c4765352}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ASUSNet20BandwidthMinimizerCDNetStreamer2.r05CloudExtenderDragonBoostFoloDriteHTTPBalancer_v2.15ImageCreator_v4.2NeonRhythmboxNetStream 1.0QOSUser2.r10REOptimizerRouteMatrixSSDOptimizerV13SSLOptimizerStreamCoder1.0StreamOptimizer{46d699b3-6a25-4071-6078-4e96aeed2e07}{5d2072a8-011e-4602-e6e3-925eeda9b86a}{7806f5a2-b248-4896-cf82-75e4cb6480df}{a329d60a-cb9f-440b-f789-14aa80a9d985}{c8730ca5-3f82-41cc-65e2-01b87600cd89}

Additional Information

The following directories were created:
%APPDATA%\agederar%APPDATA%\commar%APPDATA%\comter%APPDATA%\encemuis%APPDATA%\inminet%APPDATA%\itesing%APPDATA%\lytinsub%APPDATA%\magtu%APPDATA%\moters%APPDATA%\pendis%APPDATA%\proical%APPDATA%\sursenel%APPDATA%\tlerauic%APPDATA%\tricomfi%APPDATA%\wardmain%appdata%\denaf
Loading...