Hicosmea
Posted: May 25, 2015
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
| Ranking: | 16,535 |
|---|---|
| Threat Level: | 2/10 |
| Infected PCs: | 16,816 |
| First Seen: | May 25, 2015 |
|---|---|
| Last Seen: | January 16, 2025 |
| OS(es) Affected: | Windows |
The Hicosmea software from Nuvision Global Limited may travel with fake updates to Google Chrome and Mozilla Firefox and may contain programs like Backupdutylite and BatBrowse. Security experts classify the Hicosmea software as an adware that is coded for the sole purpose of earning affiliate revenue for its creators. The Hicosmea adware may use executable DLLs to modify the way your browser works and make sure that the infected user will see only ads by its partners. The Hicosmea adware may block the safe ads on e-commerce portals like eBay and Amazon, and you could be redirected to untrusted alternatives. Additionally, the Hicosmea adware may invite you to install rogue security apps like File Integrity Checker and Green AV by claiming they are safe and will improve your security. Security experts remind users not to trust the ads by Hicosmea. The Hicosmea adware may use banners, pop-up windows, discounts, and coupons to attract your attention and earn revenue. The Hicosmea adware will not appear on your 'Programs and Features' module of the 'Control Panel' and may append the 'Hidden' feature to its executable. The Hicosmea adware may slow down your browser and insert sponsored search results to Yahoo, Google, and Bing that may link to compromised websites. In many cases, adware such as Hicosmea may direct users to input their login information onto phishing pages to earn additional revenue, and its activities may expose you to online identity theft. Needless to say, you might want to eradicate the Hicosmea adware by using a trustworthy anti-malware application that can boost your defenses against future infection.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:C:\Users\<username>\AppData\Local\uninstallce.exe
File name: uninstallce.exeSize: 3.07 KB (3072 bytes)
MD5: 12da1f6bf5ca85e6ea7b67826a2ad0f2
Detection count: 183
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\uninstallce.exe
Group: Malware file
Last Updated: October 6, 2021
%TEMP%\4794c7bf-fe42-40aa-a623-8b795d1bb93c\bundle_nuvisiondataremarketer.exe
File name: bundle_nuvisiondataremarketer.exeSize: 118.64 KB (118649 bytes)
MD5: efe7cbfca9074a83f5b51ec386bba0a3
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\4794c7bf-fe42-40aa-a623-8b795d1bb93c
Group: Malware file
Last Updated: February 13, 2016
C:\Users\<username>\Desktop\Datos\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8NFXZ4D\Bundle_NuvisionDataRemarketer[1].exe
File name: Bundle_NuvisionDataRemarketer[1].exeSize: 103.8 KB (103803 bytes)
MD5: 8bb90bd847354bff43a399e10bf446ab
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Datos\Users\<username>\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\E8NFXZ4D\Bundle_NuvisionDataRemarketer[1].exe
Group: Malware file
Last Updated: March 24, 2024
More files
Registry Modifications
Regexp file mask%LOCALAPPDATA%\ufRouteMatrix.exe%LOCALAPPDATA%\uninstallBR.exe%LOCALAPPDATA%\uninstallce.exe%LOCALAPPDATA%\uninstallro.exe%LOCALAPPDATA%\uninstallssl.exe%USERPROFILE%\Local Settings\Application Data\uninstallce.exeHKEY..\..\..\..{RegistryKeys}Software\molecnySoftware\{57a15861-1d40-4f56-1796-2c97c4765352}HKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}ASUSNet20BandwidthMinimizerCDNetStreamer2.r05CloudExtenderDragonBoostFoloDriteHTTPBalancer_v2.15ImageCreator_v4.2NeonRhythmboxNetStream 1.0QOSUser2.r10REOptimizerRouteMatrixSSDOptimizerV13SSLOptimizerStreamCoder1.0StreamOptimizer{46d699b3-6a25-4071-6078-4e96aeed2e07}{5d2072a8-011e-4602-e6e3-925eeda9b86a}{7806f5a2-b248-4896-cf82-75e4cb6480df}{a329d60a-cb9f-440b-f789-14aa80a9d985}{c8730ca5-3f82-41cc-65e2-01b87600cd89}
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.