Threat Database Adware Adware-OneStep.b

Adware-OneStep.b

By SpideyMan in Adware

Threat Scorecard

Threat Level: 20 % (Normal)
Infected Computers: 7
First Seen: June 28, 2021
Last Seen: October 24, 2025
OS(es) Affected: Windows

Adware-OneStep.b is an unwanted adware application that integrates itself as a browser helper object. It can redirect search page and displays excessive advertisements on infected computer. Once Adware-OneStep.b has embedded itself within a computer system, it will bombard the desktop with hundreds of pop-up messages, advertising various products.

Adware-OneStep.b tends to be downloaded and installed together with other malware programs. Adware-OneStep.b is a form of an adware application, which was created with the sole purpose of displaying pop-up advertisements based on searches the user performs on popular web search engines, such as google.com, yahoo.com, search.msn.com, search.lycos.com, search.aol.com, etc. Adware-OneStep.b will monitor what a system user will search for, and continues to display web pages from partner websites, once the user enters certain keyword triggers.

Adware-OneStep.b may come bundled with third party malware applications, and is highly capable of downloading and installing additional adware. To be able to manually remove Adware-OneStep.b, one should bear in mind that it is quite a difficult process and it is not recommend, unless the user is an expert in this field. Therefore, the best defence is to download and install a reliable anti-spyware program to scan for Adware-OneStep.b and other spyware on a machine. Online threats are constantly changing and adapting to avoid detection, therefore one should definitely consult an expert should Adware-OneStep.b be detected on a system.

File System Details

Adware-OneStep.b may create the following file(s):
# File Name Detections
1. %Windir%\Temp\ZIN5.tmp
2. %Windir%\Temp\nsxA.tmp
3. %Windir%\Temp\nsw8.tmp

Registry Details

Adware-OneStep.b may create the following registry entry or registry entries:
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]

Analysis Report

General information

Family Name: Adware.OneStep.B
Signature status: No Signature

Known Samples

MD5: c74803e7496951d6a6f4adcbf1d09aee
SHA1: 431ebc4919c24618ce5e118ccd8e732cdab0e733
SHA256: C559B94115B2E3485A7A0A7C5A0D137263F8B79FC4E123757025A98210D9729A
File Size: 569.34 KB, 569344 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 200
Potentially Malicious Blocks: 30
Whitelisted Blocks: 169
Unknown Blocks: 1

Visual Map

x x x x 0 0 0 x x 0 x 0 x x x x x x ? x 0 x x x x x x x x x x x x x x x x 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 2 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\431ebc4919c24618ce5e118ccd8e732cdab0e733_0000569344.,LiQMAxHB

Trending

Most Viewed

Loading...