Jump to content

Metallica

Staff
  • Content count

    2,165
  • Joined

  • Last visited

4 Followers

About Metallica

  • Rank
    Master of PUPs
  • Birthday 05/19/1963

Profile Information

  • Location
    Netherlands

Recent Profile Visitors

160,713 profile views
  1. What is goDownload Search Plus?The Malwarebytes research team has determined that goDownload Search Plus is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by goDownload Search Plus?You may see this entry in your list of installed Chrome extensions:these warnings during install:this changed setting:and you will see this icon in your Chrome menu:How did goDownload Search Plus get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was downloaded from the webstore:How do I remove goDownload Search Plus?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of goDownload Search Plus? No, Malwarebytes removes goDownload Search Plus completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the goDownload Search Plus hijacker. It would have blocked the site promoting the extension: and the search site: Technical details for expertsPossible signs in FRST logs: CHR DefaultSearchURL: Default -> hxxp://apps.searchalgo.com/search/?category=web&s=gddp&vert=download&var=plus&q={searchTerms} CHR DefaultSearchKeyword: Default -> goDownload Search Plus CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms} CHR Extension: (goDownload Search Plus) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe [2018-08-16] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0 Adds the file manifest.json"="8/16/2018 10:49 AM, 2354 bytes, A Adds the file popup.css"="8/3/2016 11:15 AM, 6449 bytes, A Adds the file popup.html"="8/3/2016 11:15 AM, 3929 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_locales\en Adds the file messages.json"="8/16/2018 10:49 AM, 12391 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_metadata Adds the file computed_hashes.json"="8/16/2018 10:49 AM, 8292 bytes, A Adds the file verified_contents.json"="5/8/2017 12:11 PM, 7808 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\icons Adds the file 38.png"="8/16/2018 10:49 AM, 2070 bytes, A Adds the file icon128.png"="8/16/2018 10:49 AM, 6524 bytes, A Adds the file icon16.png"="8/16/2018 10:49 AM, 619 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js Adds the file background.js"="5/8/2017 12:11 PM, 7294 bytes, A Adds the file jquery.min.js"="8/3/2016 11:15 AM, 93104 bytes, A Adds the file main.js"="8/3/2016 11:15 AM, 2671 bytes, A Adds the file popup.js"="8/3/2016 11:15 AM, 33991 bytes, A Adds the file search.js"="8/3/2016 11:15 AM, 513 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus Adds the file index.html"="5/8/2017 12:11 PM, 2742 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\css Adds the file style.css"="8/3/2016 11:15 AM, 3318 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img Adds the file close.png"="8/3/2016 11:15 AM, 1109 bytes, A Adds the file dislike.png"="8/3/2016 11:15 AM, 1151 bytes, A Adds the file like.png"="8/3/2016 11:15 AM, 1108 bytes, A Adds the file logo.png"="8/3/2016 11:15 AM, 5157 bytes, A Adds the file share.png"="8/3/2016 11:15 AM, 1170 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\js Adds the file jquery.min.js"="8/3/2016 11:15 AM, 85660 bytes, A Adds the file main.js"="5/8/2017 12:11 PM, 2761 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "cbieibobpefaobhfncpimjimbijplebe"="REG_SZ", "7CAE5A65CB1CA110715064DC2541765CA633EDD899C65D5D75A994C39AF5D245" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/16/18 Scan Time: 11:00 AM Log File: d9709bfd-a132-11e8-b916-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6367 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251900 Threats Detected: 75 Threats Quarantined: 75 Time Elapsed: 3 min, 37 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 18 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons download, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\notification, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\button, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_locales\en, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_metadata, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\css, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_locales, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\icons, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CBIEIBOBPEFAOBHFNCPIMJIMBIJPLEBE, Quarantined, [14297], [443230],1.0.6367 File: 57 PUP.Optional.SearchAlgo.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CBIEIBOBPEFAOBHFNCPIMJIMBIJPLEBE\1.0.3_0\MANIFEST.JSON, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\icons\38.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\icons\icon128.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\icons\icon16.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\button\btn_save.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\button\btn_save_hover.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\big_icon.jpg, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\icon128.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\icon16.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\icon_19x19.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\icon_38x38.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons\small_icon.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons download\btn.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons download\btn_hover.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons download\frame.jpg, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons download\v.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\danger.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\delete.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\folder.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\frame.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\pause.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\play.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\referrer.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\refresh.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\remove.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\safe.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons hover\stop.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs\delete.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs\filter.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs\folder.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs\search.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\icons_tabs\settings.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\notification\open_folder.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\notification\pause.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\notification\show_download.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\images\notification\show_file.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js\background.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js\jquery.min.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js\main.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js\popup.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\js\search.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\css\style.css, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img\close.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img\dislike.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img\like.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img\logo.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\img\share.png, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\js\jquery.min.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\js\main.js, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\Plus\index.html, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_locales\en\messages.json, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_metadata\computed_hashes.json, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\_metadata\verified_contents.json, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\popup.css, Quarantined, [14297], [443230],1.0.6367 PUP.Optional.SearchAlgo.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbieibobpefaobhfncpimjimbijplebe\1.0.3_0\popup.html, Quarantined, [14297], [443230],1.0.6367 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  2. What is PureLeisureFun?The Malwarebytes research team has determined that PureLeisureFun is a potentially unwanted program that behaves like adware. These adware applications display advertisements not originating from the sites you are browsing.How do I know if my computer is affected by PureLeisureFun?You may see these warnings during install:and these browser extensions/add-ons:How did PureLeisureFun get on my computer?Adware applications use different methods for distributing themselves. This particular one was downloaded through their website:but the Chrome extension was also available in the webstore:How do I remove PureLeisureFun?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of PureLeisureFun? No, Malwarebytes removes PureLeisureFun completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this adware.The full version of Malwarebytes would have protected you against the PureLeisureFun adware by blocking their domain. Technical details for expertsPossible signs in FRST logs: FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\{df4e0189-a17d-41aa-af86-b6de65952842}.xpi [2018-08-15] CHR Extension: (PureLeisureFun) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac [2018-08-15] Significant changes made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0 Adds the file adentify.js"="8/9/2018 11:00 AM, 161397 bytes, A Adds the file background.html"="8/9/2018 10:59 AM, 178 bytes, A Adds the file background.js"="8/9/2018 10:59 AM, 113305 bytes, A Adds the file content.js"="8/9/2018 10:59 AM, 46078 bytes, A Adds the file inimgContent.js"="8/9/2018 10:59 AM, 96371 bytes, A Adds the file install.js"="8/9/2018 10:59 AM, 365 bytes, A Adds the file intextContent.js"="8/9/2018 10:59 AM, 110264 bytes, A Adds the file intextstyle.css"="8/9/2018 10:59 AM, 1613 bytes, A Adds the file manifest.json"="8/15/2018 9:11 AM, 1798 bytes, A Adds the file overlay_style.css"="8/9/2018 10:59 AM, 14208 bytes, A Adds the file vsframe.js"="8/9/2018 10:59 AM, 19080 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\_metadata Adds the file computed_hashes.json"="8/15/2018 9:11 AM, 8371 bytes, A Adds the file verified_contents.json"="8/9/2018 10:59 AM, 3100 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img Adds the file bubble_arrow.png"="8/9/2018 10:59 AM, 17460 bytes, A Adds the file bubble_close.png"="8/9/2018 10:59 AM, 396 bytes, A Adds the file close.svg"="8/9/2018 10:59 AM, 1594 bytes, A Adds the file icon.png"="8/15/2018 9:11 AM, 37498 bytes, A Adds the file icon48.png"="8/9/2018 10:59 AM, 25727 bytes, A Adds the file info.svg"="8/9/2018 10:59 AM, 1251 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac Adds the file 000003.log"="8/15/2018 9:14 AM, 1665 bytes, A Adds the file CURRENT"="8/15/2018 9:11 AM, 16 bytes, A Adds the file LOCK"="8/15/2018 9:11 AM, 0 bytes, A Adds the file LOG"="8/15/2018 9:12 AM, 409 bytes, A Adds the file LOG.old"="8/15/2018 9:11 AM, 185 bytes, A Adds the file MANIFEST-000001"="8/15/2018 9:11 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac Adds the file 000003.log"="8/15/2018 9:11 AM, 0 bytes, A Adds the file CURRENT"="8/15/2018 9:11 AM, 16 bytes, A Adds the file LOCK"="8/15/2018 9:11 AM, 0 bytes, A Adds the file LOG"="8/15/2018 9:11 AM, 184 bytes, A Adds the file MANIFEST-000001"="8/15/2018 9:11 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\browser-extension-data\{df4e0189-a17d-41aa-af86-b6de65952842} Adds the file storage.js"="8/15/2018 9:08 AM, 462 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file {df4e0189-a17d-41aa-af86-b6de65952842}.xpi"="8/15/2018 9:07 AM, 160062 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "bkpcmggkflelcjggjomffidfpcfjbeac"="REG_SZ", "F94B4DAAA6B405D70B17A2560E3B3AE2DE0182150157C665AFEF9F6AEFF37973" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/15/18 Scan Time: 11:07 AM Log File: ab3158ef-a06a-11e8-8691-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6353 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251830 Threats Detected: 39 Threats Quarantined: 39 Time Elapsed: 3 min, 23 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 6 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\_metadata, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\bkpcmggkflelcjggjomffidfpcfjbeac, Quarantined, [2111], [552443],1.0.6353 File: 33 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\EXTENSIONS\{DF4E0189-A17D-41AA-AF86-B6DE65952842}.XPI, Quarantined, [2111], [552645],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\bubble_arrow.png, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\bubble_close.png, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\close.svg, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\icon.png, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\icon48.png, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\img\info.svg, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\_metadata\computed_hashes.json, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\_metadata\verified_contents.json, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\adentify.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\background.html, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\background.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\content.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\inimgContent.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\install.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\intextContent.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\intextstyle.css, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\manifest.json, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\overlay_style.css, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkpcmggkflelcjggjomffidfpcfjbeac\6.5.0.5_0\vsframe.js, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\000003.log, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\CURRENT, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\LOCK, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\LOG, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\LOG.old, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\MANIFEST-000001, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\000003.log, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\CURRENT, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\LOCK, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\LOG, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bkpcmggkflelcjggjomffidfpcfjbeac\MANIFEST-000001, Quarantined, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [2111], [552443],1.0.6353 PUP.Optional.PureLeisureFun, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [2111], [552443],1.0.6353 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  3. What is Dr. Clean Pro 2018?The Malwarebytes research team has determined that Dr. Clean Pro 2018 is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.More information can be found on our Malwarebytes Labs blog.How do I know if I am infected with Dr. Clean Pro 2018?This is how the main screen of the system optimizer looks:You will find these icons in your taskbar, your startmenu, and on your desktop:and see these warnings during install:and these screens during "operations":You may see this entry in your list of installed programs:and these tasks in your list of Scheduled Tasks:How did Dr. Clean Pro 2018 get on my computer?These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:How do I remove Dr. Clean Pro 2018?Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Dr. Clean Pro 2018? No, Malwarebytes removes Dr. Clean Pro 2018 completely. This PUP creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this system optimizer.As you can see below the full version of Malwarebytes would have protected you against the Dr. Clean Pro 2018 installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain.Technical details for expertsYou may see these entries in FRST logs: () C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername} C:\Windows\System32\Tasks\Dr.Clean-Pro-2018_Logon C:\Users\Public\Desktop\Dr.Clean-Pro-2018.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Clean-Pro-2018 for {computername} C:\ProgramData\Dr.Clean-Pro-2018 for {computername} C:\Program Files\Dr.Clean-Pro-2018 for {computername} Dr.Clean-Pro-2018 (HKLM\...\{7B1AE0CD-7ED9-44C2-8ED8-DFA8522119DE}_is1) (Version: 3.6.0.0 - ) Task: {FF5DA2B8-C268-46E5-A20C-F83333821500} - System32\Tasks\Dr.Clean-Pro-2018_Logon => C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe [2018-04-06] () Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files\Dr.Clean-Pro-2018 for {computername} Adds the file application.ico"="2/6/2018 10:43 AM, 56150 bytes, A Adds the file danish_iss.ini"="5/23/2017 6:31 PM, 2402 bytes, A Adds the file Dutch_iss.ini"="5/23/2017 6:31 PM, 2600 bytes, A Adds the file english_iss.ini"="5/23/2017 6:31 PM, 2256 bytes, A Adds the file finish_iss.ini"="5/23/2017 6:31 PM, 2368 bytes, A Adds the file French_iss.ini"="5/23/2017 6:31 PM, 2792 bytes, A Adds the file german_iss.ini"="5/23/2017 6:31 PM, 2658 bytes, A Adds the file gtcmg.dll"="4/6/2018 4:35 PM, 1784176 bytes, A Adds the file HtmlRenderer.dll"="4/6/2018 4:35 PM, 228208 bytes, A Adds the file HtmlRenderer.WinForms.dll"="4/6/2018 4:36 PM, 66928 bytes, A Adds the file Interop.IWshRuntimeLibrary.dll"="4/6/2018 4:36 PM, 55664 bytes, A Adds the file italian_iss.ini"="5/23/2017 6:31 PM, 2532 bytes, A Adds the file japanese_iss.ini"="5/23/2017 6:32 PM, 1844 bytes, A Adds the file langs.db"="2/6/2018 4:13 PM, 446464 bytes, A Adds the file Microsoft.Win32.TaskScheduler.dll"="4/6/2018 4:36 PM, 177520 bytes, A Adds the file mysysm.exe"="4/6/2018 4:35 PM, 2036592 bytes, A Adds the file mysysm.exe.config"="4/6/2018 4:35 PM, 5468 bytes, A Adds the file NAudio.dll"="4/6/2018 4:36 PM, 477552 bytes, A Adds the file norwegian_iss.ini"="5/23/2017 6:32 PM, 2358 bytes, A Adds the file portuguese_iss.ini"="5/23/2017 6:32 PM, 2424 bytes, A Adds the file russian_iss.ini"="5/23/2017 6:32 PM, 2494 bytes, A Adds the file spanish_iss.ini"="5/23/2017 6:32 PM, 2548 bytes, A Adds the file swedish_iss.ini"="5/23/2017 6:32 PM, 2270 bytes, A Adds the file System.Data.SQLite.DLL"="4/6/2018 4:36 PM, 297328 bytes, A Adds the file TAFactory.IconPack.dll"="4/6/2018 4:36 PM, 43376 bytes, A Adds the file unins000.dat"="8/14/2018 8:55 AM, 83573 bytes, A Adds the file unins000.exe"="8/14/2018 8:53 AM, 1235312 bytes, A Adds the file unins000.msg"="8/14/2018 8:55 AM, 22701 bytes, A Adds the folder C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x64 Adds the file SQLite.Interop.dll"="4/6/2018 4:35 PM, 1182064 bytes, A Adds the folder C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x86 Adds the file SQLite.Interop.dll"="4/6/2018 4:35 PM, 861040 bytes, A Adds the folder C:\ProgramData\Dr.Clean-Pro-2018 for {computername} Adds the file mdb.db"="10/3/2017 4:30 PM, 835584 bytes, A Adds the file pcspstartrepair_en.mp3"="3/2/2017 11:05 AM, 130973 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Clean-Pro-2018 for {computername} Adds the file Buy Dr.Clean-Pro-2018.lnk"="8/14/2018 8:55 AM, 1016 bytes, A Adds the file Dr.Clean-Pro-2018.lnk"="8/14/2018 8:55 AM, 1004 bytes, A Adds the file Uninstall Dr.Clean-Pro-2018.lnk"="8/14/2018 8:55 AM, 1016 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername} Adds the file Errorlog.txt"="8/14/2018 8:57 AM, 12040 bytes, A Adds the file exlist.bin"="8/14/2018 8:55 AM, 258023 bytes, A Adds the file notifier.xml"="8/14/2018 8:55 AM, 4716 bytes, A Adds the file param.ini"="8/14/2018 8:55 AM, 336 bytes, A Adds the file res.xml"="8/14/2018 8:56 AM, 9770 bytes, A Adds the file update.xml"="8/14/2018 8:55 AM, 10186 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\smico In the existing folder C:\Users\Public\Desktop Adds the file Dr.Clean-Pro-2018.lnk"="8/14/2018 8:55 AM, 986 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Dr.Clean-Pro-2018_Logon"="8/14/2018 8:55 AM, 3082 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Dr.Clean-Pro-2018 For {computername}] "affired"="REG_DWORD", 1 "afterInstallUrl"="REG_SZ", "http://ins.entireactiv.com/install/dcp/?" "apst"="REG_DWORD", 0 "btnid"="REG_SZ", "" "cbkpoff"="REG_DWORD", 1 "country"="REG_SZ", "us" "cta"="REG_DWORD", 0 "delaytime"="REG_DWORD", 0 "dlllist"="REG_SZ", "PSMACHINE_64.DLL,MSSPELLCHECKINGFACILITY.DLL" "EmailURL"="REG_SZ", "" "expired"="REG_DWORD", 0 "hdata"="REG_BINARY, .......................................................................................................................................................................................................................................................................................................................................... "Installstring"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}" "ipaddrurl"="REG_SZ", "http://www.entireactiv.com/getip/" "isavst"="REG_DWORD", 0 "isiunidu"="REG_DWORD", 0 "isshowng"="REG_DWORD", 1 "issilent"="REG_DWORD", 0 "ISTELNO"="REG_DWORD", 1 "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "lstregscancount"="REG_DWORD", 24 "lstscandate"="REG_SZ", "8/14/2018 8:56:21 AM" "lstscanstat"="REG_DWORD", 2 "lstsecscancount"="REG_DWORD", 0 "lsttotalscancount"="REG_DWORD", 24 "ovoffdis"="REG_DWORD", 0 "paramurl"="REG_SZ", "http://trkr.entireactiv.com/ipfiles/" "playsound"="REG_DWORD", 1 "prereg"="REG_DWORD", 0 "PurchaseURL"="REG_SZ", "http://store.winoptimizertools.com/dcp/price?" "pxl"="REG_SZ", "WCL1735_WCL1700_RUNT" "referurl"="REG_SZ", "" "reg"="REG_DWORD", 0 "RenewURL"="REG_SZ", "http://store.winoptimizertools.com/dcp/renewal?" "runcam"="REG_DWORD", 1 "runpixel"="REG_DWORD", 1 "runsrc"="REG_DWORD", 1 "showtn"="REG_DWORD", 0 "showunins"="REG_DWORD", 0 "showwfo"="REG_DWORD", 0 "stdismax"="REG_DWORD", -1 "supporturl"="REG_SZ", "http://www.winoptimizertools.com/help/" "TELNO"="REG_SZ", "(855)-332-0124" "TELNO_ar"="REG_SZ", "+54 11 5236 0324" "TELNO_at"="REG_SZ", "+43 (0)720 902 309" "TELNO_au"="REG_SZ", "(61)280-733403" "TELNO_br"="REG_SZ", "+55 21 2391 4319" "TELNO_ch"="REG_SZ", "+41 (0)44 508 70 37" "TELNO_de"="REG_SZ", "0800 1822 974" "TELNO_dk"="REG_SZ", "+45 78 73 09 26" "TELNO_es"="REG_SZ", "+34 951 203 537" "TELNO_fi"="REG_SZ", "+358 (0)9 4270 4911" "TELNO_fr"="REG_SZ", "05 82 84 04 06" "TELNO_gb"="REG_SZ", "0800-031-5066" "TELNO_it"="REG_SZ", "+39 069 4802886" "TELNO_ja"="REG_SZ", "" "TELNO_lu"="REG_SZ", "0800 1822 974" "TELNO_nl"="REG_SZ", "+31-08-58882839" "TELNO_no"="REG_SZ", "+47 21 95 01 97" "TELNO_pt"="REG_SZ", "+351 70 750 2094" "TELNO_se"="REG_SZ", "+46-08124-10298" "TELNO_uk"="REG_SZ", "0800-031-5066" "TELNO_us"="REG_SZ", "(855)-332-0124" "utm_campaign"="REG_SZ", "wclkddl2" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "61188" "utm_source"="REG_SZ", "wclkddl2" "WebURL"="REG_SZ", "http://www.winoptimizertools.com/" "wfoset"="REG_DWORD", 1 "x-at"="REG_SZ", "" "x-ccode"="REG_SZ", "us" "x-context"="REG_SZ", "1-712-3f534497-7739-4d0e-9b6b-9ae32af5cc98" "x-datetime"="REG_SZ", "08-14-2018 06:55:37 AM" "x-fetch"="REG_SZ", "1" "x-ip"="REG_SZ", "77_234_46_177" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7B1AE0CD-7ED9-44C2-8ED8-DFA8522119DE}_is1] "DisplayIcon"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe" "DisplayName"="REG_SZ", "Dr.Clean-Pro-2018" "DisplayVersion"="REG_SZ", "3.6.0.0" "EstimatedSize"="REG_DWORD", 11461 "Inno Setup: App Path"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}" "Inno Setup: Icon Group"="REG_SZ", "Dr.Clean-Pro-2018 for {computername}" "Inno Setup: Language"="REG_SZ", "en" "Inno Setup: Setup Version"="REG_SZ", "5.5.8 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20180814" "InstallLocation"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}\" "MajorVersion"="REG_DWORD", 3 "MinorVersion"="REG_DWORD", 6 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Program Files\Dr.Clean-Pro-2018 for {computername}\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files\Dr.Clean-Pro-2018 for {computername}\unins000.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\RHIuQ2xlYW4tUHJvLTIwMTg=\ACT] "data"="REG_BINARY, .............. [HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr] "affiliateid"="REG_SZ", "" "btnid"="REG_SZ", "" "country"="REG_SZ", "us" "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "pxl"="REG_SZ", "WCL1735_WCL1700_RUNT" "referUrl"="REG_SZ", "" "TELNO"="REG_SZ", "" "utm_campaign"="REG_SZ", "wclkddl2" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "61188" "utm_source"="REG_SZ", "wclkddl2" "x-at"="REG_SZ", "" "x-context"="REG_SZ", "1-712-3f534497-7739-4d0e-9b6b-9ae32af5cc98" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_CURRENT_USER\Software\Dr.Clean-Pro-2018 for {computername}] "btnid"="REG_SZ", "" "InstallString"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}" "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "pxl"="REG_SZ", "WCL1735_WCL1700_RUNT" "referurl"="REG_SZ", "" "utm_campaign"="REG_SZ", "wclkddl2" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "61188" "utm_source"="REG_SZ", "wclkddl2" "x-at"="REG_SZ", "" "x-context"="REG_SZ", "1-712-3f534497-7739-4d0e-9b6b-9ae32af5cc98" "x-datetime"="REG_SZ", "08-14-2018 06:55:37 AM" "x-fetch"="REG_SZ", "1" "x-ip"="REG_SZ", "77_234_46_177" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_CURRENT_USER\Software\Dr.Clean-Pro-2018 for {computername}\3.6.0.0] "Installstring"="REG_SZ", "C:\Program Files\Dr.Clean-Pro-2018 for {computername}" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/14/18 Scan Time: 9:06 AM Log File: 89567e29-9f90-11e8-b54c-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6331 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251390 Threats Detected: 76 Threats Quarantined: 76 Time Elapsed: 3 min, 31 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe, Quarantined, [3479], [509518],1.0.6331 Module: 6 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [3479], [509518],1.0.6331 Registry Key: 10 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Dr.Clean-Pro-2018_Logon, Quarantined, [3479], [509526],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FF5DA2B8-C268-46E5-A20C-F83333821500}, Quarantined, [3479], [509526],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{FF5DA2B8-C268-46E5-A20C-F83333821500}, Quarantined, [3479], [509526],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7B1AE0CD-7ED9-44C2-8ED8-DFA8522119DE}_is1, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.PCFixerPro, HKLM\SOFTWARE\MICROSOFT\TRACING\mysysm_RASAPI32, Quarantined, [1281], [501684],1.0.6331 PUP.Optional.PCFixerPro, HKLM\SOFTWARE\MICROSOFT\TRACING\mysysm_RASMANCS, Quarantined, [1281], [501684],1.0.6331 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR, Quarantined, [418], [540842],1.0.6331 PUP.Optional.DrCleanPro, HKCU\SOFTWARE\Dr.Clean-Pro-2018 for {computername}, Quarantined, [3479], [509523],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\Dr.Clean-Pro-2018 For {computername}, Quarantined, [3479], [509522],1.0.6331 PUP.Optional.Jawego, HKLM\SOFTWARE\RHIuQ2xlYW4tUHJvLTIwMTg=, Quarantined, [522], [535314],1.0.6331 Registry Value: 4 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR|AFFILIATEID, Quarantined, [418], [540842],1.0.6331 PUP.Optional.MasterPCCleaner, HKLM\SOFTWARE\SCD-PR|PXL, Quarantined, [1119], [484510],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FF5DA2B8-C268-46E5-A20C-F83333821500}|PATH, Quarantined, [3479], [509527],1.0.6331 PUP.Optional.DrCleanPro, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7B1AE0CD-7ED9-44C2-8ED8-DFA8522119DE}_is1|DISPLAYNAME, Quarantined, [3479], [509525],1.0.6331 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 8 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x64, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x86, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\PROGRAM FILES\Dr.Clean-Pro-2018 for {computername}, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\smico, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\USERS\{username}\APPDATA\ROAMING\Dr.Clean-Pro-2018 For {computername}, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\PROGRAMDATA\Dr.Clean-Pro-2018 for {computername}, Quarantined, [3479], [509524],1.0.6331 PUP.Optional.DrCleanPro, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Dr.Clean-Pro-2018 for {computername}, Quarantined, [3479], [509519],1.0.6331 PUP.Optional.Jawego, C:\PROGRAMDATA\Dr.Clean-Pro-2018 for {computername}, Quarantined, [522], [535312],1.0.6331 File: 47 PUP.Optional.DrCleanPro, C:\USERS\PUBLIC\DESKTOP\Dr.Clean-Pro-2018.lnk, Quarantined, [3479], [509521],1.0.6331 PUP.Optional.DrCleanPro, C:\WINDOWS\SYSTEM32\TASKS\Dr.Clean-Pro-2018_Logon, Quarantined, [3479], [509526],1.0.6331 PUP.Optional.DrCleanPro, C:\PROGRAM FILES\Dr.Clean-Pro-2018 for {computername}\unins000.dat, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\x86\SQLite.Interop.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\italian_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\application.ico, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\danish_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\Dutch_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\english_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\finish_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\French_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\german_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\gtcmg.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\HtmlRenderer.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\HtmlRenderer.WinForms.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\japanese_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\langs.db, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\mysysm.exe.config, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\NAudio.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\norwegian_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\portuguese_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\russian_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\spanish_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\swedish_iss.ini, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\unins000.exe, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\Program Files\Dr.Clean-Pro-2018 for {computername}\unins000.msg, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Dr.Clean-Pro-2018.lnk, Quarantined, [3479], [509518],1.0.6331 PUP.Optional.DrCleanPro, C:\USERS\{username}\APPDATA\ROAMING\Dr.Clean-Pro-2018 For {computername}\Errorlog.txt, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\exlist.bin, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\notifier.xml, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\param.ini, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\res.xml, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\Users\{username}\AppData\Roaming\Dr.Clean-Pro-2018 For {computername}\update.xml, Quarantined, [3479], [509520],1.0.6331 PUP.Optional.DrCleanPro, C:\PROGRAMDATA\Dr.Clean-Pro-2018 for {computername}\mdb.db, Quarantined, [3479], [509524],1.0.6331 PUP.Optional.DrCleanPro, C:\ProgramData\Dr.Clean-Pro-2018 for {computername}\pcspstartrepair_en.mp3, Quarantined, [3479], [509524],1.0.6331 PUP.Optional.DrCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Clean-Pro-2018 for {computername}\Buy Dr.Clean-Pro-2018.lnk, Quarantined, [3479], [509519],1.0.6331 PUP.Optional.DrCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Clean-Pro-2018 for {computername}\Dr.Clean-Pro-2018.lnk, Quarantined, [3479], [509519],1.0.6331 PUP.Optional.DrCleanPro, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dr.Clean-Pro-2018 for {computername}\Uninstall Dr.Clean-Pro-2018.lnk, Quarantined, [3479], [509519],1.0.6331 PUP.Optional.Jawego, C:\ProgramData\Dr.Clean-Pro-2018 for {computername}\mdb.db, Quarantined, [522], [535312],1.0.6331 PUP.Optional.Jawego, C:\ProgramData\Dr.Clean-Pro-2018 for {computername}\pcspstartrepair_en.mp3, Quarantined, [522], [535312],1.0.6331 PUP.Optional.DrCleanPro, C:\USERS\{username}\DESKTOP\DCPSETUP.EXE, Quarantined, [3479], [509517],1.0.6331 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  4. What is WinZip DriverUpdater?The Malwarebytes research team has determined that WinZip DriverUpdater is a "driver updater". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.More information can be found on our Malwarebytes Labs blog.How do I know if I am infected with WinZip DriverUpdater?This is how the main screen of the system optimizer looks:You will find these icons in your taskbar, your startmenu, and on your desktop:and see this warning during install:and these screens during "operations":You may see this entry in your list of installed programs:and these tasks in your list of Scheduled Tasks:How did WinZip DriverUpdater get on my computer?These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:How do I remove WinZip DriverUpdater?Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of WinZip DriverUpdater? No, Malwarebytes removes WinZip DriverUpdater completely. This PUP creates some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this system optimizer.As you can see below the full version of Malwarebytes would have protected you against the WinZip DriverUpdater installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for expertsYou may see these entries in FRST logs: () C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe (Corel Corporation) C:\Program Files\WinZip Driver Updater\DriverUpdater.exe (Corel Corporation) C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe R2 WinZip Smart Monitor Service; C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe [816896 2017-12-04] () C:\Windows\System32\Tasks\Start WinZip Driver Updater Schedule C:\Windows\System32\Tasks\Start WinZip Driver Updater Update C:\Windows\System32\Tasks\Start WinZip Driver Updater for {computername}@{username}(logon) C:\Users\Public\Desktop\WinZip Driver Updater.lnk C:\Windows\Tasks\Start WinZip Driver Updater for {computername}@{username}(logon).job C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip C:\ProgramData\WinZip C:\Program Files\WinZip Smart Monitor C:\Program Files\WinZip Driver Updater WinZip Driver Updater (HKLM\...\WinZip Driver Updater) (Version: 5.25.3.6 - Corel Corporation) Task: {3E6BA1EC-1D92-4073-A7DF-EADE1A17FB29} - System32\Tasks\Start WinZip Driver Updater for {computername}@{username}(logon) => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe [2018-01-22] (Corel Corporation) Task: {91A08D31-A6DA-4E07-8567-11463B0EC0FD} - System32\Tasks\Start WinZip Driver Updater Update => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe [2018-01-22] (Corel Corporation) Task: {E2140951-A5BB-4ED9-A854-C4660836C649} - System32\Tasks\Start WinZip Driver Updater Schedule => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe [2018-01-22] (Corel Corporation) Task: C:\Windows\Tasks\Start WinZip Driver Updater for {computername}@{username}(logon).job => C:\Program Files\WinZip Driver Updater\DriverUpdater.exe Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files\WinZip Driver Updater Adds the file 7za.exe"="8/10/2018 12:00 PM, 591104 bytes, A Adds the file DriverUpdater.exe"="1/22/2018 2:57 PM, 31463168 bytes, A Adds the file DriverUpdater.mab"="1/22/2018 2:57 PM, 2430086 bytes, A Adds the file DriverUpdaterUpdater.exe"="1/22/2018 2:57 PM, 80640 bytes, A Adds the file DriverUpdaterUpdater.mab"="1/22/2018 2:57 PM, 10443 bytes, A Adds the file lci.lci"="8/10/2018 12:00 PM, 648 bytes, H Adds the file notifier.exe"="1/22/2018 2:57 PM, 2490624 bytes, A Adds the file notifier.mab"="1/22/2018 2:57 PM, 698833 bytes, A Adds the file tray.exe"="1/22/2018 2:57 PM, 2696448 bytes, A Adds the file tray.mab"="1/22/2018 2:57 PM, 253763 bytes, A Adds the file Uninstall.exe"="1/22/2018 2:57 PM, 551904 bytes, A Adds the folder C:\Program Files\WinZip Smart Monitor Adds the file apps"="12/4/2017 9:28 AM, 2864 bytes, A Adds the file msvcp100.dll"="5/11/2016 6:02 PM, 608080 bytes, A Adds the file msvcr100.dll"="5/11/2016 6:02 PM, 829264 bytes, A Adds the file SystemInfo-vc100-mt.dll"="12/4/2017 9:46 AM, 2238208 bytes, A Adds the file SystemInfo-vc100-mt.mab"="12/4/2017 9:46 AM, 985327 bytes, A Adds the file Uninstall.exe"="12/4/2017 9:46 AM, 227440 bytes, A Adds the file WinZip Smart Monitor Service.exe"="12/4/2017 9:46 AM, 816896 bytes, A Adds the file WinZip Smart Monitor Service.mab"="12/4/2017 9:46 AM, 260502 bytes, A Adds the file WinZipSmartMonitor.exe"="12/4/2017 9:46 AM, 3351808 bytes, A Adds the file WinZipSmartMonitor.mab"="12/4/2017 9:46 AM, 913751 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\WinZip Driver Updater Adds the file Uninstall.lnk"="8/10/2018 12:00 PM, 932 bytes, A Adds the file WinZip Driver Updater.lnk"="8/10/2018 12:00 PM, 952 bytes, A Adds the folder C:\ProgramData\WinZip\WinZip Driver Updater Adds the file CommonSettings.xml"="8/10/2018 12:00 PM, 426 bytes, A Adds the file freeDriver"="8/10/2018 12:00 PM, 101 bytes, A Adds the folder C:\ProgramData\WinZip\WinZip Driver Updater\backups Adds the file BackupInfo.xml"="8/10/2018 12:00 PM, 399 bytes, A Adds the folder C:\ProgramData\WinZip\WinZip Driver Updater\Language Adds the file Brazilian.xml"="1/22/2018 2:37 PM, 32752 bytes, A Adds the file Danish.xml"="1/22/2018 2:37 PM, 32031 bytes, A Adds the file Dutch.xml"="1/22/2018 2:37 PM, 33587 bytes, A Adds the file English.xml"="1/22/2018 2:37 PM, 30203 bytes, A Adds the file Finnish.xml"="1/22/2018 2:37 PM, 32204 bytes, A Adds the file French.xml"="1/22/2018 2:37 PM, 36420 bytes, A Adds the file German.xml"="1/22/2018 2:37 PM, 34798 bytes, A Adds the file Italian.xml"="1/22/2018 2:37 PM, 32882 bytes, A Adds the file Japanese.xml"="1/22/2018 2:37 PM, 39160 bytes, A Adds the file Norwegian.xml"="1/22/2018 2:37 PM, 31154 bytes, A Adds the file Russian.xml"="1/22/2018 2:37 PM, 49727 bytes, A Adds the file Spanish.xml"="1/22/2018 2:37 PM, 35321 bytes, A Adds the file Swedish.xml"="1/22/2018 2:37 PM, 32551 bytes, A Adds the file TradChinese.xml"="1/22/2018 2:37 PM, 29484 bytes, A Adds the file Turkish.xml"="1/22/2018 2:37 PM, 33841 bytes, A Adds the folder C:\ProgramData\WinZip\WinZip Driver Updater\{userID} Adds the file app_log.log"="8/10/2018 12:01 PM, 3530 bytes, A Adds the file AppSettings.xml"="8/10/2018 12:01 PM, 2518 bytes, A Adds the file DRmanager_log.log"="8/10/2018 12:01 PM, 1366 bytes, A Adds the file du_statistic"="8/10/2018 12:01 PM, 32768 bytes, A Adds the file Request.xml"="8/10/2018 12:01 PM, 28564 bytes, A Adds the file Response.xml"="8/10/2018 12:01 PM, 474 bytes, A Adds the folder C:\ProgramData\WinZip\WinZip Smart Monitor\{userID} Adds the file settings.data"="8/10/2018 12:00 PM, 675 bytes, A Adds the file smsettings"="8/10/2018 12:00 PM, 44 bytes, A In the existing folder C:\Users\Public\Desktop Adds the file WinZip Driver Updater.lnk"="8/10/2018 12:00 PM, 928 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Start WinZip Driver Updater for {computername}@{username}(logon)"="8/10/2018 12:00 PM, 2646 bytes, A Adds the file Start WinZip Driver Updater Schedule"="8/10/2018 12:00 PM, 3432 bytes, A Adds the file Start WinZip Driver Updater Update"="8/10/2018 12:00 PM, 3364 bytes, A In the existing folder C:\Windows\Tasks Adds the file Start WinZip Driver Updater for {computername}@{username}(logon).job"="8/10/2018 12:00 PM, 338 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SMSettings] "(Default)"="REG_SZ", "SMSettings Class" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SMSettings\CLSID] "(Default)"="REG_SZ", "{B5E0AC71-16D8-4F94-BD38-6373721A3995}" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SMSettings\CurVer] "(Default)"="REG_SZ", "WinZip.SMSettings.1.1" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SMSettings.1.1] "(Default)"="REG_SZ", "WinZipSmartMonitor settings" [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SMSettings.1.1\CLSID] "(Default)"="REG_SZ", "{B5E0AC71-16D8-4F94-BD38-6373721A3995}" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip Driver Updater] "BID"="REG_SZ", "34" "DisplayIcon"="REG_SZ", "C:\Program Files\WinZip Driver Updater\DriverUpdater.exe" "DisplayName"="REG_SZ", "WinZip Driver Updater" "DisplayVersion"="REG_SZ", "5.25.3.6" "InstallLocation"="REG_SZ", "C:\Program Files\WinZip Driver Updater" "InstallPath"="REG_SZ", "C:\Program Files\WinZip Driver Updater" "MajorVersion"="REG_DWORD", 5 "MinorVersion"="REG_DWORD", 25 "OSOURCE"="REG_SZ", "" "Publisher"="REG_SZ", "Corel Corporation" "TID"="REG_SZ", "" "UninstallString"="REG_SZ", "C:\Program Files\WinZip Driver Updater\Uninstall.exe" "URLInfoAbout"="REG_SZ", "http://esupport.winzipsystemtools.com/driver-updater/" "VersionMajor"="REG_DWORD", 5 "VersionMinor"="REG_DWORD", 25 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures] "Start WinZip Driver Updater for {computername}@{username}(logon).job"="REG_BINARY, ................................ "Start WinZip Driver Updater for {computername}@{username}(logon).job.fp"="REG_DWORD", -1506061711 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\WinZip Smart Monitor Service] "DependOnService"="REG_MULTI_SZ, "RPCSS " "Description"="REG_SZ", "WinZip Smart Monitor Service" "DisplayName"="REG_SZ", "WinZip Smart Monitor Service" "ErrorControl"="REG_DWORD", 1 "FailureActions"="REG_BINARY, ...................... "ImagePath"="REG_EXPAND_SZ, ""C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe"" "ObjectName"="REG_SZ", "LocalSystem" "Start"="REG_DWORD", 2 "Type"="REG_DWORD", 16 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/10/18 Scan Time: 12:22 PM Log File: 406eb921-9c87-11e8-9457-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6285 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251343 Threats Detected: 91 Threats Quarantined: 89 Time Elapsed: 3 min, 54 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 3 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdater.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe, Quarantined, [1604], [456267],1.0.6285 Module: 9 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdater.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcp100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcp100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcr100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcr100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\SystemInfo-vc100-mt.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\SystemInfo-vc100-mt.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe, Quarantined, [1604], [456267],1.0.6285 Registry Key: 11 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Start WinZip Driver Updater for {computername}@{username}(logon), Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3E6BA1EC-1D92-4073-A7DF-EADE1A17FB29}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{3E6BA1EC-1D92-4073-A7DF-EADE1A17FB29}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Start WinZip Driver Updater Schedule, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E2140951-A5BB-4ED9-A854-C4660836C649}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{E2140951-A5BB-4ED9-A854-C4660836C649}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Start WinZip Driver Updater Update, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{91A08D31-A6DA-4E07-8567-11463B0EC0FD}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{91A08D31-A6DA-4E07-8567-11463B0EC0FD}, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WinZip Driver Updater, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinZip Smart Monitor Service, Quarantined, [1604], [456267],1.0.6285 Registry Value: 3 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{3E6BA1EC-1D92-4073-A7DF-EADE1A17FB29}|PATH, Quarantined, [1603], [307843],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{91A08D31-A6DA-4E07-8567-11463B0EC0FD}|PATH, Quarantined, [1603], [307843],1.0.6285 PUP.Optional.WinZipDriverUpdater, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{E2140951-A5BB-4ED9-A854-C4660836C649}|PATH, Quarantined, [1603], [307843],1.0.6285 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 9 PUP.Optional.WinZipDriverUpdater, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\WINZIP\WINZIP DRIVER UPDATER, Quarantined, [1603], [310354],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\backups, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\PROGRAMDATA\WINZIP\WINZIP DRIVER UPDATER, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\PROGRAM FILES\WinZip Driver Updater, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\PROGRAM FILES\WINZIP SMART MONITOR, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\ProgramData\WinZip\WinZip Smart Monitor\{userID}, Removal Failed, [1604], [458272],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\PROGRAMDATA\WINZIP\WINZIP SMART MONITOR, Removal Failed, [1604], [458272],1.0.6285 File: 56 PUP.Optional.WinZipDriverUpdater, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\WINZIP\WINZIP DRIVER UPDATER\WINZIP DRIVER UPDATER.LNK, Quarantined, [1603], [310354],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip\WinZip Driver Updater\Uninstall.lnk, Quarantined, [1603], [310354],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Start WinZip Driver Updater for {computername}@{username}(logon), Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Start WinZip Driver Updater Schedule, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\WINDOWS\SYSTEM32\TASKS\Start WinZip Driver Updater Update, Quarantined, [1603], [307837],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\USERS\PUBLIC\DESKTOP\WINZIP DRIVER UPDATER.LNK, Quarantined, [1603], [310353],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\WINDOWS\TASKS\Start WinZip Driver Updater for {computername}@{username}(logon).job, Quarantined, [1603], [307836],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\backups\BackupInfo.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Brazilian.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Danish.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Dutch.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\English.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Finnish.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\French.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\German.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Italian.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Japanese.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Norwegian.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Russian.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Spanish.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Swedish.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\TradChinese.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\Language\Turkish.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\AppSettings.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\app_log.log, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\DRmanager_log.log, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\du_statistic, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\Request.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\{userID}\Response.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\CommonSettings.xml, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\ProgramData\WinZip\WinZip Driver Updater\freeDriver, Quarantined, [1603], [307835],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\7za.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdater.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdater.mab, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdaterUpdater.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\DriverUpdaterUpdater.mab, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\lci.lci, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\notifier.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\notifier.mab, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\tray.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\tray.mab, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\Program Files\WinZip Driver Updater\Uninstall.exe, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\WinZip Driver Updater.lnk, Quarantined, [1603], [364824],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\apps, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcp100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\msvcr100.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\SystemInfo-vc100-mt.dll, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\SystemInfo-vc100-mt.mab, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\Uninstall.exe, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.exe, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZip Smart Monitor Service.mab, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.exe, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\Program Files\WinZip Smart Monitor\WinZipSmartMonitor.mab, Quarantined, [1604], [456267],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\ProgramData\WinZip\WinZip Smart Monitor\{userID}\settings.data, Quarantined, [1604], [458272],1.0.6285 PUP.Optional.WinzipSystemUtilitiesSuite, C:\ProgramData\WinZip\WinZip Smart Monitor\{userID}\smsettings, Quarantined, [1604], [458272],1.0.6285 PUP.Optional.WinZipDriverUpdater, C:\USERS\{username}\DESKTOP\WZDU34.EXE, Quarantined, [1603], [484645],1.0.6285 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  5. What is AppSet?The Malwarebytes research team has determined that AppSet is a bundler that often delivers several browser hijackers. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice.How do I know if my computer is affected by AppSet?You may see these entries in your list of installed software:and these warnings during install:the bundled applicationsome of the bundled software can be opted-out, others are mandatory or silentsome only appear after you open your browseryou may see these browser add-ons:this type of new default search providers:and you will see these icons in your startmenu, on your taskbar and on your desktop:How did AppSet get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.How do I remove AppSet?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of AppSet? No, Malwarebytes removes AppSet completely. This PUP can create some scheduled tasks. You can read here how to check for and, if necessary, remove Scheduled Tasks. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the AppSet bundler. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. Technical details for expertsPossible signs in FRST logs: (Yandex LLC) C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.exe HKCU\...\Run: [Browser Manager] => C:\Users\{username}\AppData\Local\Yandex\BrowserManager\MBLauncher.exe [129896 2017-08-11] (Yandex LLC) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yandex.ru/?win=345&clid=2323969-3 SearchScopes: HKCU -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://yandex.ru/search/?win=345&clid=2323970-3&text={searchTerms} SearchScopes: HKCU -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://yandex.ru/search/?win=345&clid=2323970-3&text={searchTerms} FF DefaultSearchEngine: Яндекс FF SelectedSearchEngine: Яндекс FF Homepage: hxxps://www.yandex.ru/?win=345&clid=2323969-3 FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\searchplugins\yandex.ru-20180610.xml [2018-08-10] FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\Extensions\sovetnik@metabar.ru.xpi [2018-08-10] FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\Extensions\vb@yandex.ru.xpi [2018-08-10] CHR DefaultSearchURL: Default -> hxxps://yandex.ru/search/?__PARAM__from=chromesearch&text={searchTerms} CHR DefaultSearchKeyword: Default -> yandex.ru CHR DefaultSuggestURL: Default -> hxxps://suggest.yandex.net/suggest-ff.cgi?uil=ru&part={searchTerms} CHR Extension: (Яндекс) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja [2018-08-10] CHR HKLM-x32\...\Chrome\Extension: [ablpcikjmhamjanpibkccdmpoekjigja] - hxxp://clients2.google.com/service/update2/crx OPR StartupUrls: "hxxps:\/\/www.yandex.ru\/?win=345&clid=2323969-3" C:\Users\{username}\Desktop\Yandex.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Yandex C:\Users\{username}\AppData\Local\Yandex C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс C:\Users\{username}\AppData\LocalLow\Yandex C:\Users\{username}\AppData\Roaming\Yandex C:\Users\{username}\AppData\Local\4tools (appset.me ) C:\Users\{username}\Desktop\After Death.exe Yandex (HKCU\...\YandexBrowser) (Version: 18.6.1.770 - ООО «ЯНДЕКС») Yandex taskbar button (HKCU\...\YaPinLancher) (Version: 2.0.4.2157 - Yandex) Менеджер браузеров (HKCU\...\{d4bb3741-07a4-443a-8c73-0cfda821c697}) (Version: 3.0.6.829 - Яндекс) Менеджер браузеров (x32 Version: 3.0.6.829 - Яндекс) Hidden Task: {251471D4-E8A6-485F-A381-32B17C4610B7} - System32\Tasks\Обновление Браузера Яндекс => C:\Users\{username}\AppData\Local\Yandex\YandexBrowser\Application\browser.exe [2018-07-07] (YANDEX LLC) Task: C:\Windows\Tasks\Обновление Браузера Яндекс.job => C:\Users\{username}\AppData\Local\Yandex\YandexBrowser\Application\browser.exe Some significant lterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Microsoft\Internet Explorer\Services Adds the file avia.yandex.ru.ico"="8/10/2018 9:07 AM, 6518 bytes, A Adds the file kinopoisk.ru.ico"="8/10/2018 9:07 AM, 13942 bytes, A Adds the file www.yandex.ru.ico"="8/10/2018 9:07 AM, 5430 bytes, A Adds the file yandex.ru.ico"="8/10/2018 9:06 AM, 5430 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Yandex\BrowserManager Adds the file BrowserManager.Core.dll"="8/11/2017 1:00 PM, 415592 bytes, A Adds the file BrowserManager.Core.UI.dll"="8/11/2017 1:00 PM, 391528 bytes, A Adds the file BrowserManager.exe"="8/11/2017 1:00 PM, 352104 bytes, A Adds the file Crypto.Core.dll"="8/11/2017 1:00 PM, 47616 bytes, A Adds the file MBlauncher.exe"="8/11/2017 1:00 PM, 129896 bytes, A Adds the file MBlauncher_x64.exe"="8/11/2017 1:00 PM, 153960 bytes, A Adds the file ModuleUpgrader.dll"="8/11/2017 1:00 PM, 74088 bytes, A Adds the file ModuleUpgrader.dll.upgrade"="8/10/2018 9:08 AM, 76312 bytes, A Adds the file NAudio.dll"="8/11/2017 1:00 PM, 475136 bytes, A Adds the file Newtonsoft.Json.dll"="8/11/2017 1:00 PM, 521216 bytes, A Adds the file NLog.dll"="8/11/2017 1:00 PM, 577536 bytes, A Adds the file RefCheck.dll"="8/11/2017 1:00 PM, 19816 bytes, A Adds the file System.Data.SQLite.dll"="8/11/2017 1:00 PM, 311296 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Yandex\Updater Adds the folder C:\Users\{username}\AppData\Local\Yandex\Updater2 Adds the file res"="8/10/2018 9:07 AM, 1 bytes, A Adds the file show-dlg.exe"="6/14/2016 2:14 PM, 389952 bytes, A Adds the file u2-ctrl.exe"="6/14/2016 2:14 PM, 493568 bytes, A Adds the file yupdate-exec.exe"="6/14/2016 2:14 PM, 492864 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Yandex\yapin Adds the file Yandex.exe"="7/20/2018 4:33 PM, 297992 bytes, A Adds the file Yandex.lnk"="8/10/2018 9:07 AM, 2089 bytes, A Adds the file YandexWorking.exe"="7/20/2018 4:33 PM, 297992 bytes, A Adds the file Яндекс.website"="8/10/2018 9:07 AM, 520 bytes, A Adds the folder C:\Users\{username}\AppData\LocalLow\Yandex Adds the folder C:\Users\{username}\AppData\LocalLow\Yandex\Updater Adds the file u2-ctrl.log"="8/10/2018 9:07 AM, 9487 bytes, A Adds the file u2-exec-bm.log"="8/10/2018 9:07 AM, 4874 bytes, A Adds the file u2-exec-statistic.log"="8/10/2018 9:07 AM, 5557 bytes, A Adds the folder C:\Users\{username}\AppData\LocalLow\Yandex\Updater\bm Adds the file appinfo.xml"="8/10/2018 9:07 AM, 805 bytes, A Adds the file statistics.xml"="8/10/2018 9:07 AM, 278 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar Adds the file Yandex.lnk"="8/10/2018 9:07 AM, 2089 bytes, A Adds the file Кинопоиск.website"="8/10/2018 9:07 AM, 537 bytes, A Adds the file Яндекс.website"="8/10/2018 9:07 AM, 520 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Яндекс\Менеджер браузеров Adds the file Менеджер браузеров.lnk"="8/10/2018 9:07 AM, 1331 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\browser-extension-data\sovetnik@metabar.ru Adds the file storage.js"="8/10/2018 9:06 AM, 715 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\browser-extension-data\vb@yandex.ru Adds the file storage.js"="8/10/2018 9:06 AM, 715 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\extensions\staged Adds the file sovetnik@metabar.ru.json"="8/10/2018 9:06 AM, 1063 bytes, A Adds the file sovetnik@metabar.ru.xpi"="8/10/2018 9:06 AM, 705207 bytes, A Adds the file vb@yandex.ru.json"="8/10/2018 9:06 AM, 5222 bytes, A Adds the file vb@yandex.ru.xpi"="8/10/2018 9:06 AM, 1736900 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\searchplugins Adds the file yandex.ru-20180610.xml"="8/10/2018 9:06 AM, 9693 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\yandex-extensions-data Adds the file clids-sovetnik.xml"="8/10/2018 9:06 AM, 673 bytes, A Adds the file clids-vbff.xml"="8/10/2018 9:06 AM, 673 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Yandex Adds the file clids-bm.xml"="8/10/2018 9:07 AM, 201 bytes, A Adds the file clids-yabrowser.xml"="8/10/2018 9:06 AM, 619 bytes, A Adds the file ui"="8/10/2018 9:06 AM, 38 bytes, A In the existing folder C:\Users\{username}\Favorites\Links Adds the file Авиабилеты.url"="8/10/2018 9:07 AM, 415 bytes, A Adds the file Яндекс.url"="8/10/2018 9:06 AM, 331 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ablpcikjmhamjanpibkccdmpoekjigja] "install_parameter"="REG_SZ", "clid=2323970-3&win=345&" "update_url"="REG_SZ", "http://clients2.google.com/service/update2/crx" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{FABA89D9-D588-4770-9F85-F6FF9F064257}] "AuthorizedCDFPrefix"="REG_SZ", "" "Comments"="REG_SZ", "" "Contact"="REG_SZ", "" "DisplayName"="REG_SZ", "Менеджер браузеров" "DisplayVersion"="REG_SZ", "3.0.6.829" "EstimatedSize"="REG_DWORD", 9328 "HelpLink"="REG_EXPAND_SZ, "http://help.yandex.ru/bm/" "HelpTelephone"="REG_SZ", "" "InstallDate"="REG_SZ", "20180810" "InstallLocation"="REG_SZ", "" "InstallSource"="REG_SZ", "C:\Users\{username}\AppData\Local\Package Cache\{FABA89D9-D588-4770-9F85-F6FF9F064257}v3.0.6.829\" "Language"="REG_DWORD", 0 "ModifyPath"="REG_EXPAND_SZ, "MsiExec.exe /X{FABA89D9-D588-4770-9F85-F6FF9F064257}" "NoModify"="REG_DWORD", 1 "Publisher"="REG_SZ", "Яндекс" "Readme"="REG_SZ", "" "Size"="REG_SZ", "" "SystemComponent"="REG_DWORD", 1 "UninstallString"="REG_EXPAND_SZ, "MsiExec.exe /X{FABA89D9-D588-4770-9F85-F6FF9F064257}" "URLInfoAbout"="REG_SZ", "" "URLUpdateInfo"="REG_SZ", "http://bm.yandex.ru/" "Version"="REG_DWORD", 50331654 "VersionMajor"="REG_DWORD", 3 "VersionMinor"="REG_DWORD", 0 "WindowsInstaller"="REG_DWORD", 1 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "https://www.yandex.ru/?win=345&clid=2323969-3" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] "DisplayName" = REG_SZ, "Яндекс" REG_SZ, "http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IENTSR" ==> REG_SZ, "https://yandex.ru/search/?win=345&clid=2323972-3&text={searchTerms}" "SuggestionsURL_JSON"="REG_SZ", "https://suggest.yandex.ru/suggest-ff.cgi?uil=ru&part={searchTerms}" "URL" ==> REG_SZ, "https://yandex.ru/search/?win=345&clid=2323970-3&text={searchTerms}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "Browser Manager"="REG_SZ", "C:\Users\{username}\AppData\Local\Yandex\BrowserManager\MBLauncher.exe" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{d4bb3741-07a4-443a-8c73-0cfda821c697}] "BundleAddonCode"="REG_MULTI_SZ, "" "BundleCachePath"="REG_SZ", "C:\Users\{username}\AppData\Local\Package Cache\{d4bb3741-07a4-443a-8c73-0cfda821c697}\BrowserManagerInstaller.exe" "BundleDetectCode"="REG_MULTI_SZ, "" "BundlePatchCode"="REG_MULTI_SZ, "" "BundleProviderKey"="REG_SZ", "{d4bb3741-07a4-443a-8c73-0cfda821c697}" "BundleTag"="REG_SZ", "" "BundleUpgradeCode"="REG_MULTI_SZ, "{CEADE967-2D56-4D80-A02E-CD3D762C0A3D} " "BundleVersion"="REG_SZ", "3.0.6.829" "DisplayIcon"="REG_SZ", "C:\Users\{username}\AppData\Local\Package Cache\{d4bb3741-07a4-443a-8c73-0cfda821c697}\BrowserManagerInstaller.exe,0" "DisplayName"="REG_SZ", "Менеджер браузеров" "DisplayVersion"="REG_SZ", "3.0.6.829" "EngineVersion"="REG_SZ", "3.8.2029.0" "EstimatedSize"="REG_DWORD", 15269 "HelpLink"="REG_SZ", "http://help.yandex.ru/bm/" "Installed"="REG_DWORD", 1 "ModifyPath"="REG_SZ", ""C:\Users\{username}\AppData\Local\Package Cache\{d4bb3741-07a4-443a-8c73-0cfda821c697}\BrowserManagerInstaller.exe" /modify" "NoElevateOnModify"="REG_DWORD", 1 "Publisher"="REG_SZ", "Яндекс" "QuietUninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Local\Package Cache\{d4bb3741-07a4-443a-8c73-0cfda821c697}\BrowserManagerInstaller.exe" /uninstall /quiet" "Resume"="REG_DWORD", 3 "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Local\Package Cache\{d4bb3741-07a4-443a-8c73-0cfda821c697}\BrowserManagerInstaller.exe" /uninstall" "URLInfoAbout"="REG_SZ", "bm.yandex.ru" "URLUpdateInfo"="REG_SZ", "bm.yandex.ru" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\YaPinLancher] "Contact"="REG_SZ", "http://feedback.yandex.ru" "DisplayIcon"="REG_SZ", "C:\Users\{username}1\AppData\Local\MICROS~1\INTERN~1\Services\WWWYAN~1.ICO" "DisplayName"="REG_SZ", "Yandex taskbar button" "DisplayVersion"="REG_SZ", "2.0.4.2157" "HelpLink"="REG_SZ", "http://help.yandex.ru/" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "Yandex" "UninstallString"="REG_SZ", "C:\Users\{username}\AppData\Local\Yandex\yapin\YandexWorking.exe --uninstall --nopinned" "URLInfoAbout"="REG_SZ", "http://legal.yandex.ru/desktop_software_agreement/" "URLUpdateInfo"="REG_SZ", "http://soft.yandex.ru/distribution/" [HKEY_CURRENT_USER\Software\Yandex\BM] "DistrLocale"="REG_SZ", "ru-ru" "ExePath"="REG_SZ", ""C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.exe"" [HKEY_CURRENT_USER\Software\Yandex\BM\Upgrader] "ModuleBrowsersProtection"="REG_SZ", "3.0.0.12" "ModuleChromium"="REG_SZ", "3.0.0.10" "ModuleDefaultBrowser"="REG_SZ", "3.0.0.10" "ModuleFirefox"="REG_SZ", "3.0.0.8" "ModuleGeo"="REG_SZ", "3.0.0.8" "ModuleHelper"="REG_SZ", "3.0.0.8" "ModuleHosts"="REG_SZ", "3.0.0.8" "ModuleInternetExplorer"="REG_SZ", "3.0.0.8" "ModuleOperaPresto"="REG_SZ", "3.0.0.8" "ModuleSecurity"="REG_SZ", "3.0.0.12" "ModuleSeederInteraction"="REG_SZ", "3.0.0.8" "ModuleShortcuts"="REG_SZ", "3.0.0.8" "ModuleUpgrader"="REG_SZ", "3.0.0.8" "ModuleVoodoo"="REG_SZ", "3.0.0.8" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/10/18 Scan Time: 9:21 AM Log File: f8469579-9c6d-11e8-8c7f-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6283 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 252649 Threats Detected: 83 Threats Quarantined: 83 Time Elapsed: 4 min, 6 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.exe, Quarantined, [777], [383595],1.0.6283 Module: 2 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\x64\SQLite.Interop.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.exe, Quarantined, [777], [383595],1.0.6283 Registry Key: 1 PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ablpcikjmhamjanpibkccdmpoekjigja, Quarantined, [291], [510332],1.0.6283 Registry Value: 1 PUP.Optional.BrowserManager, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Browser Manager, Quarantined, [777], [383595],1.0.6283 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 18 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\SeederTasks, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\settings, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\x64, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\x86, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\USERS\{username}\APPDATA\LOCAL\YANDEX\BROWSERMANAGER, Quarantined, [777], [383595],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\ru, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\tr, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\uk, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\contextLib, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_metadata, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\icons, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\lib, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\own, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\ablpcikjmhamjanpibkccdmpoekjigja, Quarantined, [291], [510332],1.0.6283 File: 60 PUP.Optional.RussAd, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\60L2DG92.DEFAULT-1519559592148\EXTENSIONS\SOVETNIK@METABAR.RU.XPI, Quarantined, [291], [312601],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\data_exchange, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\downloads, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\Events Protection, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\GeoSettings, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\hosts, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\scuts, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\security, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\settings, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\data\voodoo, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleHelper.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleBrowsersProtection.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleChromium.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleChromium.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleDefaultBrowser.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleFirefox.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleGeo.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleH.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleHosts.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleInternetExplorer.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleOperaPresto.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleSecurity.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleSecurity.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleSeederInteraction.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleShortcuts.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleVoodoo.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\ModuleYaB.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\modules\OfferModule.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\settings\hosts, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\x64\SQLite.Interop.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\x86\SQLite.Interop.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.Core.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.Core.UI.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\BrowserManager.exe, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\Crypto.Core.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\MBlauncher.exe, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\MBlauncher_x64.exe, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\ModuleUpgrader.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\ModuleUpgrader.dll.upgrade, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\NAudio.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\Newtonsoft.Json.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\NLog.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\RefCheck.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.BrowserManager, C:\Users\{username}\AppData\Local\Yandex\BrowserManager\System.Data.SQLite.dll, Quarantined, [777], [383595],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\contextLib\service.js, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\icons\128.png, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\icons\16.png, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\icons\48.png, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\lib\background.js, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\lib\cookies.js, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\own\var.js, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\ru\messages.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\tr\messages.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_locales\uk\messages.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_metadata\computed_hashes.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\_metadata\verified_contents.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ablpcikjmhamjanpibkccdmpoekjigja\2.0.4.15_0\manifest.json, Quarantined, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [291], [510332],1.0.6283 PUP.Optional.RussAd, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [291], [510332],1.0.6283 PUP.Optional.Appset, C:\USERS\{username}\DESKTOP\AFTER DEATH.EXE, Quarantined, [4804], [550763],1.0.6283 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  6. What is Incognito Searches?The Malwarebytes research team has determined that Incognito Searches is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by Incognito Searches?You may see this entry in your list of installed Chrome extensions:and these warnings during install:this changed setting:and you will see this icon in your Chrome menu-bar:How did Incognito Searches get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their website:but it's alos available in the webstore:How do I remove Incognito Searches?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Incognito Searches? No, Malwarebytes removes Incognito Searches completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the Incognito Searches hijacker. It would have blocked the website promoting the extension, giving you a chance to stop it before it became too late. Technical details for expertsPossible signs in FRST logs: CHR DefaultSearchURL: Default -> hxxp://feed.incognitosearches.com/?q={searchTerms}&publisher=searchprivate&barcodeid=523120000000000 CHR DefaultSearchKeyword: Default -> IncognitoSearches Search CHR DefaultSuggestURL: Default -> hxxp://suggest.incognitosearches.com/suggest/get?q={searchTerms} CHR Extension: (IncognitoSearches Search) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef [2018-08-09] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0 Adds the file closer.js"="9/13/2017 11:07 AM, 15 bytes, A Adds the file manifest.json"="8/9/2018 9:30 AM, 2385 bytes, A Adds the file popup.html"="3/7/2018 2:07 PM, 503 bytes, A Adds the file tab.html"="9/13/2017 11:07 AM, 165 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\_metadata Adds the file computed_hashes.json"="8/9/2018 9:30 AM, 2402 bytes, A Adds the file verified_contents.json"="4/23/2018 2:34 PM, 2829 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images Adds the file incognito.png"="9/19/2017 7:26 AM, 3050 bytes, A Adds the file logo.png"="9/19/2017 7:26 AM, 3836 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\icons Adds the file 128x128.png"="8/9/2018 9:30 AM, 4559 bytes, A Adds the file 16x16.png"="8/9/2018 9:30 AM, 732 bytes, A Adds the file 64x64.png"="8/9/2018 9:30 AM, 3111 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts Adds the file background.js"="4/23/2018 2:50 PM, 28139 bytes, A Adds the file jquery-3.3.1.min.js"="3/7/2018 2:07 PM, 86927 bytes, A Adds the file popup.js"="9/19/2017 7:26 AM, 659 bytes, A Adds the file sitecontent.js"="9/19/2017 7:26 AM, 77 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\styles Adds the file popup.css"="9/19/2017 7:26 AM, 561 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mclkncgplnlincdikfegcbbgjcaodpef Adds the file Incognito Searches.ico"="8/9/2018 9:30 AM, 176596 bytes, A Adds the file Incognito Searches.ico.md5"="8/9/2018 9:30 AM, 16 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "mclkncgplnlincdikfegcbbgjcaodpef"="REG_SZ", "112DD3A257EF6906C7830F2CB81557B69966E98E04B401CBAD13D087CFCFCCB8" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/9/18 Scan Time: 9:35 AM Log File: d4689f1a-9ba6-11e8-a48e-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6263 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251930 Threats Detected: 25 Threats Quarantined: 25 Time Elapsed: 3 min, 34 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\icons, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\_metadata, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\styles, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MCLKNCGPLNLINCDIKFEGCBBGJCAODPEF, Quarantined, [1684], [443158],1.0.6263 File: 18 PUP.Optional.SearchIncognito, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\MCLKNCGPLNLINCDIKFEGCBBGJCAODPEF\1.0.6_0\MANIFEST.JSON, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\icons\128x128.png, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\icons\16x16.png, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\icons\64x64.png, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\incognito.png, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\images\logo.png, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts\background.js, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts\jquery-3.3.1.min.js, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts\popup.js, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\scripts\sitecontent.js, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\styles\popup.css, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\_metadata\computed_hashes.json, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\_metadata\verified_contents.json, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\closer.js, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\popup.html, Quarantined, [1684], [443158],1.0.6263 PUP.Optional.SearchIncognito, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\mclkncgplnlincdikfegcbbgjcaodpef\1.0.6_0\tab.html, Quarantined, [1684], [443158],1.0.6263 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  7. What is Online Privacy?The Malwarebytes research team has determined that Online Privacy is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by Online Privacy?You may see this entry in your list of installed Firefox add-ons:and these warnings during install:How did Online Privacy get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was offered as an upgrade after a redirect:How do I remove Online Privacy?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Online Privacy? No, Malwarebytes removes Online Privacy completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the Online Privacy hijacker. It would have warned you before the website could load, giving you a chance to stop it before it became too late. Or if you were using the Malwarebytes Browser extension for Firefox it would have stopped the website even before the domain was added to our database: Technical details for expertsPossible signs in FRST logs: FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{default}.profile\Extensions\privacypro@mybestprivacy.com.xpi [2018-08-08] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{default}.profile\browser-extension-data\privacypro@mybestprivacy.com Adds the file storage.js"="8/8/2018 9:02 AM, 48 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{default}.profile\extensions Adds the file privacypro@mybestprivacy.com.xpi"="8/8/2018 9:02 AM, 10132 bytes, A Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/8/18 Scan Time: 9:11 AM Log File: 496ac7e9-9ada-11e8-9399-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6247 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251386 Threats Detected: 1 Threats Quarantined: 1 Time Elapsed: 3 min, 19 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 1 PUP.Optional.PrivacyPro, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{default}.profile\EXTENSIONS\PRIVACYPRO@MYBESTPRIVACY.COM.XPI, Quarantined, [4657], [549763],1.0.6247 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  8. What is MapsGalaxy?The Malwarebytes research team has determined that MapsGalaxy is a browser NewTab. These so-called "NewTabs" can manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice.MapsGalaxy is a member of the Mindspark/Ask family now known as IAC Applications.How do I know if my computer is affected by MapsGalaxy?You may see these browser extensions/add-ons:these warnings during install:You may see this entry in your list of installed software:and this new homepage in the affected browsers:How did MapsGalaxy get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their website.How do I remove MapsGalaxy?Our program Malwarebytes can detect and remove this potentially unwanted program.You can use their own uninstall instructions first, but I would advise to follow the steps below anyway. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of MapsGalaxy? If you are using an older version of Malwarebytes, you may have to remove the Chrome extension manually under Tools > More Tools > Extensions. Click on the bin behind the MapsGalaxy entry and confirm Remove in the prompt. If your browsers have been hijacked, you should read our Restore Browser page. You can read there how to fix additional browser redirect methods. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the MapsGalaxy hijacker. It would have warned you before the hijacker could install itself, giving you a chance to stop it before it became too late. and it blocks traffic to their domains: Technical details for expertsPossible signs in a FRST log: HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp.myway.com/mapsgalaxy/ttab02/index.html?n={n}&p2={p2}&ptb={ptb}&coid={coid} FF Homepage: moz-extension://a7a4f4e0-d8bc-4b9b-b0ba-1639bf175198/dynamicHomePage.html FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\_39Members_@www.mapsgalaxy.com.xpi [2018-08-07] CHR Extension: (MapsGalaxy) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm [2018-08-07] C:\Users\{username}\AppData\Local\MapsGalaxyTooltab MapsGalaxy Internet Explorer Homepage and New Tab (HKCU\...\MapsGalaxyTooltab Uninstall Internet Explorer) (Version: - Mindspark Interactive Network, Inc.) <==== ATTENTION Significant changes made by the installers: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0 Adds the file manifest.json"="8/7/2018 10:47 AM, 2458 bytes, A Adds the file newtabproduct.html"="6/7/2018 10:22 AM, 1136 bytes, A Adds the file stubby.html"="6/7/2018 10:22 AM, 1137 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\_metadata Adds the file computed_hashes.json"="8/7/2018 10:47 AM, 4096 bytes, A Adds the file verified_contents.json"="6/7/2018 10:22 AM, 4879 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\config Adds the file config.json"="6/7/2018 10:22 AM, 1733 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons Adds the file icon128.png"="8/7/2018 10:47 AM, 21746 bytes, A Adds the file icon16.png"="6/7/2018 10:22 AM, 1315 bytes, A Adds the file icon19disabled.png"="6/7/2018 10:22 AM, 1388 bytes, A Adds the file icon19on.png"="8/7/2018 10:47 AM, 961 bytes, A Adds the file icon48.png"="8/7/2018 10:47 AM, 5280 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js Adds the file ajax.js"="6/7/2018 10:22 AM, 2250 bytes, A Adds the file background.js"="6/7/2018 10:22 AM, 21002 bytes, A Adds the file chrome.js"="6/7/2018 10:22 AM, 180 bytes, A Adds the file content_script.js"="6/7/2018 10:22 AM, 5815 bytes, A Adds the file dlp.js"="6/7/2018 10:22 AM, 5690 bytes, A Adds the file dlpHelper.js"="6/7/2018 10:22 AM, 1836 bytes, A Adds the file extension_detect.js"="6/7/2018 10:22 AM, 4343 bytes, A Adds the file genericLoadRemoteSettings.js"="6/7/2018 10:22 AM, 2908 bytes, A Adds the file index.js"="6/7/2018 10:22 AM, 82 bytes, A Adds the file initOfferCEF.js"="6/7/2018 10:22 AM, 8842 bytes, A Adds the file logger.js"="6/7/2018 10:22 AM, 575 bytes, A Adds the file offerService.js"="6/7/2018 10:22 AM, 13159 bytes, A Adds the file pageUtils.js"="6/7/2018 10:22 AM, 1811 bytes, A Adds the file PartnerId.js"="6/7/2018 10:22 AM, 16439 bytes, A Adds the file product.js"="6/7/2018 10:22 AM, 4511 bytes, A Adds the file storage.js"="6/7/2018 10:22 AM, 1675 bytes, A Adds the file TabManager.js"="6/7/2018 10:22 AM, 189 bytes, A Adds the file TemplateParser.js"="6/7/2018 10:22 AM, 3080 bytes, A Adds the file ul.js"="6/7/2018 10:22 AM, 3862 bytes, A Adds the file urlFragmentActions.js"="6/7/2018 10:22 AM, 2521 bytes, A Adds the file urlUtils.js"="6/7/2018 10:22 AM, 5385 bytes, A Adds the file util.js"="6/7/2018 10:22 AM, 3235 bytes, A Adds the file webtooltabAPI.js"="6/7/2018 10:22 AM, 8762 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm Adds the file 000003.log"="8/7/2018 10:51 AM, 5065 bytes, A Adds the file CURRENT"="8/7/2018 10:47 AM, 16 bytes, A Adds the file LOCK"="8/7/2018 10:47 AM, 0 bytes, A Adds the file LOG"="8/7/2018 10:51 AM, 412 bytes, A Adds the file LOG.old"="8/7/2018 10:47 AM, 185 bytes, A Adds the file MANIFEST-000001"="8/7/2018 10:47 AM, 41 bytes, A Adds the folder C:\Users\{username}\AppData\Local\MapsGalaxyTooltab Adds the file TooltabExtension.dll"="5/18/2018 2:48 AM, 273008 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\browser-extension-data\_39Members_@www.mapsgalaxy.com Adds the file storage.js"="8/7/2018 10:51 AM, 2465 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file _39Members_@www.mapsgalaxy.com.xpi"="8/7/2018 10:46 AM, 76061 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "cpjbkhbhimkbbekiaelopeddeheljabm"="REG_SZ", "1B5E475DC1D93D437EF5C57355445F2BAC569314B2518A5E2DD35F096B2D9275" [HKEY_CURRENT_USER\Software\MapsGalaxy] "Start Page"="REG_SZ", "http://hp.myway.com/mapsgalaxy/ttab02/index.html?n={n}&p2={ptb1}&ptb={ptb}&coid={coid}" "UnInstallSurveyUrl"="REG_SZ", "http://@{downloadDomain}.dl.myway.com/uninstall.jhtml?surveyUrl=https%3A%2F%2Fwww.research.net%2Fr%2FZC5XFLJ%3Fc%3D{ptb}%26ptb%3D{ptb1}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" = REG_SZ, "http://hp.myway.com/mapsgalaxy/ttab02/index.html?n={n}&p2={p2}&ptb={ptb}&coid={coid}" [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\MapsGalaxyTooltab Uninstall Internet Explorer] "DisplayName"="REG_SZ", "MapsGalaxy Internet Explorer Homepage and New Tab" "HelpLink"="REG_SZ", "http://support.mindspark.com/" "Publisher"="REG_SZ", "Mindspark Interactive Network, Inc." "UninstallString"="REG_SZ", "Rundll32.exe "C:\Users\{username}\AppData\Local\MapsGalaxyTooltab\TooltabExtension.dll" U uninstall:MapsGalaxy" "URLInfoAbout"="REG_SZ", "http://support.mindspark.com/" The Malwarebytes scan log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/7/18 Scan Time: 10:57 AM Log File: e1ed92d7-9a1f-11e8-ae50-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6235 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 252250 Threats Detected: 62 Threats Quarantined: 62 Time Elapsed: 3 min, 32 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 1 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MapsGalaxyTooltab\TooltabExtension.dll, Quarantined, [1688], [356944],1.0.6235 Registry Key: 2 PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MapsGalaxyTooltab Uninstall Internet Explorer, Quarantined, [1688], [356944],1.0.6235 PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MapsGalaxy, Quarantined, [1688], [444113],1.0.6235 Registry Value: 2 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\MapsGalaxyTooltab Uninstall Internet Explorer|PUBLISHER, Quarantined, [541], [352442],1.0.6235 PUP.Optional.MindSpark.Generic, HKCU\SOFTWARE\MapsGalaxy|START PAGE, Quarantined, [1688], [444113],1.0.6235 Registry Data: 1 PUP.Optional.MindSpark, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, Replaced, [541], [293497],1.0.6235 Data Stream: 0 (No malicious items detected) Folder: 9 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MapsGalaxyTooltab, Quarantined, [1688], [356944],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\BROWSER-EXTENSION-DATA\_39Members_@www.mapsgalaxy.com, Quarantined, [1688], [468075],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\_metadata, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\config, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CPJBKHBHIMKBBEKIAELOPEDDEHELJABM\13.651.13.21587_0, Quarantined, [1688], [456842],1.0.6235 File: 47 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\MapsGalaxyTooltab\TooltabExtension.dll, Quarantined, [1688], [356944],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\EXTENSIONS\_39Members_@www.mapsgalaxy.com.xpi, Quarantined, [1688], [457930],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\browser-extension-data\_39Members_@www.mapsgalaxy.com\storage.js, Quarantined, [1688], [468075],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\000003.log, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\CURRENT, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\LOCK, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\LOG, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\LOG.old, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpjbkhbhimkbbekiaelopeddeheljabm\MANIFEST-000001, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\CPJBKHBHIMKBBEKIAELOPEDDEHELJABM\13.651.13.21587_0\CONFIG\CONFIG.JSON, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons\icon128.png, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons\icon16.png, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons\icon19disabled.png, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons\icon19on.png, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\icons\icon48.png, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\ajax.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\background.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\chrome.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\content_script.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\dlp.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\dlpHelper.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\extension_detect.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\genericLoadRemoteSettings.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\index.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\initOfferCEF.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\logger.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\offerService.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\pageUtils.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\PartnerId.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\product.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\storage.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\TabManager.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\TemplateParser.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\ul.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\urlFragmentActions.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\urlUtils.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\util.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\js\webtooltabAPI.js, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\_metadata\computed_hashes.json, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\_metadata\verified_contents.json, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\manifest.json, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\newtabproduct.html, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjbkhbhimkbbekiaelopeddeheljabm\13.651.13.21587_0\stubby.html, Quarantined, [1688], [456842],1.0.6235 PUP.Optional.MindSpark, C:\USERS\{username}\DESKTOP\MAPSGALAXY.EXE, Quarantined, [541], [365288],1.0.6235 PUP.Optional.MindSpark, C:\DOWNLOADS\MAPSGALAXY.EXE, Quarantined, [541], [365288],1.0.6235 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  9. What is Auto Speedup 2018?The Malwarebytes research team has determined that Auto Speedup 2018 is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.More information can be found on our Malwarebytes Labs blog.How do I know if I am infected with Auto Speedup 2018?This is how the main screen of the system optimizer looks:You will find these icons in your taskbar, your startmenu, and on your desktop:and see these warnings during install:and this type of screen during "operations":You may see this entry in your list of installed programs:and this task in your list of Scheduled Tasks:How did Auto Speedup 2018 get on my computer?These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:How do I remove Auto Speedup 2018?Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Auto Speedup 2018? No, Malwarebytes removes Auto Speedup 2018 completely. This PUP creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this system optimizer.As you can see below the full version of Malwarebytes would have protected you against the Auto Speedup 2018 installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain: Technical details for expertsYou may see these entries in FRST logs: () C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername} C:\Windows\System32\Tasks\Auto Speed~Up 2018_Logon C:\Users\Public\Desktop\Auto Speed~Up 2018.lnk C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto Speed~Up 2018 for {computername} C:\ProgramData\Auto Speed~Up 2018 for {computername} C:\Program Files\Auto Speed~Up 2018 for {computername} Auto Speed~Up 2018 (HKLM\...\{7E2A1CC9-F4EA-4A56-BFED-116B0222873C}_is1) (Version: 1.0.3.5 - ) Task: {4DABAF6B-7757-4E9E-B989-4051C82667CF} - System32\Tasks\Auto Speed~Up 2018_Logon => C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe [2018-07-30] () Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files\Auto Speed~Up 2018 for {computername} Adds the file application.ico"="7/12/2018 1:32 PM, 94222 bytes, A Adds the file danish_iss.ini"="5/16/2018 11:25 AM, 2402 bytes, A Adds the file Dutch_iss.ini"="5/16/2018 11:25 AM, 2600 bytes, A Adds the file english_iss.ini"="5/16/2018 11:25 AM, 2256 bytes, A Adds the file finish_iss.ini"="5/16/2018 11:25 AM, 2368 bytes, A Adds the file French_iss.ini"="5/16/2018 11:25 AM, 2792 bytes, A Adds the file german_iss.ini"="5/16/2018 11:25 AM, 2658 bytes, A Adds the file gtcmg.dll"="7/30/2018 5:53 PM, 1919912 bytes, A Adds the file HtmlRenderer.dll"="7/30/2018 5:53 PM, 228264 bytes, A Adds the file HtmlRenderer.WinForms.dll"="7/30/2018 5:53 PM, 66984 bytes, A Adds the file Interop.IWshRuntimeLibrary.dll"="7/30/2018 5:53 PM, 55720 bytes, A Adds the file italian_iss.ini"="5/16/2018 11:25 AM, 2532 bytes, A Adds the file japanese_iss.ini"="5/16/2018 11:25 AM, 1844 bytes, A Adds the file langs.db"="5/16/2018 2:50 PM, 449536 bytes, A Adds the file Microsoft.Win32.TaskScheduler.dll"="7/30/2018 5:53 PM, 177576 bytes, A Adds the file NAudio.dll"="7/30/2018 5:53 PM, 477608 bytes, A Adds the file Newtonsoft.Json.dll"="7/30/2018 5:53 PM, 467368 bytes, A Adds the file norwegian_iss.ini"="5/16/2018 11:25 AM, 2358 bytes, A Adds the file PaddleCheckoutSDK.dll"="7/30/2018 5:53 PM, 61864 bytes, A Adds the file portuguese_iss.ini"="5/16/2018 11:25 AM, 2424 bytes, A Adds the file rclr.exe"="7/30/2018 5:53 PM, 2702496 bytes, A Adds the file rclr.exe.config"="7/30/2018 5:52 PM, 5959 bytes, A Adds the file russian_iss.ini"="5/16/2018 11:25 AM, 2494 bytes, A Adds the file spanish_iss.ini"="5/16/2018 11:25 AM, 2548 bytes, A Adds the file swedish_iss.ini"="5/16/2018 11:25 AM, 2270 bytes, A Adds the file System.Data.SQLite.DLL"="7/30/2018 5:53 PM, 297384 bytes, A Adds the file TAFactory.IconPack.dll"="7/30/2018 5:53 PM, 43432 bytes, A Adds the file unins000.dat"="8/6/2018 8:54 AM, 84961 bytes, A Adds the file unins000.exe"="8/6/2018 8:53 AM, 1273256 bytes, A Adds the file unins000.msg"="8/6/2018 8:54 AM, 22701 bytes, A Adds the folder C:\Program Files\Auto Speed~Up 2018 for {computername}\x64 Adds the file SQLite.Interop.dll"="7/30/2018 5:53 PM, 1182120 bytes, A Adds the folder C:\Program Files\Auto Speed~Up 2018 for {computername}\x86 Adds the file SQLite.Interop.dll"="7/30/2018 5:53 PM, 861096 bytes, A Adds the folder C:\ProgramData\Auto Speed~Up 2018 for {computername} Adds the file mdb.db"="5/16/2018 11:25 AM, 835584 bytes, A Adds the file pcspstartrepair_en.mp3"="5/16/2018 11:25 AM, 130973 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto Speed~Up 2018 for {computername} Adds the file Auto Speed~Up 2018.lnk"="8/6/2018 8:54 AM, 995 bytes, A Adds the file Buy Auto Speed~Up 2018.lnk"="8/6/2018 8:54 AM, 1007 bytes, A Adds the file Uninstall Auto Speed~Up 2018.lnk"="8/6/2018 8:54 AM, 1019 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername} Adds the file Errorlog.txt"="8/6/2018 8:56 AM, 14614 bytes, A Adds the file exlist.bin"="8/6/2018 8:54 AM, 257997 bytes, A Adds the file notifier.xml"="8/6/2018 8:54 AM, 11564 bytes, A Adds the file param.ini"="8/6/2018 8:54 AM, 424 bytes, A Adds the file pplan.xml"="8/6/2018 8:54 AM, 668 bytes, A Adds the file res.xml"="8/6/2018 8:55 AM, 9798 bytes, A Adds the file update.xml"="8/6/2018 8:54 AM, 32744 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\smico In the existing folder C:\Users\Public\Desktop Adds the file Auto Speed~Up 2018.lnk"="8/6/2018 8:54 AM, 977 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Auto Speed~Up 2018_Logon"="8/6/2018 8:54 AM, 3080 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Auto Speed~Up 2018 For {computername}] "affired"="REG_DWORD", 1 "afterInstallUrl"="REG_SZ", "http://ins.alfactiv.com/install/pca/?" "apst"="REG_DWORD", 0 "btnid"="REG_SZ", "" "buybowinapp"="REG_SZ", "http://store.pcbooster.pw/pca/plan?" "cbkpoff"="REG_DWORD", 1 "country"="REG_SZ", "nl" "cta"="REG_DWORD", 0 "delaytime"="REG_DWORD", 0 "dlllist"="REG_SZ", "PSMACHINE_64.DLL,MSSPELLCHECKINGFACILITY.DLL" "EmailURL"="REG_SZ", "" "expired"="REG_DWORD", 0 "hdata"="REG_BINARY, ......................................................................................................................................................................................................................................................................................................................................... "Installstring"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}" "ipaddrurl"="REG_SZ", "http://www.alfactiv.com/getip/" "isavst"="REG_DWORD", 0 "isiunidu"="REG_DWORD", 0 "isprmjsn"="REG_DWORD", 0 "isshowng"="REG_DWORD", 1 "issilent"="REG_DWORD", 0 "ISTELNO"="REG_DWORD", 1 "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "lstregscancount"="REG_DWORD", 24 "lstscandate"="REG_SZ", "8/6/2018 8:55:00 AM" "lstscanstat"="REG_DWORD", 2 "lstsecscancount"="REG_DWORD", 0 "lsttotalscancount"="REG_DWORD", 24 "ovoffdis"="REG_DWORD", 0 "paramurl"="REG_SZ", "http://trkr.alfactiv.com/ipfiles/" "pdtm"="REG_DWORD", 30 "playsound"="REG_DWORD", 1 "plurl"="REG_SZ", "http://pp.alfactiv.com/ProductPrice.svc/" "prereg"="REG_DWORD", 0 "PurchaseURL"="REG_SZ", "https://store.pcbooster.pw/pca/price?" "pxl"="REG_SZ", "AVP3532_AVP3460_RUNT" "referurl"="REG_SZ", "" "reg"="REG_DWORD", 0 "RenewURL"="REG_SZ", "https://store.pcbooster.pw/pca/renewal?" "runcam"="REG_DWORD", 1 "runpixel"="REG_DWORD", 1 "runsrc"="REG_DWORD", 1 "showtn"="REG_DWORD", 0 "showunins"="REG_DWORD", 0 "showwfo"="REG_DWORD", 0 "stdismax"="REG_DWORD", -1 "supporturl"="REG_SZ", "http://www.pcbooster.pw/help/" "TELNO"="REG_SZ", "085 888 7056" "TELNO_ar"="REG_SZ", "+54 11 5236 0324" "TELNO_at"="REG_SZ", "+43 (0)720 902 309" "TELNO_au"="REG_SZ", "(61)280-733403" "TELNO_be"="REG_SZ", "+32-28085306" "TELNO_br"="REG_SZ", "+55 21 2391 4319" "TELNO_ch"="REG_SZ", "+41 (0)44 508 70 37" "TELNO_de"="REG_SZ", "0800 1822 974" "TELNO_dk"="REG_SZ", "+45 78 73 09 26" "TELNO_es"="REG_SZ", "+34 951 203 537" "TELNO_fi"="REG_SZ", "+358 (0)9 4270 4911" "TELNO_fr"="REG_SZ", "05 82 84 04 06" "TELNO_gb"="REG_SZ", "0800-031-5066" "TELNO_it"="REG_SZ", "+39 069 4802886" "TELNO_ja"="REG_SZ", "" "TELNO_lu"="REG_SZ", "0800 1822 974" "TELNO_nl"="REG_SZ", "085 888 7056" "TELNO_no"="REG_SZ", "+47 21 95 01 97" "TELNO_pt"="REG_SZ", "+351 70 750 2094" "TELNO_se"="REG_SZ", "+46-08124-10298" "TELNO_uk"="REG_SZ", "0800-031-5066" "TELNO_us"="REG_SZ", "(855)-332-0124" "utm_campaign"="REG_SZ", "avpcrpalf" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "c8814a99-5c17-41bd-8169-ac419ec68c5e" "utm_source"="REG_SZ", "avpcrpalf" "WebURL"="REG_SZ", "https://www.pcbooster.pw/" "wfoset"="REG_DWORD", 1 "x-at"="REG_SZ", "GHIGHId77O83CGC7EK05OF1DSKUP32" "x-ccode"="REG_SZ", "nl" "x-context"="REG_SZ", "d77O83CGC7EK05OF1DSKUP32" "x-datetime"="REG_SZ", "08-06-2018 06:54:21 AM" "x-fetch"="REG_SZ", "1" "x-ip"="REG_SZ", "90_145_230_242" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7E2A1CC9-F4EA-4A56-BFED-116B0222873C}_is1] "DisplayIcon"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe" "DisplayName"="REG_SZ", "Auto Speed~Up 2018" "DisplayVersion"="REG_SZ", "1.0.3.5" "EstimatedSize"="REG_DWORD", 12971 "Inno Setup: App Path"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}" "Inno Setup: Icon Group"="REG_SZ", "Auto Speed~Up 2018 for {computername}" "Inno Setup: Language"="REG_SZ", "en" "Inno Setup: Setup Version"="REG_SZ", "5.5.8 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20180806" "InstallLocation"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Program Files\Auto Speed~Up 2018 for {computername}\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files\Auto Speed~Up 2018 for {computername}\unins000.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\QXV0byBTcGVlZH5VcCAyMDE4\ACT] "data"="REG_BINARY, ................................................................................................................................................................................................................................................................................................................................................................................................................................ [HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr] "affiliateid"="REG_SZ", "" "btnid"="REG_SZ", "" "country"="REG_SZ", "nl" "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "pxl"="REG_SZ", "AVP3532_AVP3460_RUNT" "referUrl"="REG_SZ", "" "TELNO"="REG_SZ", "" "utm_campaign"="REG_SZ", "avpcrpalf" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "c8814a99-5c17-41bd-8169-ac419ec68c5e" "utm_source"="REG_SZ", "avpcrpalf" "x-at"="REG_SZ", "GHIGHId77O83CGC7EK05OF1DSKUP32" "x-context"="REG_SZ", "d77O83CGC7EK05OF1DSKUP32" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_CURRENT_USER\Software\Auto Speed~Up 2018 for {computername}] "btnid"="REG_SZ", "" "InstallString"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}" "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "pxl"="REG_SZ", "AVP3532_AVP3460_RUNT" "referurl"="REG_SZ", "" "TELNO"="REG_SZ", "085 888 7056" "TELNO_nl"="REG_SZ", "085 888 7056" "utm_campaign"="REG_SZ", "avpcrpalf" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "c8814a99-5c17-41bd-8169-ac419ec68c5e" "utm_source"="REG_SZ", "avpcrpalf" "x-at"="REG_SZ", "GHIGHId77O83CGC7EK05OF1DSKUP32" "x-context"="REG_SZ", "d77O83CGC7EK05OF1DSKUP32" "x-datetime"="REG_SZ", "08-06-2018 06:54:21 AM" "x-fetch"="REG_SZ", "1" "x-ip"="REG_SZ", "90_145_230_242" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_CURRENT_USER\Software\Auto Speed~Up 2018 for {computername}\1.0.3.5] "Installstring"="REG_SZ", "C:\Program Files\Auto Speed~Up 2018 for {computername}" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/6/18 Scan Time: 9:06 AM Log File: 40b0eacd-9947-11e8-b990-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6219 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251428 Threats Detected: 77 Threats Quarantined: 77 Time Elapsed: 3 min, 33 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe, Quarantined, [417], [548193],1.0.6219 Module: 7 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\PaddleCheckoutSDK.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [417], [548193],1.0.6219 Registry Key: 8 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Auto Speed~Up 2018_Logon, Quarantined, [417], [548203],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4DABAF6B-7757-4E9E-B989-4051C82667CF}, Quarantined, [417], [548203],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{4DABAF6B-7757-4E9E-B989-4051C82667CF}, Quarantined, [417], [548203],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E2A1CC9-F4EA-4A56-BFED-116B0222873C}_is1, Quarantined, [417], [548193],1.0.6219 PUP.Optional.Jawego, HKLM\SOFTWARE\QXV0byBTcGVlZH5VcCAyMDE4, Quarantined, [521], [534889],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR, Quarantined, [417], [540842],1.0.6219 PUP.Optional.PCVARK, HKCU\SOFTWARE\Auto Speed~Up 2018 for {computername}, Quarantined, [417], [548199],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\Auto Speed~Up 2018 For {computername}, Quarantined, [417], [548198],1.0.6219 Registry Value: 6 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{4DABAF6B-7757-4E9E-B989-4051C82667CF}|PATH, Quarantined, [417], [548201],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{7E2A1CC9-F4EA-4A56-BFED-116B0222873C}_is1|DISPLAYNAME, Quarantined, [417], [548200],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR|AFFILIATEID, Quarantined, [417], [540842],1.0.6219 PUP.Optional.MasterPCCleaner, HKLM\SOFTWARE\SCD-PR|PXL, Quarantined, [1116], [484510],1.0.6219 PUP.Optional.PCVARK, HKCU\SOFTWARE\Auto Speed~Up 2018 for {computername}|TELNO, Quarantined, [417], [548199],1.0.6219 PUP.Optional.PCVARK, HKLM\SOFTWARE\Auto Speed~Up 2018 For {computername}|AFFIRED, Quarantined, [417], [548198],1.0.6219 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.PCVARK, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Auto Speed~Up 2018 for {computername}, Quarantined, [417], [548194],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\smico, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\USERS\{username}\APPDATA\ROAMING\Auto Speed~Up 2018 For {computername}, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\PROGRAMDATA\Auto Speed~Up 2018 for {computername}, Quarantined, [417], [548195],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\x64, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\x86, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\PROGRAM FILES\Auto Speed~Up 2018 for {computername}, Quarantined, [417], [548193],1.0.6219 File: 48 PUP.Optional.PCVARK, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Auto Speed~Up 2018 for {computername}\Buy Auto Speed~Up 2018.lnk, Quarantined, [417], [548194],1.0.6219 PUP.Optional.PCVARK, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto Speed~Up 2018 for {computername}\Auto Speed~Up 2018.lnk, Quarantined, [417], [548194],1.0.6219 PUP.Optional.PCVARK, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auto Speed~Up 2018 for {computername}\Uninstall Auto Speed~Up 2018.lnk, Quarantined, [417], [548194],1.0.6219 PUP.Optional.PCVARK, C:\USERS\{username}\APPDATA\ROAMING\Auto Speed~Up 2018 For {computername}\Errorlog.txt, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\exlist.bin, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\notifier.xml, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\param.ini, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\pplan.xml, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\res.xml, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Auto Speed~Up 2018 For {computername}\update.xml, Quarantined, [417], [548196],1.0.6219 PUP.Optional.PCVARK, C:\WINDOWS\SYSTEM32\TASKS\Auto Speed~Up 2018_Logon, Quarantined, [417], [548203],1.0.6219 PUP.Optional.PCVARK, C:\PROGRAMDATA\Auto Speed~Up 2018 for {computername}\mdb.db, Quarantined, [417], [548195],1.0.6219 PUP.Optional.PCVARK, C:\ProgramData\Auto Speed~Up 2018 for {computername}\pcspstartrepair_en.mp3, Quarantined, [417], [548195],1.0.6219 PUP.Optional.PCVARK, C:\PROGRAM FILES\Auto Speed~Up 2018 for {computername}\unins000.dat, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\x86\SQLite.Interop.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\application.ico, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\danish_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Dutch_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\english_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\finish_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\French_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\german_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\gtcmg.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\HtmlRenderer.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\HtmlRenderer.WinForms.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\italian_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\japanese_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\langs.db, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\NAudio.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\Newtonsoft.Json.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\norwegian_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\PaddleCheckoutSDK.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\portuguese_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\rclr.exe.config, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\russian_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\spanish_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\swedish_iss.ini, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\unins000.exe, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\Program Files\Auto Speed~Up 2018 for {computername}\unins000.msg, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Auto Speed~Up 2018.lnk, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\USERS\PUBLIC\DESKTOP\Auto Speed~Up 2018.lnk, Quarantined, [417], [548193],1.0.6219 PUP.Optional.PCVARK, C:\USERS\{username}\DESKTOP\ATSPSETUP.EXE, Quarantined, [417], [548206],1.0.6219 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  10. What is SocialNewPages?The Malwarebytes research team has determined that SocialNewPages is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by SocialNewPages?You may see these browser add-ons:these warnings during install:and these changed settingsHow did SocialNewPages get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was downloaded from their website:How do I remove SocialNewPages?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of SocialNewPages? No, Malwarebytes removes SocialNewPages completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the SocialNewPages hijacker. It would have blocked the website pushing the extensions, giving you a chance to stop it before it became too late. Technical details for expertsPossible signs in FRST logs: FF Extension: No Name - C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\Extensions\{230a5283-ab42-49a2-8860-b06d797917c7}.xpi [2018-08-03] CHR Extension: (SocialNewPages) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe [2018-08-03] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0 Adds the file background.js"="1/25/2017 1:44 PM, 4144 bytes, A Adds the file logo.png"="8/3/2018 8:57 AM, 31081 bytes, A Adds the file manifest.json"="8/3/2018 8:57 AM, 1082 bytes, A Adds the file redirect.html"="10/26/2016 12:11 PM, 52 bytes, A Adds the file redirect.js"="11/7/2016 2:10 PM, 718 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\_metadata Adds the file computed_hashes.json"="8/3/2018 8:57 AM, 395 bytes, A Adds the file verified_contents.json"="1/25/2017 1:44 PM, 1737 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\{profile}.default\extensions Adds the file {230a5283-ab42-49a2-8860-b06d797917c7}.xpi"="8/3/2018 8:58 AM, 62429 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "ipmhhojdlfeeiefkadleefbjgjkemjoe"="REG_SZ", "D3BFCAC44B23A1F5E82D967D1885B9F17204869E42254B5156E6F5B7F3F22601" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/3/18 Scan Time: 9:02 AM Log File: 2f320fd3-96eb-11e8-9e1e-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6181 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 252109 Threats Detected: 13 Threats Quarantined: 13 Time Elapsed: 3 min, 13 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 3 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\_metadata, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IPMHHOJDLFEEIEFKADLEEFBJGJKEMJOE, Quarantined, [14318], [521546],1.0.6181 File: 10 PUP.Optional.SocialNewsPage, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}.default\EXTENSIONS\{230A5283-AB42-49A2-8860-B06D797917C7}.XPI, Quarantined, [4679], [491800],1.0.6181 PUP.Optional.SocialNewPages, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\IPMHHOJDLFEEIEFKADLEEFBJGJKEMJOE\0.6_0\MANIFEST.JSON, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\_metadata\computed_hashes.json, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\_metadata\verified_contents.json, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\background.js, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\logo.png, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\redirect.html, Quarantined, [14318], [521546],1.0.6181 PUP.Optional.SocialNewPages, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmhhojdlfeeiefkadleefbjgjkemjoe\0.6_0\redirect.js, Quarantined, [14318], [521546],1.0.6181 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  11. What is Instagram2go?The Malwarebytes research team has determined that Instagram2go is adware. These adware applications display advertisements not originating from the sites you are browsing.How do I know if my computer is affected by Instagram2go?You may see these warnings during install:and this entry in your list of installed Programs and Features:This is the main screen of the program:and you will see these icons in your taskbar, on your dersktop, an in your startmenu:How did Instagram2go get on my computer?Adware applications use different methods for distributing themselves. This particular one was installed from their website:How do I remove Instagram2go?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Instagram2go? No, Malwarebytes removes Instagram2go completely. The "Pinned" shortcut in the taskbar can be removed by unpinning it. Rightclick on th icon > choose "Unpin this program from the taskbar". How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this adware.As you can see below the full version of Malwarebytes would have protected you against the Instagram2go adware. It would have blocked the installer before it became too late. and it would have blocked the site hosting the program: Technical details for expertsPossible signs in FRST logs: () C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe HKLM-x32\...\Run: [Instagram2go] => C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe [47951712 2018-06-17] () C:\Users\{username}\Desktop\Instagram2go.lnk C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instagram2go C:\Users\{username}\AppData\Roaming\Instagram2go C:\Users\{username}\AppData\Local\Instagram2go Instagram2go - Instagram for Desktop (HKLM-x32\...\Instagram2go) (Version: 14.1806.1inst_pa - Instagram2go) Significant changes made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Instagram2go Adds the file cookies"="8/2/2018 9:06 AM, 6144 bytes, A Adds the file cookies-journal"="8/2/2018 9:06 AM, 1544 bytes, A Adds the file lockfile"="8/2/2018 9:06 AM, 0 bytes, A Adds the file QuotaManager"="8/2/2018 9:07 AM, 13312 bytes, A Adds the file QuotaManager-journal"="8/2/2018 9:07 AM, 8768 bytes, A Adds the file Web Data"="8/2/2018 9:06 AM, 40960 bytes, A Adds the file Web Data-journal"="8/2/2018 9:06 AM, 512 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Instagram2go\Cache Adds the file index"="8/2/2018 9:06 AM, 24 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Instagram2go\Cache\index-dir Adds the file the-real-index"="8/2/2018 9:07 AM, 476 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Instagram2go\databases Adds the file Databases.db"="8/2/2018 9:06 AM, 7168 bytes, A Adds the file Databases.db-journal"="8/2/2018 9:06 AM, 5672 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Instagram2go\databases\file__0 Adds the file 1"="8/2/2018 9:06 AM, 4096 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Instagram2go\Local Storage Adds the file file__0.localstorage"="8/2/2018 9:06 AM, 3072 bytes, A Adds the file file__0.localstorage-journal"="8/2/2018 9:06 AM, 3608 bytes, A Adds the file https_www.instagram.com_0.localstorage"="8/2/2018 9:06 AM, 3072 bytes, A Adds the file https_www.instagram.com_0.localstorage-journal"="8/2/2018 9:06 AM, 512 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Instagram2go Adds the file ffmpegsumo.dll"="6/17/2018 1:43 PM, 1652896 bytes, A Adds the file icudtl.dat"="6/17/2018 1:38 PM, 10457856 bytes, A Adds the file Instagram2go.exe"="6/17/2018 1:43 PM, 47951712 bytes, A Adds the file nw.pak"="6/17/2018 1:38 PM, 7481810 bytes, A Adds the file storage.json"="8/2/2018 9:06 AM, 88 bytes, A Adds the file Uninstall.exe"="8/2/2018 9:06 AM, 472518 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Instagram2go\locales Adds the file uk.pak"="6/17/2018 1:38 PM, 15 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar Adds the file Instagram2go.lnk"="8/2/2018 9:06 AM, 947 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instagram2go Adds the file Instagram2go.lnk"="8/2/2018 9:06 AM, 1905 bytes, A Adds the file Uninstall.lnk"="8/2/2018 9:06 AM, 1884 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file Instagram2go.lnk"="8/2/2018 9:06 AM, 995 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Instagram2go"="REG_SZ", "C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe su" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Instagram2go] "DisplayIcon"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\Instagram2go\Uninstall.exe"" "DisplayName"="REG_SZ", "Instagram2go - Instagram for Desktop" "DisplayVersion"="REG_SZ", "14.1806.1inst_pa" "EstimatedSize"="REG_DWORD", 65961 "Publisher"="REG_SZ", "Instagram2go" "UninstallString"="REG_SZ", ""C:\Users\{username}\AppData\Roaming\Instagram2go\Uninstall.exe"" [HKEY_CURRENT_USER\Software\AppDataLow\Software\Instagram2go] "uid"="REG_SZ", "AF8D3D65-66AD-4EAD-8715-9D665EE5E4B2" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/2/18 Scan Time: 9:15 AM Log File: d620aa06-9623-11e8-b6e0-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6167 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251507 Threats Detected: 133 Threats Quarantined: 133 Time Elapsed: 3 min, 21 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 9 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 Module: 15 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 Registry Key: 1 PUP.Optional.Instagram2go, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Instagram2go, Quarantined, [3496], [539349],1.0.6167 Registry Value: 1 PUP.Optional.Instagram2go, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Instagram2go, Quarantined, [3496], [539349],1.0.6167 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 9 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\databases\file__0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\index-dir, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Local Storage, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\databases, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\LOCAL\INSTAGRAM2GO, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\ROAMING\INSTAGRAM2GO, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\INSTAGRAM2GO, Quarantined, [3496], [539352],1.0.6167 File: 98 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\LOCAL\INSTAGRAM2GO\WEB DATA, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\index-dir\the-real-index, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\7fd16d6949240560_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\1da1a8b152c77e1e_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\1ff1103df7e87e1f_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\23320b9ffca43d58_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\47b93bd4e0278387_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\49d77bc23c2e757f_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\4fef5ee7a37c7c09_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\582a5a8128448579_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\6ebb30277b6c5429_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\746b300a64fbe122_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\84f9e7f2d65511aa_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\9db00f8fcd2accb6_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\add2fe9ade1871af_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\ccae00c2367e1cdb_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\cf21652956bde47e_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\d329cf2848a29eeb_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\d90876e9cb5daf4a_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\f6b7a3768a566676_0, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Cache\index, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\databases\file__0\1, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\databases\Databases.db, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\databases\Databases.db-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Local Storage\file__0.localstorage, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Local Storage\file__0.localstorage-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Local Storage\https_www.instagram.com_0.localstorage, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Local Storage\https_www.instagram.com_0.localstorage-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\cookies, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\cookies-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\lockfile, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\QuotaManager, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\QuotaManager-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Local\Instagram2go\Web Data-journal, Quarantined, [3496], [539350],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\ROAMING\INSTAGRAM2GO\ICUDTL.DAT, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\hr.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\am.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ar.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\bg.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\bn.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ca.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\cs.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\da.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\de.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\el.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\en-GB.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\en-US.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\es-419.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\es.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\et.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\fa.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\fi.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\fil.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\fr.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\gu.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\hi.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\hu.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\id.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\it.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\iw.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ja.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\kn.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ko.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\lt.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\lv.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ml.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\mr.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ms.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\nl.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\no.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\pl.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\pt-BR.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\pt-PT.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ro.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ru.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\sk.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\sl.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\sr.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\sv.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\sw.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\ta.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\te.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\th.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\tr.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\uk.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\vi.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\zh-CN.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\locales\zh-TW.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\ffmpegsumo.dll, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Instagram2go.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\nw.pak, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\storage.json, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Instagram2go\Uninstall.exe, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\User Pinned\TaskBar\Instagram2go.lnk, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\DESKTOP\Instagram2go.lnk, Quarantined, [3496], [539349],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instagram2go\Instagram2go.lnk, Quarantined, [3496], [539352],1.0.6167 PUP.Optional.Instagram2go, C:\Users\{username}\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Instagram2go\Uninstall.lnk, Quarantined, [3496], [539352],1.0.6167 PUP.Optional.Instagram2go, C:\USERS\{username}\DESKTOP\INSTAGRAM2GO.14.1806.1INST_PA.EXE, Quarantined, [3496], [539354],1.0.6167 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  12. What is Super Speedup 2018?The Malwarebytes research team has determined that Super Speedup 2018 is a "system optimizer". These so-called "system optimizers" use intentional false positives to convince users that their systems have problems. Then they try to sell you their software, claiming it will remove these problems.More information can be found on our Malwarebytes Labs blog.How do I know if I am infected with Super Speedup 2018?This is how the main screen of the system optimizer looks:You will find these icons in your taskbar, your startmenu, and on your desktop:and see these warnings during install:and these screens during "operations":You may see this entry in your list of installed programs:and this task in your list of Scheduled Tasks:How did Super Speedup 2018 get on my computer?These so-called system optimizers use different methods of getting installed. This particular one was downloaded from their website:How do I remove Super Speedup 2018?Our program Malwarebytes can detect and remove this potentially unwanted application. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Super Speedup 2018? No, Malwarebytes removes Super Speedup 2018 completely. This PUP creates a scheduled task. You can read here how to check for and, if necessary, remove Scheduled Tasks. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this system optimizer.As you can see below the full version of Malwarebytes would have protected you against the Super Speedup 2018 installer. It would have warned you before the application could install itself, giving you a chance to stop it before it became too late. and we block access to their domain.Technical details for expertsYou may see these entries in FRST logs: () C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername} C:\Windows\System32\Tasks\Super Speedup 2018_Logon C:\Users\Public\Desktop\Super Speedup 2018.lnk C:\ProgramData\Super Speedup 2018 for {computername} C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Speedup 2018 for {computername} C:\Program Files\Super Speedup 2018 for {computername} Super Speedup 2018 (HKLM\...\{F7D26159-077B-4FA1-940A-B1715D1893D5}_is1) (Version: 1.0.0.0 - ) Task: {AAD09319-EED5-4DDE-B019-7B5EB0EC2198} - System32\Tasks\Super Speedup 2018_Logon => C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe [2018-07-17] () Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files\Super Speedup 2018 for {computername} Adds the file application.ico"="7/17/2018 1:01 PM, 94222 bytes, A Adds the file danish_iss.ini"="5/16/2018 11:25 AM, 2402 bytes, A Adds the file Dutch_iss.ini"="5/16/2018 11:25 AM, 2600 bytes, A Adds the file english_iss.ini"="5/16/2018 11:25 AM, 2256 bytes, A Adds the file finish_iss.ini"="5/16/2018 11:25 AM, 2368 bytes, A Adds the file French_iss.ini"="5/16/2018 11:25 AM, 2792 bytes, A Adds the file german_iss.ini"="5/16/2018 11:25 AM, 2658 bytes, A Adds the file gtcmg.dll"="7/17/2018 1:31 PM, 1927608 bytes, A Adds the file HtmlRenderer.dll"="7/17/2018 1:31 PM, 228280 bytes, A Adds the file HtmlRenderer.WinForms.dll"="7/17/2018 1:31 PM, 67000 bytes, A Adds the file Interop.IWshRuntimeLibrary.dll"="7/17/2018 1:31 PM, 55736 bytes, A Adds the file italian_iss.ini"="5/16/2018 11:25 AM, 2532 bytes, A Adds the file japanese_iss.ini"="5/16/2018 11:25 AM, 1844 bytes, A Adds the file langs.db"="5/16/2018 2:50 PM, 449536 bytes, A Adds the file Microsoft.Win32.TaskScheduler.dll"="7/17/2018 1:31 PM, 177592 bytes, A Adds the file mpr.exe"="7/17/2018 1:31 PM, 1852344 bytes, A Adds the file mpr.exe.config"="7/17/2018 1:31 PM, 6049 bytes, A Adds the file NAudio.dll"="7/17/2018 1:31 PM, 477624 bytes, A Adds the file Newtonsoft.Json.dll"="7/17/2018 1:31 PM, 467384 bytes, A Adds the file norwegian_iss.ini"="5/16/2018 11:25 AM, 2358 bytes, A Adds the file PaddleCheckoutSDK.dll"="7/17/2018 1:31 PM, 61880 bytes, A Adds the file portuguese_iss.ini"="5/16/2018 11:25 AM, 2424 bytes, A Adds the file russian_iss.ini"="5/16/2018 11:25 AM, 2494 bytes, A Adds the file spanish_iss.ini"="5/16/2018 11:25 AM, 2548 bytes, A Adds the file swedish_iss.ini"="5/16/2018 11:25 AM, 2270 bytes, A Adds the file System.Data.SQLite.DLL"="7/17/2018 1:31 PM, 297400 bytes, A Adds the file TAFactory.IconPack.dll"="7/17/2018 1:31 PM, 43448 bytes, A Adds the file unins000.dat"="8/1/2018 9:18 AM, 84971 bytes, A Adds the file unins000.exe"="8/1/2018 9:17 AM, 1273272 bytes, A Adds the file unins000.msg"="8/1/2018 9:18 AM, 22701 bytes, A Adds the folder C:\Program Files\Super Speedup 2018 for {computername}\x64 Adds the file SQLite.Interop.dll"="7/17/2018 1:31 PM, 1182136 bytes, A Adds the folder C:\Program Files\Super Speedup 2018 for {computername}\x86 Adds the file SQLite.Interop.dll"="7/17/2018 1:31 PM, 861112 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Speedup 2018 for {computername} Adds the file Buy Super Speedup 2018.lnk"="8/1/2018 9:18 AM, 1000 bytes, A Adds the file Super Speedup 2018.lnk"="8/1/2018 9:18 AM, 988 bytes, A Adds the file Uninstall Super Speedup 2018.lnk"="8/1/2018 9:18 AM, 1019 bytes, A Adds the folder C:\ProgramData\Super Speedup 2018 for {computername} Adds the file mdb.db"="5/16/2018 11:25 AM, 835584 bytes, A Adds the file pcspstartrepair_en.mp3"="5/16/2018 11:25 AM, 130973 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername} Adds the file Errorlog.txt"="8/1/2018 9:20 AM, 15456 bytes, A Adds the file exlist.bin"="8/1/2018 9:18 AM, 258019 bytes, A Adds the file notifier.xml"="8/1/2018 9:18 AM, 11565 bytes, A Adds the file pplan.xml"="8/1/2018 9:18 AM, 668 bytes, A Adds the file res.xml"="8/1/2018 9:19 AM, 9774 bytes, A Adds the file update.xml"="8/1/2018 9:18 AM, 32746 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\smico In the existing folder C:\Users\Public\Desktop Adds the file Super Speedup 2018.lnk"="8/1/2018 9:18 AM, 970 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file Super Speedup 2018_Logon"="8/1/2018 9:18 AM, 3078 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F7D26159-077B-4FA1-940A-B1715D1893D5}_is1] "DisplayIcon"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe" "DisplayName"="REG_SZ", "Super Speedup 2018" "DisplayVersion"="REG_SZ", "1.0.0.0" "EstimatedSize"="REG_DWORD", 12156 "Inno Setup: App Path"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}" "Inno Setup: Icon Group"="REG_SZ", "Super Speedup 2018 for {computername}" "Inno Setup: Language"="REG_SZ", "en" "Inno Setup: Setup Version"="REG_SZ", "5.5.8 (u)" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20180801" "InstallLocation"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}\" "MajorVersion"="REG_DWORD", 1 "MinorVersion"="REG_DWORD", 0 "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "QuietUninstallString"="REG_SZ", ""C:\Program Files\Super Speedup 2018 for {computername}\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files\Super Speedup 2018 for {computername}\unins000.exe"" [HKEY_LOCAL_MACHINE\SOFTWARE\scd-pr] "affiliateid"="REG_SZ", "" "btnid"="REG_SZ", "" "country"="REG_SZ", "nl" "LangCode"="REG_SZ", "en" "lpid"="REG_SZ", "" "pxl"="REG_SZ", "" "referUrl"="REG_SZ", "" "TELNO"="REG_SZ", "" "utm_campaign"="REG_SZ", "" "utm_medium"="REG_SZ", "" "utm_pubid"="REG_SZ", "" "utm_source"="REG_SZ", "" "x-at"="REG_SZ", "" "x-context"="REG_SZ", "" "x-plt"="REG_SZ", "" "x-var1"="REG_SZ", "" "x-var2"="REG_SZ", "" "x-var3"="REG_SZ", "" [HKEY_LOCAL_MACHINE\SOFTWARE\Super Speedup 2018 For {computername}] "affired"="REG_DWORD", 1 "afterInstallUrl"="REG_SZ", "http://ins.trkinstl.com/install/ssu/?" "apst"="REG_DWORD", 0 "buybowinapp"="REG_SZ", "http://store.winboost.review/ssu/plan?" "cbkpoff"="REG_DWORD", 1 "country"="REG_SZ", "nl" "cta"="REG_DWORD", 0 "delaytime"="REG_DWORD", 0 "dlllist"="REG_SZ", "PSMACHINE_64.DLL,MSSPELLCHECKINGFACILITY.DLL" "EmailURL"="REG_SZ", "" "expired"="REG_DWORD", 0 "hdata"="REG_BINARY, ......................................................................................................................................................................................................................................................................................................................................... "Installstring"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}" "ipaddrurl"="REG_SZ", "http://www.trkinstl.com/getip/" "isavst"="REG_DWORD", 0 "isiunidu"="REG_DWORD", 0 "isprmjsn"="REG_DWORD", 1 "isshowng"="REG_DWORD", 1 "issilent"="REG_DWORD", 0 "ISTELNO"="REG_DWORD", 1 "LangCode"="REG_SZ", "en" "lstregscancount"="REG_DWORD", 24 "lstscandate"="REG_SZ", "8/1/2018 9:19:02 AM" "lstscanstat"="REG_DWORD", 2 "lstsecscancount"="REG_DWORD", 0 "lsttotalscancount"="REG_DWORD", 24 "ovoffdis"="REG_DWORD", 0 "paramurl"="REG_SZ", "https://d1gnsi8fpqop2n.cloudfront.net/" "pdtm"="REG_DWORD", 30 "playsound"="REG_DWORD", 1 "plurl"="REG_SZ", "http://pp.trkinstl.com/ProductPrice.svc/" "prereg"="REG_DWORD", 0 "PurchaseURL"="REG_SZ", "http://store.winboost.review/ssu/price?" "reg"="REG_DWORD", 0 "RenewURL"="REG_SZ", "http://store.winboost.review/ssu/renewal?" "runcam"="REG_DWORD", 1 "runpixel"="REG_DWORD", 1 "runsrc"="REG_DWORD", 1 "showtn"="REG_DWORD", 0 "showunins"="REG_DWORD", 0 "showwfo"="REG_DWORD", 0 "stdismax"="REG_DWORD", -1 "supporturl"="REG_SZ", "http://www.winboost.review/help/" "TELNO"="REG_SZ", "085 888 7056" "TELNO_ar"="REG_SZ", "+54 11 5236 0324" "TELNO_at"="REG_SZ", "+43 (0)720 902 309" "TELNO_au"="REG_SZ", "(61)280-733403" "TELNO_be"="REG_SZ", "+32-28085306" "TELNO_br"="REG_SZ", "+55 21 2391 4319" "TELNO_ch"="REG_SZ", "+41 (0)44 508 70 37" "TELNO_de"="REG_SZ", "0800 1822 974" "TELNO_dk"="REG_SZ", "+45 78 73 09 26" "TELNO_es"="REG_SZ", "+34 951 203 537" "TELNO_fi"="REG_SZ", "+358 (0)9 4270 4911" "TELNO_fr"="REG_SZ", "05 82 84 04 06" "TELNO_gb"="REG_SZ", "0800-031-5066" "TELNO_it"="REG_SZ", "+39 069 4802886" "TELNO_ja"="REG_SZ", "" "TELNO_lu"="REG_SZ", "0800 1822 974" "TELNO_nl"="REG_SZ", "085 888 7056" "TELNO_no"="REG_SZ", "+47 21 95 01 97" "TELNO_pt"="REG_SZ", "+351 70 750 2094" "TELNO_se"="REG_SZ", "+46-08124-10298" "TELNO_uk"="REG_SZ", "0800-031-5066" "TELNO_us"="REG_SZ", "(855)-332-0124" "WebURL"="REG_SZ", "http://www.winboost.review/" "wfoset"="REG_DWORD", 1 "x-ccode"="REG_SZ", "nl" "x-datetime"="REG_SZ", "" "x-fetch"="REG_SZ", "0" "x-ip"="REG_SZ", "90_145_230_242" [HKEY_LOCAL_MACHINE\SOFTWARE\U3VwZXIgU3BlZWR1cCAyMDE4\ACT] "data"="REG_BINARY, ..............................................................................................................................................................................................................................................................................................................................................................................................._............................... [HKEY_CURRENT_USER\Software\Super Speedup 2018 for {computername}] "InstallString"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}" "LangCode"="REG_SZ", "en" "TELNO"="REG_SZ", "085 888 7056" "TELNO_nl"="REG_SZ", "085 888 7056" "x-datetime"="REG_SZ", "" "x-fetch"="REG_SZ", "0" "x-ip"="REG_SZ", "90_145_230_242" [HKEY_CURRENT_USER\Software\Super Speedup 2018 for {computername}\1.0.0.0] "Installstring"="REG_SZ", "C:\Program Files\Super Speedup 2018 for {computername}" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 8/1/18 Scan Time: 12:40 PM Log File: 52b70a37-9577-11e8-a55a-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6153 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251287 Threats Detected: 74 Threats Quarantined: 74 Time Elapsed: 3 min, 42 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe, Quarantined, [417], [547386],1.0.6153 Module: 7 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\PaddleCheckoutSDK.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [417], [547386],1.0.6153 Registry Key: 7 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Super Speedup 2018_Logon, Quarantined, [417], [547396],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6E0A8381-4E73-4FD0-8450-70A73A7609F6}, Quarantined, [417], [547396],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\LOGON\{6E0A8381-4E73-4FD0-8450-70A73A7609F6}, Quarantined, [417], [547396],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F7D26159-077B-4FA1-940A-B1715D1893D5}_is1, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR, Quarantined, [417], [540842],1.0.6153 PUP.Optional.PCVARK, HKCU\SOFTWARE\Super Speedup 2018 for {computername}, Quarantined, [417], [547392],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\Super Speedup 2018 For {computername}, Quarantined, [417], [547391],1.0.6153 Registry Value: 6 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{6E0A8381-4E73-4FD0-8450-70A73A7609F6}|PATH, Quarantined, [417], [547394],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\SCD-PR|AFFILIATEID, Quarantined, [417], [540842],1.0.6153 PUP.Optional.MasterPCCleaner, HKLM\SOFTWARE\SCD-PR|PXL, Quarantined, [1115], [484510],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F7D26159-077B-4FA1-940A-B1715D1893D5}_is1|DISPLAYNAME, Quarantined, [417], [547393],1.0.6153 PUP.Optional.PCVARK, HKCU\SOFTWARE\Super Speedup 2018 for {computername}|TELNO, Quarantined, [417], [547392],1.0.6153 PUP.Optional.PCVARK, HKLM\SOFTWARE\Super Speedup 2018 For {computername}|AFFIRED, Quarantined, [417], [547391],1.0.6153 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 7 PUP.Optional.PCVARK, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Super Speedup 2018 for {computername}, Quarantined, [417], [547387],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\smico, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\USERS\{username}\APPDATA\ROAMING\Super Speedup 2018 For {computername}, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\x64, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\x86, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\PROGRAM FILES\Super Speedup 2018 for {computername}, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\PROGRAMDATA\Super Speedup 2018 for {computername}, Quarantined, [417], [547388],1.0.6153 File: 46 PUP.Optional.PCVARK, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Super Speedup 2018 for {computername}\Buy Super Speedup 2018.lnk, Quarantined, [417], [547387],1.0.6153 PUP.Optional.PCVARK, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Speedup 2018 for {computername}\Super Speedup 2018.lnk, Quarantined, [417], [547387],1.0.6153 PUP.Optional.PCVARK, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Speedup 2018 for {computername}\Uninstall Super Speedup 2018.lnk, Quarantined, [417], [547387],1.0.6153 PUP.Optional.PCVARK, C:\USERS\{username}\APPDATA\ROAMING\Super Speedup 2018 For {computername}\Errorlog.txt, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\exlist.bin, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\notifier.xml, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\pplan.xml, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\res.xml, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\Users\{username}\AppData\Roaming\Super Speedup 2018 For {computername}\update.xml, Quarantined, [417], [547389],1.0.6153 PUP.Optional.PCVARK, C:\WINDOWS\SYSTEM32\TASKS\Super Speedup 2018_Logon, Quarantined, [417], [547396],1.0.6153 PUP.Optional.PCVARK, C:\USERS\PUBLIC\DESKTOP\Super Speedup 2018.lnk, Quarantined, [417], [547390],1.0.6153 PUP.Optional.PCVARK, C:\PROGRAM FILES\Super Speedup 2018 for {computername}\unins000.dat, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\x64\SQLite.Interop.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\x86\SQLite.Interop.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Microsoft.Win32.TaskScheduler.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\application.ico, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\danish_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Dutch_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\english_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\finish_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\French_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\german_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\gtcmg.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\HtmlRenderer.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\HtmlRenderer.WinForms.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Interop.IWshRuntimeLibrary.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\italian_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\japanese_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\langs.db, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\mpr.exe.config, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\NAudio.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\Newtonsoft.Json.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\norwegian_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\PaddleCheckoutSDK.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\portuguese_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\russian_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\spanish_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\swedish_iss.ini, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\System.Data.SQLite.DLL, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\TAFactory.IconPack.dll, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\unins000.exe, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\Program Files\Super Speedup 2018 for {computername}\unins000.msg, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\Super Speedup 2018.lnk, Quarantined, [417], [547386],1.0.6153 PUP.Optional.PCVARK, C:\PROGRAMDATA\Super Speedup 2018 for {computername}\mdb.db, Quarantined, [417], [547388],1.0.6153 PUP.Optional.PCVARK, C:\ProgramData\Super Speedup 2018 for {computername}\pcspstartrepair_en.mp3, Quarantined, [417], [547388],1.0.6153 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  13. What is Directions.cn?The Malwarebytes research team has determined that Directions.cn is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by Directions.cn?You may see this entry in your list of installed Chrome extensions:and these warnings during install:You will see this newtab page:and you will see this icon in your Chrome menu-bar:How did Directions.cn get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was downloaded from one of their websites:How do I remove Directions.cn?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Directions.cn? No, Malwarebytes removes Directions.cn completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the Directions.cn hijacker. It would have blocked the domain promoting the extension: Technical details for expertsPossible signs in FRST logs: CHR Extension: (Directions.cm) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg [2018-07-31] Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0 Adds the file background.js"="6/8/2018 2:04 PM, 9831 bytes, A Adds the file content.js"="2/28/2018 4:46 PM, 239 bytes, A Adds the file manifest.json"="7/31/2018 9:10 AM, 1647 bytes, A Adds the file tyContent.js"="6/8/2018 1:31 PM, 266 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\_metadata Adds the file computed_hashes.json"="7/31/2018 9:10 AM, 23489 bytes, A Adds the file verified_contents.json"="6/8/2018 1:31 PM, 8403 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons Adds the file 128.png"="7/31/2018 9:10 AM, 6512 bytes, A Adds the file 16.png"="7/31/2018 9:10 AM, 668 bytes, A Adds the file 32.png"="7/31/2018 9:10 AM, 1620 bytes, A Adds the file 48.png"="7/31/2018 9:10 AM, 2259 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab Adds the file analytics.js"="2/28/2018 4:46 PM, 1679 bytes, A Adds the file autocomplete.js"="2/28/2018 4:46 PM, 1557 bytes, A Adds the file blank.css"="2/28/2018 4:46 PM, 12599 bytes, A Adds the file blank.html"="2/28/2018 4:46 PM, 5437 bytes, A Adds the file blank.js"="5/24/2018 2:46 PM, 3742 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\css Adds the file font-awesome.css"="2/28/2018 4:46 PM, 35132 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts Adds the file fontawesome-webfont.eot"="1/11/2018 3:36 PM, 76518 bytes, A Adds the file fontawesome-webfont.svg"="2/28/2018 4:46 PM, 391622 bytes, A Adds the file fontawesome-webfont.ttf"="1/11/2018 3:36 PM, 152796 bytes, A Adds the file fontawesome-webfont.woff"="1/11/2018 3:36 PM, 90412 bytes, A Adds the file fontawesome-webfont.woff2"="1/11/2018 3:36 PM, 71896 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images Adds the file c-arrow.png"="1/11/2018 3:36 PM, 26749 bytes, A Adds the file dropbox.png"="1/11/2018 3:36 PM, 2062 bytes, A Adds the file evernote.png"="1/11/2018 3:36 PM, 1783 bytes, A Adds the file facebook.png"="1/11/2018 3:36 PM, 1471 bytes, A Adds the file giki.png"="1/11/2018 3:08 PM, 15969 bytes, A Adds the file google.png"="1/11/2018 3:36 PM, 16122 bytes, A Adds the file instargram.png"="1/11/2018 3:36 PM, 1756 bytes, A Adds the file linkin.png"="1/11/2018 3:36 PM, 1600 bytes, A Adds the file logo.png"="1/11/2018 3:36 PM, 2081 bytes, A Adds the file map-bg.jpg"="1/11/2018 3:36 PM, 84566 bytes, A Adds the file mt_logo.png"="1/11/2018 3:36 PM, 11889 bytes, A Adds the file mt_logo_gray.png"="1/11/2018 3:36 PM, 26977 bytes, A Adds the file pb_yahoo.png"="1/11/2018 3:36 PM, 2955 bytes, A Adds the file pinterest.png"="1/11/2018 3:36 PM, 1909 bytes, A Adds the file tumbler.png"="1/11/2018 3:36 PM, 1526 bytes, A Adds the file twitter.png"="1/11/2018 3:36 PM, 1715 bytes, A Adds the file wiki.png"="1/11/2018 3:36 PM, 1847 bytes, A Adds the file yahoo.png"="1/11/2018 3:36 PM, 1759 bytes, A Adds the file youtube.png"="1/11/2018 3:36 PM, 16338 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery Adds the file jquery-3.2.1.min.js"="2/28/2018 4:46 PM, 86659 bytes, A Adds the file jquery-ui.css"="2/28/2018 4:46 PM, 31344 bytes, A Adds the file jquery-ui.js"="2/28/2018 4:46 PM, 365673 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images Adds the file ui-bg_flat_0_aaaaaa_40x100.png"="11/28/2017 11:28 AM, 180 bytes, A Adds the file ui-bg_flat_75_ffffff_40x100.png"="11/28/2017 11:28 AM, 178 bytes, A Adds the file ui-bg_glass_55_fbf9ee_1x400.png"="11/28/2017 11:28 AM, 120 bytes, A Adds the file ui-bg_glass_65_ffffff_1x400.png"="11/28/2017 11:28 AM, 105 bytes, A Adds the file ui-bg_glass_75_dadada_1x400.png"="11/28/2017 11:28 AM, 111 bytes, A Adds the file ui-bg_glass_75_e6e6e6_1x400.png"="11/28/2017 11:28 AM, 110 bytes, A Adds the file ui-bg_glass_95_fef1ec_1x400.png"="11/28/2017 11:28 AM, 119 bytes, A Adds the file ui-bg_highlight-soft_75_cccccc_1x100.png"="11/28/2017 11:28 AM, 101 bytes, A Adds the file ui-icons_222222_256x240.png"="11/28/2017 11:28 AM, 4369 bytes, A Adds the file ui-icons_2e83ff_256x240.png"="11/28/2017 11:28 AM, 4369 bytes, A Adds the file ui-icons_454545_256x240.png"="11/28/2017 11:28 AM, 4369 bytes, A Adds the file ui-icons_888888_256x240.png"="11/28/2017 11:28 AM, 4369 bytes, A Adds the file ui-icons_cd0a0a_256x240.png"="11/28/2017 11:28 AM, 4369 bytes, A Adds the folder C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg Adds the file 000003.log"="7/31/2018 9:10 AM, 267 bytes, A Adds the file CURRENT"="7/31/2018 9:10 AM, 16 bytes, A Adds the file LOCK"="7/31/2018 9:10 AM, 0 bytes, A Adds the file LOG"="7/31/2018 9:11 AM, 412 bytes, A Adds the file LOG.old"="7/31/2018 9:10 AM, 412 bytes, A Adds the file MANIFEST-000001"="7/31/2018 9:10 AM, 41 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings] "bkcjncmijlkmlignahmdgbjldkmfiikg"="REG_SZ", "6B52EC17764C87C96B617B71D9F6367E84198D02DA8E7BA7F4644A009DE6CF5D" Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 7/31/18 Scan Time: 9:15 AM Log File: 86ee1e8e-9491-11e8-9fb3-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.391 Update Package Version: 1.0.6135 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251706 Threats Detected: 75 Threats Quarantined: 75 Time Elapsed: 3 min, 22 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 0 (No malicious items detected) Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 11 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\css, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\_metadata, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\bkcjncmijlkmlignahmdgbjldkmfiikg, Quarantined, [249], [546418],1.0.6135 File: 64 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons\128.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons\16.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons\32.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\icons\48.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\css\font-awesome.css, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts\fontawesome-webfont.eot, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts\fontawesome-webfont.svg, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts\fontawesome-webfont.ttf, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts\fontawesome-webfont.woff, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\fonts\fontawesome-webfont.woff2, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\c-arrow.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\dropbox.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\evernote.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\facebook.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\giki.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\google.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\instargram.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\linkin.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\logo.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\map-bg.jpg, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\mt_logo.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\mt_logo_gray.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\pb_yahoo.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\pinterest.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\tumbler.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\twitter.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\wiki.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\yahoo.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\images\youtube.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_flat_0_aaaaaa_40x100.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_flat_75_ffffff_40x100.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_glass_55_fbf9ee_1x400.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_glass_65_ffffff_1x400.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_glass_75_dadada_1x400.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_glass_75_e6e6e6_1x400.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_glass_95_fef1ec_1x400.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-bg_highlight-soft_75_cccccc_1x100.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-icons_222222_256x240.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-icons_2e83ff_256x240.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-icons_454545_256x240.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-icons_888888_256x240.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\images\ui-icons_cd0a0a_256x240.png, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\jquery-3.2.1.min.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\jquery-ui.css, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\jquery\jquery-ui.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\analytics.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\autocomplete.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\blank.css, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\blank.html, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\newtab\blank.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\_metadata\computed_hashes.json, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\_metadata\verified_contents.json, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\background.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\content.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\manifest.json, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkcjncmijlkmlignahmdgbjldkmfiikg\1.0.18.608_0\tyContent.js, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\000003.log, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\CURRENT, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\LOCK, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\LOG, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\LOG.old, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bkcjncmijlkmlignahmdgbjldkmfiikg\MANIFEST-000001, Quarantined, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [249], [546418],1.0.6135 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [249], [546418],1.0.6135 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  14. What is RegistrySmart?The Malwarebytes research team has determined that RegistrySmart is a fake registry scanning application. These so-called "rogues" use intentional false positives to convince users that their systems have been compromised. Then they try to sell you their software, claiming it will remove these threats. In extreme cases the false threats are actually the very trojans that advertise or even directly install the rogue. You are stronglyadvised to follow our removal instructions below.How do I know if I am infected with RegistrySmart?This is how the main screen of the rogue application looks:You will find these icons in your taskbar, on your desktop and in your Start-menu:And see these warnings during install:and thhis type of warning after a "scan":You may see this entry in your list of installed programs:and this task in your Scheduled Tasks:How did RegistrySmart get on my computer?Rogue programs use different methods for spreading themselves. This particular one was installed by a bundler.How do I remove RegistrySmart?Our program Malwarebytes can detect and remove this rogue. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of RegistrySmart? No, Malwarebytes removes RegistrySmart completely. How would the full version of Malwarebytes help protect me?We hope our application has helped you eradicate this malicious software. If your current security solution let this infection through, you might please consider purchasing the FULL version of Malwarebytes for additional protection.As you can see below the full version of Malwarebytes would have protected you against the RegistrySmart rogue. It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late. Technical details for expertsPossible signs in FRST logs: (E-NextMedia) C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe C:\Windows\System32\Tasks\RegistrySmart Scheduled Scan C:\Users\{username}\Desktop\RegistrySmart.lnk C:\Windows\Tasks\RegistrySmart Scheduled Scan.job C:\Users\{username}\AppData\Roaming\RegistrySmart C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistrySmart C:\Program Files (x86)\RegistrySmart RegistrySmart 2.10.4342 (HKLM-x32\...\RegistrySmart_is1) (Version: 2.10 - E-NextMedia) Task: {17BA9627-AFC4-4A8A-A2AE-E0331FA6372D} - System32\Tasks\RegistrySmart Scheduled Scan => C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe [2011-11-11] (E-NextMedia) Task: C:\Windows\Tasks\RegistrySmart Scheduled Scan.job => C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe scheduled C:\Program Files (x86)\RegistrySmart {username}.Run Alterations made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- Adds the folder C:\Program Files (x86)\RegistrySmart Adds the file DataBase.ref"="11/11/2011 12:02 PM, 16164 bytes, A Adds the file license.rtf"="7/2/2009 8:19 AM, 9989 bytes, A Adds the file RegistrySmart.exe"="11/11/2011 12:02 PM, 4780032 bytes, A Adds the file RegistrySmart.url"="7/30/2018 11:52 AM, 53 bytes, A Adds the file unins000.dat"="7/30/2018 11:52 AM, 5273 bytes, A Adds the file unins000.exe"="7/30/2018 11:51 AM, 774489 bytes, A Adds the folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistrySmart Adds the file RegistrySmart on the Web.lnk"="7/30/2018 11:52 AM, 1690 bytes, A Adds the file RegistrySmart.lnk"="7/30/2018 11:52 AM, 1983 bytes, A Adds the file Uninstall RegistrySmart.lnk"="7/30/2018 11:52 AM, 986 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch Adds the file RegistrySmart.lnk"="7/30/2018 11:52 AM, 1133 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\RegistrySmart\Log Adds the file 2018 Jul 30 - 11_52_27 AM_094.log"="7/30/2018 11:52 AM, 0 bytes, A In the existing folder C:\Users\{username}\Desktop Adds the file RegistrySmart.lnk"="7/30/2018 11:52 AM, 1965 bytes, A In the existing folder C:\Windows\System32\Tasks Adds the file RegistrySmart Scheduled Scan"="7/30/2018 11:52 AM, 3342 bytes, A In the existing folder C:\Windows\Tasks Adds the file RegistrySmart Scheduled Scan.job"="7/30/2018 11:52 AM, 458 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures] "RegistrySmart Scheduled Scan.job"="REG_BINARY, ................................ "RegistrySmart Scheduled Scan.job.fp"="REG_DWORD", -177504305 [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RegistrySmart_is1] "DisplayIcon"="REG_SZ", "C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe" "DisplayName"="REG_SZ", "RegistrySmart 2.10.4342" "DisplayVersion"="REG_SZ", "2.10" "Inno Setup: App Path"="REG_SZ", "C:\Program Files (x86)\RegistrySmart" "Inno Setup: Deselected Tasks"="REG_SZ", "" "Inno Setup: Icon Group"="REG_SZ", "RegistrySmart" "Inno Setup: Selected Tasks"="REG_SZ", "desktopicon,quicklaunchicon" "Inno Setup: Setup Version"="REG_SZ", "5.2.2" "Inno Setup: User"="REG_SZ", "{username}" "InstallDate"="REG_SZ", "20180730" "InstallLocation"="REG_SZ", "C:\Program Files (x86)\RegistrySmart\" "NoModify"="REG_DWORD", 1 "NoRepair"="REG_DWORD", 1 "Publisher"="REG_SZ", "E-NextMedia" "QuietUninstallString"="REG_SZ", ""C:\Program Files (x86)\RegistrySmart\unins000.exe" /SILENT" "UninstallString"="REG_SZ", ""C:\Program Files (x86)\RegistrySmart\unins000.exe"" "URLInfoAbout"="REG_SZ", "http://www.regsmartpro.com/" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\RegistrySmart\RegistrySmart\Settings] "Updated"="REG_DWORD", 1 [HKEY_CURRENT_USER\Software\RegistrySmart\RegistrySmart\RegistrySmart] "AskIfOne"="REG_DWORD", 0 [HKEY_CURRENT_USER\Software\RegistrySmart\RegistrySmart\SectionToScan] "CheckAppPaths"="REG_DWORD", 1 "CheckComReg"="REG_DWORD", 1 "CheckDrivers"="REG_DWORD", 1 "CheckFileAss"="REG_DWORD", 1 "CheckFonts"="REG_DWORD", 1 "CheckHelpDiles"="REG_DWORD", 1 "CheckHistory"="REG_DWORD", 1 "CheckServices"="REG_DWORD", 1 "CheckSharedFiles"="REG_DWORD", 1 "CheckShortcuts"="REG_DWORD", 1 "CheckSounds"="REG_DWORD", 1 "CheckStartup"="REG_DWORD", 1 "CheckUninstall"="REG_DWORD", 1 "CheckUser"="REG_DWORD", 1 Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 7/30/18 Scan Time: 11:59 AM Log File: 34ec19fe-93df-11e8-add8-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.374 Update Package Version: 1.0.6123 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 251110 Threats Detected: 29 Threats Quarantined: 29 Time Elapsed: 3 min, 29 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 1 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe, Quarantined, [1364], [171220],1.0.6123 Module: 1 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe, Quarantined, [1364], [171220],1.0.6123 Registry Key: 6 Rogue.RegistrySmart, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\RegistrySmart Scheduled Scan, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{17BA9627-AFC4-4A8A-A2AE-E0331FA6372D}, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\PLAIN\{17BA9627-AFC4-4A8A-A2AE-E0331FA6372D}, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\RegistrySmart_is1, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, HKLM\SOFTWARE\WOW6432NODE\RegistrySmart, Quarantined, [1364], [212840],1.0.6123 Rogue.RegistrySmart, HKCU\SOFTWARE\RegistrySmart, Quarantined, [1364], [210497],1.0.6123 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 4 Rogue.RegistrySmart, C:\Users\{username}\AppData\Roaming\RegistrySmart\Log, Quarantined, [1364], [170329],1.0.6123 Rogue.RegistrySmart, C:\USERS\{username}\APPDATA\ROAMING\REGISTRYSMART, Quarantined, [1364], [170329],1.0.6123 Rogue.RegistrySmart, C:\PROGRAM FILES (X86)\REGISTRYSMART, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\REGISTRYSMART, Quarantined, [1364], [171858],1.0.6123 File: 17 Rogue.RegistrySmart, C:\USERS\{username}\APPDATA\ROAMING\Microsoft\Windows\Recent\RegistrySmart - Changes.txt.lnk, Quarantined, [1364], [199824],1.0.6123 Rogue.RegistrySmart, C:\USERS\{username}\DESKTOP\RegistrySmart - Changes.txt, Quarantined, [1364], [199824],1.0.6123 Rogue.RegistrySmart, C:\USERS\{username}\DESKTOP\RegistrySmart.exe, Quarantined, [1364], [199824],1.0.6123 Rogue.RegistrySmart, C:\USERS\{username}\DESKTOP\RegistrySmart.lnk, Quarantined, [1364], [199824],1.0.6123 Rogue.RegistrySmart, C:\Users\{username}\AppData\Roaming\RegistrySmart\Log\2018 Jul 30 - 11_52_27 AM_094.log, Quarantined, [1364], [170329],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\DataBase.ref, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\license.rtf, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\RegistrySmart.exe, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\RegistrySmart.url, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\unins000.dat, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\Program Files (x86)\RegistrySmart\unins000.exe, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\WINDOWS\SYSTEM32\TASKS\RegistrySmart Scheduled Scan, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\USERS\{username}\APPDATA\ROAMING\Microsoft\Internet Explorer\Quick Launch\RegistrySmart.lnk, Quarantined, [1364], [171220],1.0.6123 Rogue.RegistrySmart, C:\WINDOWS\TASKS\RegistrySmart Scheduled Scan.job, Quarantined, [1364], [207855],1.0.6123 Rogue.RegistrySmart, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistrySmart\RegistrySmart on the Web.lnk, Quarantined, [1364], [171858],1.0.6123 Rogue.RegistrySmart, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistrySmart\RegistrySmart.lnk, Quarantined, [1364], [171858],1.0.6123 Rogue.RegistrySmart, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RegistrySmart\Uninstall RegistrySmart.lnk, Quarantined, [1364], [171858],1.0.6123 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
  15. What is Search Manager?The Malwarebytes research team has determined that Search Manager is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.How do I know if my computer is affected by Search Manager?You may see these Chrome extensions:these warnings during install:this prompt when you click the icon in the Chrome menu bar:and this changed settings:How did Search Manager get on my computer?Browser hijackers use different methods for distributing themselves. This particular one was installed by a bundler posing as a Flash Player update:How do I remove Search Manager?Our program Malwarebytes can detect and remove this potentially unwanted program. Please download Malwarebytes to your desktop. Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program. Then click Finish. Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu. If another update of the definitions is available, it will be implemented before the rest of the scanning procedure. When the scan is complete, make sure that all Threats are selected, and click Remove Selected. Restart your computer when prompted to do so. Is there anything else I need to do to get rid of Search Manager? No, Malwarebytes removes Search Manager completely. How would the full version of Malwarebytes help protect me?We hope our application and this guide have helped you eradicate this hijacker.As you can see below the full version of Malwarebytes would have protected you against the Search Manager hijacker by blocking the bundler:Technical details for expertsPossible signs in FRST logs: SearchScopes: HKCU -> {518b33ae-375d-712d-6742-d1fe0400268d} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_kpf8ace8acsz_18_30_20&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3Dwingy%26cd%3D2XzuyEtN2Y1L1QzutDzztDtDtByBtBtAyD0DyByCyBtDyCyCtN0D0Tzu0StBtAzyzytN1L2XzuyEtFtByCtFtDtFzyzztN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyDtDzzzzzy0A0F0AtGtD0CyB0CtG0F0F0DtCtGtD0AzytCtG0C0FyDzytB0EzytAyByE0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtDtCyDzz1RyC1StG1RtAyDzztGyEyCyCzztG1T1RzzyDtGyDyCtBzy1StAtBtDtCyBtAyE2QtN0A0LzutDtN1B2Z1V1T1S1NzutN1Q2Z1B1P1RzutCyDtAtByCzztCyCtCyB%26cr%3D977776022%26a%3Dbgy_kpf8ace8acsz_18_30_20%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate&p={searchTerms} FF Homepage: hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_kpf8ace8acsz_18_30_20&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3Dwingy%26cd%3D2XzuyEtN2Y1L1QzutDzztDtDtByBtBtAyD0DyByCyBtDyCyCtN0D0Tzu0StBtAzyzytN1L2XzuyEtFtByCtFtDtFzyzztN1L1CzutN1L1G1B1V1N2Y1L1Qzu2SyDtDzzzzzy0A0F0AtGtD0CyB0CtG0F0F0DtCtGtD0AzytCtG0C0FyDzytB0EzytAyByE0CtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCtDtCyDzz1RyC1StG1RtAyDzztGyEyCyCzztG1T1RzzyDtGyDyCtBzy1StAtBtDtCyBtAyE2QtN0A0LzutDtN1B2Z1V1T1S1NzutN1Q2Z1B1P1RzutCyDtAtByCzztCyCtCyB%26cr%3D977776022%26a%3Dbgy_kpf8ace8acsz_18_30_20%26os_ver%3D6.1%26os%3DWindows%2B7%2BUltimate FF SearchPlugin: C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\searchplugins\yahoo! powered search.xml [2018-07-27] CHR DefaultSearchURL: Default -> hxxp://srchbar.com/?q={searchTerms} CHR DefaultSearchKeyword: Default -> sm CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms} CHR Extension: (Search Manager) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2018-07-27] CHR Extension: (Search Manager) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej [2018-07-27] Significant chnages made by the installer: File system details [View: All details] (Selection) --------------------------------------------------- In the existing folder C:\Users\{username}\AppData\LocalLow\Microsoft\Internet Explorer\Services Adds the file Yahoo! Powered Search.ico"="7/27/2018 10:53 AM, 5406 bytes, A In the existing folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148 Alters the file prefs.js 7/6/2018 8:33 AM, 12250 bytes, A ==> 7/27/2018 10:53 AM, 12767 bytes, A Adds the file prefs.js.copy"="7/27/2018 10:53 AM, 12767 bytes, A Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\60l2dg92.default-1519559592148\searchplugins Adds the file yahoo! powered search.xml"="7/27/2018 10:53 AM, 1846 bytes, A Registry details [View: All details] (Selection) ------------------------------------------------ [HKEY_CURRENT_USER\Software\csastats\ic\1633c09e3c4d5d39f62fd6a30e2cbf65c3f2365eebb3092eb7afc008daeffd08] "advertisers_ids"="REG_SZ", "554cb9c7b6" "channel"="REG_SZ", "fa4c6bd7a1041373f7d7e4e48a86d46b2e70b2b807d5b6d5e28969e058476090" "hmac_sha256_validation"="REG_SZ", "5b174f6189ecbaeae8488cde1ff5a0ab575af47fc928ad9439fd8136a4ce3a2a" "install_id"="REG_SZ", "1633c09e3c4d5d39f62fd6a30e2cbf65c3f2365eebb3092eb7afc008daeffd08" "install_time_client"="REG_SZ", "20180727105303076" "install_time_server"="REG_SZ", "20180727035305426" "publisher_id"="REG_SZ", "5bce72fa04" "vendor_id"="REG_SZ", "ic" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page" ==> REG_SZ, "https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_kpf8ace8acsz_18_30_20" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes] "DefaultScope" ==> REG_SZ, "{518b33ae-375d-712d-6742-d1fe0400268d}" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{518b33ae-375d-712d-6742-d1fe0400268d}] "(Default)"="REG_SZ", "Yahoo! Powered Search" "DisplayName"="REG_SZ", "Yahoo! Powered Search" "FaviconPath"="REG_SZ", "C:\Users\{username}\AppData\LocalLow\Microsoft\Internet Explorer\Services\Yahoo! Powered Search.ico" "URL"="REG_SZ", "https://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=bgy_kpf8ace8acsz_18_30_20&p={searchTerms}" [HKEY_CURRENT_USER\Software\ProductSetup\Uninstall\0B2U2Z1P0F1P1G1R1P1V0A1Q1Q0O1G] "uninstall"="REG_SZ", "0B2U2Z1P0F1P1G1R1P0M1F1Q2Y1I1P" [HKEY_CURRENT_USER\Software\ProductSetup\Uninstall\0S1P1T1C1R1MtT0P1C1F2X1L1Q1P1QtT1S2UtT0Y1T1M1F1F] Malwarebytes log: Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 7/27/18 Scan Time: 11:03 AM Log File: ff6a7089-917b-11e8-8b9b-00ffdcc6fdfc.json Administrator: Yes -Software Information- Version: 3.5.1.2522 Components Version: 1.0.374 Update Package Version: 1.0.6089 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 252480 Threats Detected: 391 Threats Quarantined: 391 Time Elapsed: 4 min, 15 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 7 PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, HKCU\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\PILPLLOABDEDFMIALNFCHJOMJMPJCOEJ, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, HKCU\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\PILPLLOABDEDFMIALNFCHJOMJMPJCOEJ, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pilplloabdedfmialnfchjomjmpjcoej, Quarantined, [245], [260991],1.0.6089 PUP.Optional.WinYahoo, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{518b33ae-375d-712d-6742-d1fe0400268d}, Quarantined, [248], [413444],1.0.6089 Registry Value: 1 PUP.Optional.WinYahoo, HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{518b33ae-375d-712d-6742-d1fe0400268d}|URL, Quarantined, [248], [413444],1.0.6089 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 44 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\tiles, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\pt_BR, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\fonts, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\en, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\fr, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\hi, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\vi, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\skin\icons, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_metadata, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\vendor, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\skin, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\EXTENSIONS\nahhmpbckpgdidfnmfkfgiflpjijilce, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\tiles, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\pt_BR, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\fonts, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\en, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\fr, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\hi, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\vi, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\skin\icons, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_metadata, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\vendor, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\skin, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Extensions\PILPLLOABDEDFMIALNFCHJOMJMPJCOEJ, Quarantined, [245], [260991],1.0.6089 File: 339 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\LOCAL STORAGE\chrome-extension_pilplloabdedfmialnfchjomjmpjcoej_0.localstorage, Quarantined, [245], [453138],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\fonts\HelveticaNeue-Thin.otf, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\fonts\HelveticaNeueLT-Roman.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\fonts\neue-bold.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\fonts\neue.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\close-FF8A5A.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\collection-9B9B9B.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\collection-FF691E.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\doc-icon-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\error-FF691E.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\pdf-2-doc-9B9B9B.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\pdf-2-doc-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\pdf-icon-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\success-FF8A5A.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\tab-arrow-FF691E.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\converter\upload-FF691E.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\amazon-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\amazon.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\close.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\enlarge-000000-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\enlarge-FFCA00-000000.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\hulu-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\hulu.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\minimize-000000-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\netflix-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\netflix.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\refresh-FFFFFF-000000.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\shrink-FFCA00-000000.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\shuffle-000000.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\shuffle-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\vudu-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films\vudu.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\128.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\16.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\48.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\close.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\favicon.ico, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\icons\trends.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\bing-maps-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\from-to-icon-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\google-maps-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\location-icon-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\search-4A4A4A.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\search-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\switch-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\tab-arrow-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\whereto-logo-8881FF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\maps\whereto-logo-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\facebook_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\aliexpress.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\aliexpress_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\amazon.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\amazon_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\booking.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\booking_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\ebay.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\ebay_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\expedia.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\expedia_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\facebook.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\gmail.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\gmail_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\google-translate-icon-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\gtranslte.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\pinterest.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\pinterest_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\twitter.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\twitter_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\wix.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\wix_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\yahoo.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\yahoo_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\youtube.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sitesThumbnails\youtube_tile_v2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\tiles\DOC-to-PDF.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\tiles\PDF-to-DOC.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\tiles\Translation.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\tiles\View-PDF.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\01d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\01n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\02d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\02n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\03d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\03n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\04d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\04n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\09d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\09n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\10d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\10n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\11d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\11n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\13d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\13n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\50d.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\weather\50n.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\down.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\alot.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\angle-arrow-down.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\bing.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\bing_large.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\bluesky-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\brush.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\bt.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\clock.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\cloud.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\cupcake-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\desk-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\doodle.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\enhanced_google.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\eyeglass.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\eyeglass_transparent.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\films-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\gmx_large.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\google.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\google_large.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\hero-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\just-the-box-empty.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\just-the-box.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\mountain-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\pointer2.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\radio-selected.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\radio-unselected.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\sea-bg.jpg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\search-D7D7D7.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\search-FFFFFF.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\settings.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\smallMagnifier.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\star-unselected.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\star.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\todoc.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\toggle-off.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\toggle-on.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\topdf.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\transparent_img.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\yahoo.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\yahoo.svg, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\yahoo_large.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\yandex.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\_enhanced_google.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\images\_gmx_large.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\content\bundle.v0.0.1.min.css, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\skin\icons\16.png, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\vendor\md5.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\vendor\react-dom.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\vendor\react-with-addons.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\en\messages.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\fr\messages.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\hi\messages.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\pt_BR\messages.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_locales\vi\messages.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_metadata\computed_hashes.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\_metadata\verified_contents.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\2bfc185be71f44cd73ac81511fc1f5a5.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\b495e340f4ef8924fea0284c1bf9e7ac.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\background.html, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\background.v0.0.1.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\c5a5cbf4dbcaa7064f2bc77f52101aec.otf, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\client.v0.0.1.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\common.js.v0.0.1.min.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\e5d3501d500d07b0a1e952b0f8a81d78.woff, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\e_.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\index.html, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\manifest.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\popupTab2.html, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\popupTab2.js, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce\10.1.3.52_0\responseConfig.json, Quarantined, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [245], [443378],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\fonts\HelveticaNeue-Thin.otf, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\fonts\HelveticaNeueLT-Roman.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\fonts\neue-bold.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\fonts\neue.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\close-FF8A5A.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\collection-9B9B9B.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\collection-FF691E.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\doc-icon-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\error-FF691E.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\pdf-2-doc-9B9B9B.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\pdf-2-doc-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\pdf-icon-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\success-FF8A5A.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\tab-arrow-FF691E.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\converter\upload-FF691E.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\amazon-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\amazon.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\close.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\enlarge-000000-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\enlarge-FFCA00-000000.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\hulu-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\hulu.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\minimize-000000-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\netflix-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\netflix.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\refresh-FFFFFF-000000.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\shrink-FFCA00-000000.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\shuffle-000000.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\shuffle-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\vudu-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films\vudu.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\128.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\16.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\48.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\close.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\favicon.ico, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\icons\trends.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\bing-maps-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\from-to-icon-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\google-maps-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\location-icon-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\search-4A4A4A.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\search-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\switch-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\tab-arrow-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\whereto-logo-8881FF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\maps\whereto-logo-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\facebook_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\aliexpress.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\aliexpress_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\amazon.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\amazon_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\booking.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\booking_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\ebay.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\ebay_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\expedia.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\expedia_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\facebook.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\gmail.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\gmail_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\google-translate-icon-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\gtranslte.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\pinterest.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\pinterest_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\twitter.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\twitter_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\wix.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\wix_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\yahoo.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\yahoo_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\youtube.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sitesThumbnails\youtube_tile_v2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\tiles\DOC-to-PDF.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\tiles\PDF-to-DOC.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\tiles\Translation.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\tiles\View-PDF.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\01d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\01n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\02d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\02n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\03d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\03n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\04d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\04n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\09d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\09n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\10d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\10n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\11d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\11n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\13d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\13n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\50d.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\weather\50n.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\down.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\alot.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\angle-arrow-down.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\bing.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\bing_large.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\bluesky-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\brush.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\bt.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\clock.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\cloud.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\cupcake-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\desk-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\doodle.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\enhanced_google.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\eyeglass.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\eyeglass_transparent.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\films-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\gmx_large.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\google.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\google_large.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\hero-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\just-the-box-empty.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\just-the-box.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\mountain-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\pointer2.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\radio-selected.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\radio-unselected.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\sea-bg.jpg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\search-D7D7D7.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\search-FFFFFF.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\settings.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\smallMagnifier.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\star-unselected.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\star.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\todoc.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\toggle-off.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\toggle-on.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\topdf.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\transparent_img.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\yahoo.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\yahoo.svg, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\yahoo_large.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\yandex.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\_enhanced_google.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\images\_gmx_large.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\content\bundle.v0.0.1.min.css, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\skin\icons\16.png, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\vendor\md5.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\vendor\react-dom.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\vendor\react-with-addons.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\en\messages.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\fr\messages.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\hi\messages.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\pt_BR\messages.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_locales\vi\messages.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\_metadata\verified_contents.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\2bfc185be71f44cd73ac81511fc1f5a5.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\b495e340f4ef8924fea0284c1bf9e7ac.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\background.html, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\background.v0.0.1.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\c5a5cbf4dbcaa7064f2bc77f52101aec.otf, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\client.v0.0.1.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\common.js.v0.0.1.min.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\e5d3501d500d07b0a1e952b0f8a81d78.woff, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\e_.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\index.html, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\manifest.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\popupTab2.html, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\popupTab2.js, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\pilplloabdedfmialnfchjomjmpjcoej\10.1.3.54_0\responseConfig.json, Quarantined, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [245], [260991],1.0.6089 PUP.Optional.SearchManager, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [245], [260991],1.0.6089 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\60L2DG92.DEFAULT-1519559592148\PREFS.JS, Replaced, [248], [413431],1.0.6089 PUP.Optional.WinYahoo, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\60L2DG92.DEFAULT-1519559592148\SEARCHPLUGINS\YAHOO! POWERED SEARCH.XML, Quarantined, [248], [413427],1.0.6089 PUP.Optional.InstallCore.Generic, C:\USERS\{username}\DESKTOP\MPP_SETUP_1820095530.EXE, Quarantined, [6192], [511843],1.0.6089 Physical Sector: 0 (No malicious items detected) WMI: 0 (No malicious items detected) (end) As mentioned before the full version of Malwarebytes could have protected your computer against this threat.We use different ways of protecting your computer(s): Dynamically Blocks Malware Sites & Servers Malware Execution Prevention Save yourself the hassle and get protected.
×

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.