Jump to content

Removal instructions for FireDive


Recommended Posts

  • Staff

What is FireDive?

The Malwarebytes research team has determined that FireDive is a browser hijacker. These so-called "hijackers" alter your startpage or searchscopes so that the effected browser visits their site or one of their choice. This one also displays advertisements.

How do I know if my computer is effected by FireDive?

You may see these browser extensions/add-ons:

warning1.png

warning2.png

warning3.png

How did FireDive get on my computer?

Browser hijackers use different methods for distributing themselves. This particular one was offered as a browser extension to speed up your downloads.

How do I remove FireDive?

Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted program. You will need Malwarebytes Anti-Malware version 2.00 (beta) or newer to disable the Chrome and Firefox extensions.

  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-consumer.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of FireDive?
  • The Firefox extension can now safely be removed. Open the "Extensions" tab under "Add-ons" and click "Remove" and "Restart" to complete the removal.
  • The Chrome extension can now safely be removed. Open "Settings" > "Extensions" and click the bin behind the Picora 2.0 listing. Then confirm removal.
How would the full version of Malwarebytes Anti-Malware help protect me?

We hope our application and this guide have helped you eradicate this hijacker.

As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the FireDive browser hijacker. It would have warned you before the browser extensions could install itself, giving you a chance to stop it before it became too late.

protection1.png

Technical details for experts

Signs in a HijackThis log:

O2 - BHO: CrossriderApp0051739 - {11111111-1111-1111-1111-110511171139} - C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-bho.dll
Alterations made by the installer:

Malwarebytes Anti-Malware log:

Malwarebytes Anti-Malwarewww.malwarebytes.orgScan Date: 3/2/2014Scan Time: 9:28:28 AMLogfile: mbamFireDive.txtAdministrator: YesVersion: 2.00.0.0504Malware Database: v2014.03.02.04Rootkit Database: v2014.02.20.01License: TrialMalware Protection: DisabledMalicious Website Protection: DisabledChameleon: DisabledOS: Windows 7 Service Pack 1CPU: x86File System: NTFSUser: MalwarebytesScan Type: Threat ScanResult: CompletedObjects Scanned: 197839Time Elapsed: 4 min, 6 secMemory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledShuriken: EnabledPUP: EnabledPUM: EnabledProcesses: 0(No malicious items detected)Modules: 0(No malicious items detected)Registry Keys: 19PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511171139}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440544174439}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550555175539}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660566176639}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0051739.BHO.1, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110511171139}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0051739.BHO, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110511171139}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110511171139}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220522172239}, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0051739.Sandbox.1, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CrossriderApp0051739.Sandbox, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110511171139}\INPROCSERVER32, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\Firedive Downloader V9.0, Quarantined, [3d3f946a95e5270fae332762e71b3ec2],PUP.Optional.Ligtning.A, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\cekcjpgehmohobmdiikfnopibipmgnml, Quarantined, [8fedc638f783ca6c4218c8c56999966a],PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [9ae2b24ce595ff371d33ebd122e104fc],PUP.Optional.FirediveDownloader.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Firedive Downloader V9.0, Quarantined, [314b9c62fe7c34027c638108c83a30d0],PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\installdaddy, Quarantined, [e498bf3f80fa3ef8e0b5c0e89b68bb45],PUP.Optional.FirediveDownloader.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Firedive Downloader V9.0, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],Registry Values: 0(No malicious items detected)Registry Data: 0(No malicious items detected)Folders: 15PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log, Quarantined, [d2aad925d7a32b0b0f67b0ddfe04f907],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\userCode, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons\actions, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\popupResource, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],Files: 98PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-bho.dll, Quarantined, [44387787afcba492aef91f80c43d42be],PUP.Optional.SockshareDownloader.A, C:\Users\{username}\Desktop\Mvoqlaq.exe, Quarantined, [0874fb0389f1b5814e8688152ad7c23e],PUP.Optional.FirediveDownloader.A, C:\Windows\Tasks\Firedive Downloader V9.0-chromeinstaller.job, Quarantined, [bac26a946c0e58de06d8b5d4ec16d030],PUP.Optional.FirediveDownloader.A, C:\Windows\Tasks\Firedive Downloader V9.0-codedownloader.job, Quarantined, [d7a5e01e7efc64d2924c0782936f8878],PUP.Optional.FirediveDownloader.A, C:\Windows\Tasks\Firedive Downloader V9.0-enabler.job, Quarantined, [acd0c935740686b036a8d4b504fe7b85],PUP.Optional.FirediveDownloader.A, C:\Windows\Tasks\Firedive Downloader V9.0-firefoxinstaller.job, Quarantined, [67159866c7b31422c816b4d520e2a15f],PUP.Optional.FirediveDownloader.A, C:\Windows\Tasks\Firedive Downloader V9.0-updater.job, Quarantined, [601c23dbf18938feac323158fe04bd43],PUP.Optional.eSafe.A, C:\ProgramData\eSafe\log\eGdpSvc.LOG, Quarantined, [d2aad925d7a32b0b0f67b0ddfe04f907],PUP.Optional.NewTab.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtab.crx, Quarantined, [126a59a57a007db9d818d3ba7e84fc04],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\background.html, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\background.js, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\data.json, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\icon128.png, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\jquery.js, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\manifest.json, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\xa.js, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.Lightning.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\cekcjpgehmohobmdiikfnopibipmgnml\1.3_0\xagainit.js, Quarantined, [7ffd1ae483f74de9a07ed6b1b44e817f],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\background.html, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\chromeCoreFilesIndex.txt, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\crossriderManifest.json, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\manifest.json, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\popup.html, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\manifest.xml, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins.json, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\207_dbWrapper.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\1000020_analytics.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\1000025_analyticsFront.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\1000030_mz.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\13_CrossriderAppUtils.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\14_CrossriderUtils.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\177_crossriderDashboard.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\17_jQuery.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\180_bpo_serp_m.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\182_openUrl.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\183_tabsWrapper.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\19_CHAppAPIWrapper.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\1_base.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\21_debug.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\22_resources.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\28_initializer.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\47_resources_background.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\4_jquery_1_7_1.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\64_appApiMessage.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\72_appApiValidation.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\78_CrossriderInfo.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\80_CHPopupAppAPI.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\91_monetizationLoader.js.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\plugins\97_resourceApiWrapper.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\userCode\background.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\extensionData\userCode\extension.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons\icon128.png, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons\icon16.png, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons\icon48.png, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\icons\actions\1.png, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\background.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\main.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\platformVersion.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\chrome.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\cookie.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\message.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\monitor.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\pageAction.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\api\pageActionBG.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\app_api.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\bg_app_api.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\consts.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\cookie_store.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\crossriderAPI.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\delegate.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\events.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\extensionDataStore.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\installer.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\logFile.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\logging.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\onBGDocumentLoad.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\reports.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\storageWrapper.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\updateManager.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\util.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\xhr.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\popupResource\newPopup.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\ianpkncpdncekpjnlflanaomeeenkehn\1.26.8_0\js\lib\popupResource\popup.js, Quarantined, [2c507e800f6b082e97251e6a15eda65a],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\51739.crx, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\51739.xpi, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\background.html, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-bg.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-buttonutil.dll, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-buttonutil.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-chromeinstaller.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-codedownloader.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-enabler.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-firefoxinstaller.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-helper.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0-updater.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Firedive Downloader V9.0.ico, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Installer.log, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\Uninstall.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],PUP.Optional.FirediveDownloader.A, C:\Program Files\Firedive Downloader V9.0\utils.exe, Quarantined, [c4b8f806d9a186b09c23b9cfec16e818],Physical Sectors: 0(No malicious items detected)(end)
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.

We use different ways of protecting your computer(s):

  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.