PUP.Optional.SearchProtect.A

Logo_Malware
SearchProtect is an advertising program whose objective is to earn money by generating Web traffic. It usually moved without your knowledge via the download of freeware. For consultation of some sites, like Amazon, it offers coupons on multiple products. It collects information about your navigation habits. It promotes its products (advertisements) and boosted the ranking of sponsored sites. It displays messages of safety on the instability of the system. It slowed down the performance of the system and internet navigation.
Identified 20/05/2015

Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– Vendor : PUP.Optional

Main Actions

– It installs as a process launched at startup of the system (RP),
– It changes the start page of the browser Internet Explorer (R0),
– It changes the browser Internet Explorer search page (R1),
– It installs a program of extension for browser Mozilla Firefox (M2)
– It installs a plugin for the browser Mozilla Firefox (M3)
– It installs a program of extension for the browser Google Chrome (G2)
– It is installed as a BHO (Browser Helper Object) of internet browser (O2),
– It installs as a service to be launched each time the system (O23),(SS/SR).
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It creates multiple files users (O61),
– It creates a Legacy pointing to a malware service, key in the registry (O64),
– It creates registry keys Tracing (O100),
– It creates keys from registry CLSID (O101),

– (.Client Connect LTD – Search Protect.) — C:Program Files (x86)SearchProtectSearchProtectbincltmng.exe
– (.Client Connect LTD – Search Protect.) — C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe
– (.Client Connect LTD – Search Protect.) — C:Program Files (x86)SearchProtectUIbincltmngui.exe
O4 – HKUS.DEFAULT..RunOnce: Clé orpheline
O4 – HKUSS-1-5-18..RunOnce: Clé orpheline
O2 – BHO: SearchProtect – {26e67fb2-111e-417f-966e-547ac43968cf} . (.SearchProtect – SearchProtect.) — C:Program Files (x86)SearchProtectSearchProtectBHO.dll
O20 – AppInit_DLLs: . (.Client Connect LTD – Search Protect.) – C:Program Files (x86)SearchProtectSearchProtectbinSPVC64Loader.dll
O23 – Service: Search Protect Service (CltMngSvc) . (.Client Connect LTD – Search Protect.) – C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe
O23 – Service: Update SearchProtect (Update SearchProtect) . (.Client Connect LTD – SearchProtect.) – C:Program Files (x86)SearchProtectSearchProtectbincltmng.exe
O23 – Service: Util SearchProtect (Util SearchProtect) . (.Client Connect LTD – SearchProtect.) – C:Program Files (x86)SearchProtectUIbincltmngui.exe
O42 – Logiciel: Search Protect – (.Client Connect LTD.) — SearchProtect

O43 – CFD: 23/11/2013 – 08:14:22 – —-D C:Program FilesSearchProtect
O61 – LFC: 10/03/2014 – 17:05:30 —A- . (…) — C:UsersCoolmanAppDataLocalGoogleChromeUser DataDefaultExtensions{random}1.0.1_0background.js
O61 – LFC: 10/03/2014 – 17:05:30 —A- . (…) — C:UsersCoolmanAppDataLocalGoogleChromeUser DataDefaultExtensions{random}1.0.1_0content.js
O61 – LFC: 10/03/2014 – 17:05:30 —A- . (…) — C:UsersCoolmanAppDataLocalGoogleChromeUser DataDefaultExtensions{random}1.0.1_0icon.png
O61 – LFC: 10/03/2014 – 17:05:30 —A- . (…) — C:UsersCoolmanAppDataLocalGoogleChromeUser DataDefaultExtensions{random}1.0.1_0manifest.json
O61 – LFC: 30/05/2014 – 13:48:57 —A- . (…) — C:UsersCoolmanAppDataLocalTempn7093SearchProtect_0104-57366623.exe
O64 – Services: CurCS – 08/11/2013 – C:Program FilesSearchProtectupdateSearchProtect.exe (Update SearchProtect) .(…) – LEGACY_UPDATE_SearchProtect
O64 – Services: CurCS – 23/11/2013 – C:Program FilesSearchProtectbinutilSearchProtect.exe (Util SearchProtect) .(…) – LEGACY_UTIL_SearchProtect
SR – | Auto 08/11/2013 66336 | (Update SearchProtect) . (.Client Connect LTD – SearchProtect.) – C:Program Files (x86)SearchProtectupdateSearchProtect.exe
SR – | Auto 15/11/2013 66336 | (Util SearchProtect) . (.Client Connect LTD – SearchProtect.) – C:Program Files (x86)SearchProtectbinutilSearchProtect.exe
SR – | Auto 2014-05-23 2497856 | (CltMngSvc) . (.Client Connect LTD.) – C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe
HKLMSOFTWAREMicrosoftTracingSearchProtect_RASAPI32
HKLMSOFTWAREMicrosoftTracingSearchProtect_RASMANCS
HKLMSOFTWAREMicrosoftTracingSearchProtect_RASAPI32
HKLMSOFTWAREMicrosoftTracingSearchProtect_RASMANCS
HKLMSOFTWAREMicrosoftTracingupdateSearchProtect_RASAPI32
HKLMSOFTWAREMicrosoftTracingupdateSearchProtect_RASMANCS
HKLMSOFTWAREMicrosoftTracingutilSearchProtect_RASAPI32
HKLMSOFTWAREMicrosoftTracingutilSearchProtect_RASMANCS

C:Program FilesSearchProtect
C:Program Files (x86)SearchProtect
C:Program Files (x86)SearchProtectSearchProtectbincltmng.exe
C:Program Files (x86)SearchProtectUIbincltmngui.exe
C:Program Files (x86)SearchProtectMainbinCltMngSvc.exe

Alias

PUP.Optional.SearchProtect.A
PUP.Optional.Sambreel
Adware.SearchProtect
Adware.SuperWeb
Adware.Sambreel

Remove Software

– Remove extension of all installed browsers
– Remove the plugin of all installed browsers,
– Remove software in Windows Configuration Panel,

Remove with ZHPcleaner

Diagnose with ZHPDiag

1 Vote2 Votes3 Votes4 Votes5 Votes (No Ratings Yet)
SOSVirusLoading...

Leave a Comment