Home Malware Programs Potentially Unwanted Programs (PUPs) Express Find

Express Find

Posted: May 21, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 2,387
First Seen: March 23, 2015
Last Seen: February 5, 2023
OS(es) Affected: Windows

The Express Find browser plug-in is another adware by the infamous Yontoo Technology, Inc. that is being deployed in freeware bundles under the 'Advanced' or 'Custom' option. The Express Find software may claim to help you search faster on Bing and Google, but it might change your default search engine and homepage. Additionally, the Express Find adware powered plug-in might present you with numerous commercials, coupons and discounts loaded on banners and pop-up windows. Security analysts add that the Express Find adware may add a task in the Windows Task Scheduler to update its binary and may introduce other adware on your OS like the Sale Charger and the Plumoweb. You should note that the Express Find adware may use tracking cookies and record your URL input in order to execute behavioral advertising and supply you with promotions suited to your interests. Security analysts add that the Express Find adware may redirect users to harmful domains and insecure content. Therefore, you may wish to install a credible anti-spyware solution to erase all files associated with the Express Find adware on your PC.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{1EECA870-D9EB-4E21-A571-577388F04054}Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d39539bb-f65e-4088-a9d1-6e5f01a42a3e}SYSTEM\ControlSet001\Services\Service Mgr ExpressFindSYSTEM\ControlSet001\Services\Update Mgr ExpressFindSYSTEM\ControlSet002\Services\Service Mgr ExpressFindSYSTEM\ControlSet002\Services\Update Mgr ExpressFindSYSTEM\CurrentControlSet\Services\Service Mgr ExpressFindSYSTEM\CurrentControlSet\Services\Update Mgr ExpressFindHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Express Find

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\77790361-426c-4fa2-8cf3-5994543d685d%ALLUSERSPROFILE%\Application Data\77790361-426c-4fa2-8cf3-5994543d685d%PROGRAMFILES%\Common Files\77790361-426c-4fa2-8cf3-5994543d685d%PROGRAMFILES%\Express Find%PROGRAMFILES(x86)%\Common Files\77790361-426c-4fa2-8cf3-5994543d685d%PROGRAMFILES(x86)%\Express Find%TEMP%\Express Find