Home Malware Programs Potentially Unwanted Programs (PUPs) Fresh Outlook

Fresh Outlook

Posted: June 26, 2015

Threat Metric

Ranking: 13,459
Threat Level: 2/10
Infected PCs: 1,389
First Seen: June 26, 2015
Last Seen: September 6, 2023
OS(es) Affected: Windows

Fresh Outlook is a suspicious browser add-on, created and distributed by the infamous company SuperWeb LLC. Similarly to the other products by this software developer, Fresh Outlook is associated with an adware activity. Although the authors claim that their application will cause positive modifications to the browsers, the majority of users have enough reasons to disagree. Fresh Outlook creates advertisements in different formats – including pop-ups, banners, in-text ads and interstitial ads. The Potentially Unwanted Program (PUP) also alters the legitimate search results and inserts sponsored links. This behavior may have unpleasant effects on the functionality of your Internet clients, no matter if you use Google Chrome, Mozilla Firefox or Internet Explorer. Although some offers and discounts may attract your interest, you should abstain from clicking on the marketing materials. SuperWeb LLC doesn't have a history of carefully choosing its partners, so some promoted pages may be dangerous. The download button on the official page of the product, which is freshestoutlook.com, doesn't work properly. Instead of direct downloads, SuperWeb LLC spreads its programs as additions to other free applications. This method explains why some users cannot remember loading Fresh Outlook intentionally. As this adware is usually of no help to its clients, you should delete it with a credible security application as soon as you notice it.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{6CD9547F-0F4A-4872-A7DE-9BA536B52A14}{A4078544-F9E1-468A-84A8-E93ABAADBEAE}{a542f0e9-b62a-4bd8-bcc8-06bad0c5f435}File name without pathapi.freshestoutlook[1].xmlapifreshestoutlo-a.akamaihd[1].xmlhttps_api.freshestoutlook.com_0.localstorageHKEY..\..\..\..{RegistryKeys}SOFTWARE\Fresh OutlookSoftware\Microsoft\Internet Explorer\Approved Extensions\{A542F0E9-B62A-4BD8-BCC8-06BAD0C5F435}Software\Microsoft\Internet Explorer\Approved Extensions\{b4e2a505-3819-470f-9bcf-dcd8bead1771}Software\Microsoft\Internet Explorer\Approved Extensions\{f9b0dee4-c19a-48f5-a772-545772efda27}Software\Microsoft\Internet Explorer\DOMStorage\api.freshestoutlook.comSoftware\Microsoft\Internet Explorer\DOMStorage\apifreshestoutlo-a.akamaihd.netSoftware\Microsoft\Internet Explorer\DOMStorage\freshestoutlook.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\api.freshestoutlook.comSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\apifreshestoutlo-a.akamaihd.netSoftware\Microsoft\Internet Explorer\LowRegistry\DOMStorage\freshestoutlook.comSOFTWARE\Microsoft\Tracing\updateFreshOutlook_RASAPI32SOFTWARE\Microsoft\Tracing\updateFreshOutlook_RASMANCSSOFTWARE\Microsoft\Tracing\utilFreshOutlook_RASAPI32SOFTWARE\Wow6432Node\Fresh OutlookSOFTWARE\Wow6432Node\Microsoft\Tracing\updateFreshOutlook_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateFreshOutlook_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilFreshOutlook_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilFreshOutlook_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update Fresh OutlookSYSTEM\ControlSet001\services\eventlog\Application\Util Fresh OutlookSYSTEM\ControlSet001\services\Update Fresh OutlookSYSTEM\ControlSet001\services\Util Fresh OutlookSYSTEM\CurrentControlSet\services\eventlog\Application\Update Fresh OutlookSYSTEM\CurrentControlSet\services\eventlog\Application\Util Fresh OutlookSYSTEM\CurrentControlSet\services\Update Fresh OutlookSYSTEM\CurrentControlSet\services\Util Fresh OutlookHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Fresh Outlook

Additional Information

The following directories were created:
%PROGRAMFILES%\Fresh Outlook%PROGRAMFILES(x86)%\Fresh Outlook%Temp%\Fresh Outlook
The following URL's were detected:
freshestoutlook.com
Loading...