Home Malware Programs Adware Hold Page

Hold Page

Posted: November 24, 2014

Threat Metric

Ranking: 7,735
Threat Level: 2/10
Infected PCs: 7,987
First Seen: November 24, 2014
Last Seen: September 29, 2023
OS(es) Affected: Windows

Hold Page is a browser extension that provides you with attractive coupons, deals, and offers. However, Hold Page is considered adware that aggressively displays numerous pop-ups, ads, banners, and coupons over the entire surface of user's web browser. Hold Page extension may impair you browsing experience and track your online habits in order to help its sponsors develop better marketing strategies. Adware such as Hold Page is bundled with freeware, and computer users should use the 'Custom' or 'Advanced' option to reveal additional programs in installers. Users may want to remove Hold Page from their system using a trusted anti-spyware solution.

Aliases

Generic.225 [AVG]

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Hold Page\bin\utilHoldPage.exe File name: utilHoldPage.exe
Size: 524.01 KB (524016 bytes)
MD5: 5a78b4ff176ff76240a3ea2ac0d2ade6
Detection count: 546
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\Hold Page\bin
Group: Malware file
Last Updated: October 23, 2021
%PROGRAMFILES%\Hold Page\bin\utilHoldPage.exe File name: utilHoldPage.exe
Size: 524.01 KB (524016 bytes)
MD5: 0ec1d93e484a90d4dc3832dede2865ab
Detection count: 525
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Hold Page\bin
Group: Malware file
Last Updated: December 4, 2014

Registry Modifications

The following newly produced Registry Values are:

CLSID{180BD92C-7EC0-4CF9-9329-7CEA0405B796}{6c14185e-4de6-4a79-985b-19f23fd1e638}{9B0B3C08-2AC3-43AD-AC78-3DB45181A1E1}{9D1B61FF-B675-445A-A94C-4377E9B6AECD}{bd324f55-add4-4b16-869d-382bd74747b9}{F3F93F63-9570-44B4-9A6C-9976FA78CBF5}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Hold PageSoftware\Microsoft\Internet Explorer\Approved Extensions\{6c14185e-4de6-4a79-985b-19f23fd1e638}Software\Microsoft\Internet Explorer\Approved Extensions\{BD324F55-ADD4-4B16-869D-382BD74747B9}SOFTWARE\Microsoft\Tracing\updateHoldPage_RASAPI32SOFTWARE\Microsoft\Tracing\updateHoldPage_RASMANCSSOFTWARE\Microsoft\Tracing\utilHoldPage_RASAPI32SOFTWARE\Microsoft\Tracing\utilHoldPage_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{6c14185e-4de6-4a79-985b-19f23fd1e638}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6c14185e-4de6-4a79-985b-19f23fd1e638}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6c14185e-4de6-4a79-985b-19f23fd1e638}SOFTWARE\Wow6432Node\Hold PageSOFTWARE\Wow6432Node\Microsoft\Tracing\updateHoldPage_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updateHoldPage_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\utilHoldPage_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\utilHoldPage_RASMANCSSYSTEM\ControlSet001\services\eventlog\Application\Update Hold PageSYSTEM\ControlSet001\services\eventlog\Application\Util Hold PageSYSTEM\ControlSet001\services\Update Hold PageSYSTEM\ControlSet001\services\Util Hold PageSYSTEM\ControlSet002\services\eventlog\Application\Util Hold PageSYSTEM\ControlSet002\services\Util Hold PageSYSTEM\CurrentControlSet\services\eventlog\Application\Update Hold PageSYSTEM\CurrentControlSet\services\eventlog\Application\Util Hold PageSYSTEM\CurrentControlSet\services\Update Hold PageSYSTEM\CurrentControlSet\services\Util Hold PageHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Hold Page

Additional Information

The following directories were created:
%PROGRAMFILES%\Hold Page%PROGRAMFILES(x86)%\Hold Page%Temp%\Hold Page
Loading...