Home Malware Programs Adware Package Return Ads

Package Return Ads

Posted: April 27, 2015

Threat Metric

Threat Level: 2/10
Infected PCs: 94
First Seen: April 22, 2015
Last Seen: December 30, 2019
OS(es) Affected: Windows

The Package Return browser tool may claim to deliver useful functionality, but you may want to know that it is perceived by security analysts as adware because it functions as a private ad platform. The adware developers behind Package Return use it to show banners, ad panels and pop-ups in your web browser and profit from your clicks. The Package Return adware is deployed embedded with freeware setup files that most users install via the 'Express' or 'Typical' option. Security analysts note that the Package Return adware may appear as a plugin and a browser extension in order to facilitate its operations. Also, the Package Return adware may use DOM storage data and HTTP cookies to record your search terms and browsing history. The data gathered by the Package Return adware could e used by advertisers to push target marketing content in your web browser and obstruct your comfortable online activities. Moreover, the Package Return adware may feature links to untrusted websites where your cyber security may be at risk. Computer users may want to remove the Package Return adware from their PC by using a credible anti-spyware solution.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}Software\Microsoft\Internet Explorer\Approved Extensions\{0c30d18a-2f9d-49b9-a29d-9480bb2e4f02}SOFTWARE\package returnSOFTWARE\Wow6432Node\package returnSYSTEM\ControlSet001\services\eventlog\Application\Update package returnSYSTEM\ControlSet001\services\eventlog\Application\Util package returnSYSTEM\ControlSet001\services\Update package returnSYSTEM\CurrentControlSet\services\eventlog\Application\Update package returnSYSTEM\CurrentControlSet\services\eventlog\Application\Util package returnSYSTEM\CurrentControlSet\services\Update package return

Additional Information

The following directories were created:
%PROGRAMFILES%\package return%PROGRAMFILES(x86)%\package return%Temp%\package return
Loading...