Home Malware Programs Adware PlurPush

PlurPush

Posted: October 10, 2013

Threat Metric

Threat Level: 2/10
Infected PCs: 2,967
First Seen: October 10, 2013
Last Seen: July 20, 2024
OS(es) Affected: Windows

PlurPush is a legitimate program developed by Super Web LLC, which can be installed and work in Internet Explorer, Mozilla Firefox and Google Chrome web browsers. However, despite that PlurPush is not a malware threat, this application may perform various annoying activities on the computer. Therefore, PlurPush is considered to be a potentially unwanted program/adware. PlurPush may display repeated pop-up messages and ads on the screen of the PC, initiate browser redirects to doubtful websites or slow down the computer system. According to the publisher of PlurPush, this program is created to help save the money for web users, because it delivers alerts informing about discounts, coupons and offers once the computer user accesses any online shopping website. Web users should not rely on these advertisements because mostly they may make the PC user visit affiliated commercial websites. PlurPush can be downloaded from numerous download websites. However, it may also enter the vulnerable computer without the PC owner knowing about it. PlurPush may come bundled with freeware and shareware applications, and invade the computers as a free addition. In order to evade PlurPush, computer users should pay more attention to the installation process of freeware and shareware programs. Usually, PC users should choose a 'Custom' or 'Advanced' installation method and uncheck the option, which agrees with the installation of PlurPush. No matter that PlurPush conceals itself from the PC user when it strives to invade the computer, it starts occurring as soon as it enters the PC.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

CLSID{089EDE16-F82F-4CB5-B64E-433860459D81}{6A9F605F-89D1-4AF7-8747-2A17F002E20E}{82249076-d5c8-431d-982b-023779779587}HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Tracing\PlurPush_RASAPI32SOFTWARE\Microsoft\Tracing\PlurPush_RASMANCSSOFTWARE\Microsoft\Tracing\updatePlurPush_RASAPI32SOFTWARE\Microsoft\Tracing\updatePlurPush_RASMANCSSOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{82249076-d5c8-431d-982b-023779779587}Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82249076-D5C8-431D-982B-023779779587}Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82249076-D5C8-431D-982B-023779779587}Software\PlurPushSOFTWARE\Wow6432Node\Microsoft\Tracing\PlurPush_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\PlurPush_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\updatePlurPush_RASAPI32SOFTWARE\Wow6432Node\Microsoft\Tracing\updatePlurPush_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{82249076-d5c8-431d-982b-023779779587}SOFTWARE\Wow6432Node\PlurPushSYSTEM\ControlSet001\services\eventlog\Application\Update PlurPushSYSTEM\ControlSet001\services\Update PlurPushSYSTEM\ControlSet001\services\Util PlurPushSYSTEM\ControlSet002\services\eventlog\Application\Update PlurPushSYSTEM\ControlSet002\services\Update PlurPushSYSTEM\ControlSet002\services\Util PlurPushSYSTEM\CurrentControlSet\services\eventlog\Application\Update PlurPushSYSTEM\CurrentControlSet\services\Update PlurPushHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}PlurPush

Additional Information

The following directories were created:
%PROGRAMFILES%\PlurPush%PROGRAMFILES(x86)%\PlurPush
The following URL's were detected:
PlurPush
Loading...