Home Possibly Unwanted Program PUP.IFEO

PUP.IFEO

Posted: March 16, 2015

Threat Metric

Ranking: 1,929
Threat Level: 1/10
Infected PCs: 151,173
First Seen: March 16, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe\DebuggerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdaterService.exe\DebuggerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hayzumflex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflipSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\l2.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Plusdax.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Subair.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaroSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteeraSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Plusdax.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Zaamla.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe\DebuggerSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdaterService.exe\DebuggerSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hayzumflex.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflipSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\l2.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Plusdax.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Subair.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaroSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteeraSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Plusdax.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Zaamla.exe
Loading...