Home Possibly Unwanted Program PUP.IFEO

PUP.IFEO

Posted: March 16, 2015

Threat Metric

Ranking: 2,937
Threat Level: 1/10
Infected PCs: 153,468
First Seen: March 16, 2015
Last Seen: March 10, 2025
OS(es) Affected: Windows

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{RegistryKeys}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe\DebuggerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdaterService.exe\DebuggerSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hayzumflex.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflipSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\l2.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Plusdax.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Subair.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaroSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteeraSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Plusdax.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Zaamla.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdate.exe\DebuggerSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GoogleUpdaterService.exe\DebuggerSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Hayzumflex.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflipSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\l2.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Plusdax.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Subair.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaroSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteeraSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exeSOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Plusdax.exeSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\SilentProcessExit\Zaamla.exe
Loading...