Home Malware Programs Potentially Unwanted Programs (PUPs) RuTube Chrome Extension

RuTube Chrome Extension

Posted: September 12, 2017

Threat Metric

Ranking: 400
Threat Level: 1/10
Infected PCs: 195,451
First Seen: September 13, 2017
Last Seen: October 17, 2023
OS(es) Affected: Windows

The RuTube Chrome Extension is a browser extension that can be installed as part of an adware bundle. In some cases, the installation may be executed automatically. As its name suggests, the RuTube Chrome Extension is targeted at Russian speakers (RuTube is a Russian version of YouTube), and its description reads 'Смотри то, что любишь!,' which can be translated to 'Watch what you love!' While the RuTube Chrome Extension is classified as a Potentially Unwanted Program (PUP) and is not as unsafe as other forms of malware, users are still advised to remove the Ru Tube Chrome Extension as it can have some undesired consequences.

Once installed, the RuTube Chrome Extension has the necessary permissions to read and change all of the user's data on any visited website. This means that the Ru Tube Chrome Extension may start collecting the user's Internet history and browsing habits. Furthermore, this PUP may change the default search settings resulting in unwanted redirects. Through ads displayed on these redirected sites, the authors of the RuTube Chrome Extension may generate revenue. Additional revenue may be generated through the injection of sponsored links in the displayed search results. The data that may be gathered from the user also may be sold.

If you notice that the RuTube Chrome Extension appears in your browser suddenly or if you see any ads for the program, it could be a sign that your system has been infiltrated by additional adware. It is strongly advised to remove such PUPs from your computer with a legitimated security software.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

File name without pathhttps_rutube.ru_0.localstoragehttps_rutube.ru_0.localstorage-journal

Additional Information

The following URL's were detected:
/rutube.ru/
Loading...