Home Malware Programs Potentially Unwanted Programs (PUPs) Your Packages Now

Your Packages Now

Posted: March 28, 2016

Threat Metric

Ranking: 4,286
Threat Level: 5/10
Infected PCs: 9,322
First Seen: December 11, 2015
Last Seen: October 16, 2023
OS(es) Affected: Windows

Your Packages Now by Yontoo Technology, Inc is a Potentially Unwanted Program (PUP) that the majority of PC users prefer to delete shortly after it enters. This questionable application may cause a variety of changes in the present Web browsers. Its ultimate goal is not to assist the users but to make them visit sponsored domains. The developer of Your Packages Now promotes it as a suitable solution for all users who want to track their UPS or FedEx shipments. In theory, this software is supposed to provide real-time data about the status of your delivery. However, you have no reason whatsoever to install the PUP. All it does is to include a toolbar that contains buttons for fast access to the sites of the listed package delivery companies. You can visit these pages directly or create bookmarks for them, so there is no need to install the toolbar. The lack of real utility is not the only reason to ignore the PUP. Your Packages Now has some typical adware features as well. It may bombard Google Chrome, Mozilla Firefox and Internet Explorer with tons of unwanted commercial materials. They may take the shape of pop-ups, banners, interstitial and transitional ads. The suspicious tool also may replace your homepage. The PUP is known to interfere with the searching experience of the user by placing a few sponsored links above the other results. Some of these ads may correspond to your interests pretty accurately. Your Packages Now may have access to almost everything you do when you are online. Your Packages Now may see your surfing and searching histories, which may provide enough data about the content that may interest you. Your Packages Now cannot read your passwords. It is not safe to click on the ads for security reasons. In case you decide to check the offers and deals that Your Packages Now may generate, you should be extremely careful not to install any software that may harm your PC. The numerous ads may lead to annoying functionality problems, so you should use special security software to delete the PUP.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\appdata\local\apps\2.0\z9xbtcc1.5b3\7h0xhmee.vjd\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9 File name: C:\Users\<username>\appdata\local\apps\2.0\z9xbtcc1.5b3\7h0xhmee.vjd\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9
Mime Type: unknown/0000_bc0f30a01021d6f9
Group: Malware file
C:\Users\<username>\appdata\Local\Apps\2.0\Z9XBTCC1.5B3\7H0XHMEE.VJD\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9\My Email XP.exe /u "Your Package File name: C:\Users\<username>\appdata\Local\Apps\2.0\Z9XBTCC1.5B3\7H0XHMEE.VJD\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9\My Email XP.exe /u "Your Package
Mime Type: unknown/exe /u "Your Package
Group: Malware file
Newtonsoft.Json.dll File name: Newtonsoft.Json.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
C:\Users\<username>\appdata\local\apps\2.0\z9xbtcc1.5b3\7h0xhmee.vjd\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9\my email xp.exe File name: C:\Users\<username>\appdata\local\apps\2.0\z9xbtcc1.5b3\7h0xhmee.vjd\your..snow_3fc9ac0b77bf2b60_0001.0000_bc0f30a01021d6f9\my email xp.exe
MD5: 1bdc7b24cf36228ab8e828da2584da3b
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Additional Information

The following URL's were detected:
yourpackagesnow.com
Loading...