Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Browsers+_App+_Pro+

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,514 posts
Content is republished with permission from Malwarebytes.

What is Browsers+_App+_Pro+?
 
The Malwarebytes research team has determined that Browsers+_App+_Pro+ is a browser hijacker. These so-called "hijackers" manipulate your browser(s), for example to change your startpage or searchscopes, so that the affected browser visits their site or one of their choice. This one also displays advertisements.
 
How do I know if my computer is affected by Browsers+_App+_Pro+?
 
You may see these browser extensions/add-ons:
 
warning1.png
 
warning2.png

warning3.png
 
and this entry in your list of installed programs:
 
warning4.png
 
 
How did Browsers+_App+_Pro+ get on my computer?
 
Browser hijackers use different methods for distributing themselves. This particular one was bundled with other software.
 
How do I remove Browsers+_App+_Pro+?
 
Our program Malwarebytes Anti-Malware can detect and remove this potentially unwanted application.
  • Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup-version.exe and follow the prompts to install the program.
  • At the end, be sure a check-mark is placed next to the following:
    • Enable free trial of Malwarebytes Anti-Malware Premium
    • Launch Malwarebytes Anti-Malware
  • Then click Finish.
  • If an update is found, you will be prompted to download and install the latest version.
  • Once the program has loaded, select Scan now. Or select the Threat Scan from the Scan menu.
  • When the scan is complete , make sure that everything is set to "Quarantine", and click Apply Actions.
  • Reboot your computer if prompted.
Is there anything else I need to do to get rid of Browsers+_App+_Pro+?
  • If you are using Opera, you may have to remove the Extension manually under Opera > Extensions click the x behind Browsers+_App+_Pro+ and click OK in the prompt to confirm.
How would the full version of Malwarebytes Anti-Malware help protect me?
 
We hope our application and this guide have helped you eradicate this hijacker.  
 
As you can see below the full version of Malwarebytes Anti-Malware would have protected you against the Browsers+_App+_Pro+ hijacker.  It would have warned you before the rogue could install itself, giving you a chance to stop it before it became too late.
 
 

protection1.png


 
Technical details for experts
 
Signs in a HijackThis log:
 
 

O2 - BHO: 8d6c6b503bec4fef8265c6850bf8e3d80065055 - {11111111-1111-1111-1111-110611501155} - C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bho.dll
 
Alterations made by the installer:
 

 
File system details  
---------------------------------------------
    Adds the folder C:\Program Files\Browsers+_App+_Pro+
       Adds the file 1293297481.mxaddon"="8/14/2014 6:46 PM, 44330 bytes, A
       Adds the file 243b0fc7-b9e9-4275-8a66-adae7831cb12.exe"="9/26/2014 9:22 AM, 32160 bytes, A
       Adds the file 370a7d99-2f01-48eb-b3c8-c263d28f13f5.crx"="9/26/2014 9:22 AM, 251837 bytes, A
       Adds the file 6dcefde1-2842-4b29-aaf4-8c23ede5723c.exe"="9/26/2014 9:22 AM, 328096 bytes, A
       Adds the file background.html"="9/22/2014 4:00 PM, 729 bytes, A
       Adds the file Browsers+_App+_Pro+.ico"="9/22/2014 4:00 PM, 15086 bytes, A
       Adds the file Browsers+_App+_Pro+-bg.exe"="9/26/2014 9:22 AM, 545184 bytes, A
       Adds the file Browsers+_App+_Pro+-bho.dll"="9/26/2014 9:22 AM, 523168 bytes, A
       Adds the file Browsers+_App+_Pro+-codedownloader.exe"="9/26/2014 9:22 AM, 1059232 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e.crx"="9/26/2014 9:22 AM, 250638 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e.xpi"="9/26/2014 9:22 AM, 290879 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.exe"="9/26/2014 9:22 AM, 1901472 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.exe"="9/26/2014 9:22 AM, 885664 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-4.exe"="9/26/2014 9:22 AM, 1450400 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.exe"="9/26/2014 9:22 AM, 820640 bytes, A
       Adds the file Interop.IWshRuntimeLibrary.dll"="9/26/2014 9:22 AM, 53664 bytes, A
       Adds the file Newtonsoft.Json.dll"="9/26/2014 9:22 AM, 495520 bytes, A
       Adds the file SuperSocket.ClientEngine.Common.dll"="9/26/2014 9:22 AM, 23456 bytes, A
       Adds the file SuperSocket.ClientEngine.Core.dll"="9/26/2014 9:22 AM, 26528 bytes, A
       Adds the file SuperSocket.ClientEngine.Protocol.dll"="9/26/2014 9:22 AM, 19872 bytes, A
       Adds the file Uninstall.exe"="9/26/2014 9:21 AM, 87456 bytes, A
       Adds the file utils.exe"="9/26/2014 9:21 AM, 2482903 bytes, A
       Adds the file WebSocket4Net.dll"="9/26/2014 9:22 AM, 64416 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com
       Adds the file chrome.manifest"="9/26/2014 9:22 AM, 438 bytes, A
       Adds the file install.rdf"="9/26/2014 9:22 AM, 1199 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\hoidflomjnnnbiemmkjdjkkialmhbago\1.26.9_0
    In the existing folder C:\Windows\System32\Tasks
       Adds the file 243b0fc7-b9e9-4275-8a66-adae7831cb12"="9/26/2014 9:22 AM, 3612 bytes, A
       Adds the file 6dcefde1-2842-4b29-aaf4-8c23ede5723c"="9/26/2014 9:22 AM, 4416 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1"="9/26/2014 9:22 AM, 5810 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11"="9/26/2014 9:22 AM, 7524 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2"="9/26/2014 9:22 AM, 5138 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5"="9/26/2014 9:22 AM, 5474 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user"="9/26/2014 9:22 AM, 5480 bytes, A
    In the existing folder C:\Windows\Tasks
       Adds the file 243b0fc7-b9e9-4275-8a66-adae7831cb12.job"="9/26/2014 9:22 AM, 576 bytes, A
       Adds the file 6dcefde1-2842-4b29-aaf4-8c23ede5723c.job"="9/26/2014 9:22 AM, 1386 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1.job"="9/26/2014 9:22 AM, 2780 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.job"="9/26/2014 9:22 AM, 4494 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.job"="9/26/2014 9:22 AM, 2108 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.job"="9/26/2014 9:22 AM, 2444 bytes, A
       Adds the file c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user.job"="9/26/2014 9:22 AM, 2444 bytes, A
 
Registry details  
------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Browsers+_App+_Pro+\Firefox]
       "TotalProfiles"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Browsers+_App+_Pro+\Firefox\Profiles]
       "C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Browsers+_App+_Pro+\IE]
       "TotalProfiles"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Browsers+_App+_Pro+\IE\Profiles]
       "S-1-5-21-4016700205-1717049133-1125222536-1001"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Browsers+_App+_Pro+\Installer]
       "BundledAddCh"="REG_DWORD", 1
       "BundledFirefox"="REG_DWORD", 1
       "BundledIe"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO\CLSID]
       "(Default)"="REG_SZ", "{11111111-1111-1111-1111-110611501155}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO\CurVer]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO.1]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO.1\CLSID]
       "(Default)"="REG_SZ", "{11111111-1111-1111-1111-110611501155}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox\CLSID]
       "(Default)"="REG_SZ", "{22222222-2222-2222-2222-220622502255}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox\CurVer]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox.1]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox.1\CLSID]
       "(Default)"="REG_SZ", "{22222222-2222-2222-2222-220622502255}"
   [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}]
       "(Default)"="REG_SZ", "Browsers+_App+_Pro+"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\Implemented Categories]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
       "(Default)"="REG_SZ", ""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bho.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\ProgID]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO.1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644504455}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611501155}\VersionIndependentProgID]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}\InprocServer32]
       "(Default)"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bho.dll"
       "ThreadingModel"="REG_SZ", "Apartment"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}\ProgID]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox.1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}\Programmable]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644504455}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622502255}\VersionIndependentProgID]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655505555}]
       "(Default)"="REG_SZ", "ICrossriderBHO"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655505555}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655505555}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655505555}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644504455}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666506655}]
       "(Default)"="REG_SZ", "ISandBox"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666506655}\ProxyStubClsid]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666506655}\ProxyStubClsid32]
       "(Default)"="REG_SZ", "{00020424-0000-0000-C000-000000000046}"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666506655}\TypeLib]
       "(Default)"="REG_SZ", "{44444444-4444-4444-4444-440644504455}"
       "Version"="REG_SZ", "1.0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644504455}\1.0]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055 Type Library"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644504455}\1.0\0\win32]
       "(Default)"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bho.dll"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644504455}\1.0\FLAGS]
       "(Default)"="REG_SZ", "0"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644504455}\1.0\HELPDIR]
       "(Default)"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+"
    [HKEY_LOCAL_MACHINE\SOFTWARE\InstalledBrowserExtensions\21636]
       "65055"="REG_SZ", "Browsers+_App+_Pro+"
    [HKEY_LOCAL_MACHINE\SOFTWARE\InstalledBrowserExtensions\21636\Status]
       "Installed"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]
       "Browsers+_App+_Pro+-bg.exe"="REG_DWORD", 8000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611501155}]
       "(Default)"="REG_SZ", "8d6c6b503bec4fef8265c6850bf8e3d80065055"
       "NoExplorer"="REG_DWORD", 1
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID]
       "{11111111-1111-1111-1111-110611501155}"="REG_SZ", "1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browsers+_App+_Pro+]
       "CrAppId"="REG_SZ", "65055"
       "CrPublisherId"="REG_SZ", "21636"
       "DisplayIcon"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+\utils.exe"
       "DisplayName"="REG_SZ", "Browsers+_App+_Pro+"
       "DisplayVersion"="REG_SZ", "1.35.9.16"
       "Publisher"="REG_SZ", "browser"
       "UninstallString"="REG_SZ", "C:\Program Files\Browsers+_App+_Pro+\Uninstall.exe /fcp=1"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\CompatibilityAdapter\Signatures]
       "243b0fc7-b9e9-4275-8a66-adae7831cb12.job"="REG_BINARY, ................................
       "243b0fc7-b9e9-4275-8a66-adae7831cb12.job.fp"="REG_DWORD", -537220893
       "6dcefde1-2842-4b29-aaf4-8c23ede5723c.job"="REG_BINARY, ................................
       "6dcefde1-2842-4b29-aaf4-8c23ede5723c.job.fp"="REG_DWORD", -1403048340
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1.job"="REG_BINARY, ................................
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1.job.fp"="REG_DWORD", 1217883093
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.job"="REG_BINARY, ................................
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.job.fp"="REG_DWORD", -1794375052
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.job"="REG_BINARY, ................................
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.job.fp"="REG_DWORD", -1035638533
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.job"="REG_BINARY, ................................
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.job.fp"="REG_DWORD", -1623574319
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user.job"="REG_BINARY, ................................
       "c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user.job.fp"="REG_DWORD", -592514713
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+]
       "ActiveAppId"="REG_SZ", "65055"
       "BhoRunningVersion"="REG_SZ", "154"
       "IsBhoEnabled"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+\Background]
       " { javascript removed, full log available by request } "
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+\Debug]
       "DebuggedAppUrl"="REG_SZ", "file://C:\Users\{username}\Documents\debug.js"
       "DebuggedBgUrl"="REG_SZ", "file://C:\Users\{username}\Documents\bg_debug.js"
       "DebuggedNewTabUrl"="REG_SZ", "file://C:\Users\{username}\Documents\new_debug.js"
       "IsDebuggingPlugins"="REG_DWORD", 0
       "IsDebugMode"="REG_DWORD", 0
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+\Installer]
       "AdditionalInfo"="REG_SZ", "{"asw":[67108864, -1073733563, 0],"browser_name":"ie"}"
       "CodeDownloadDomain"="REG_SZ", "http://js.newclientstaticsrv.com"
       "CodeDownloadFbDomain"="REG_SZ", "http://js.clientdemocloud.com"
       "DefaultBrowser"="REG_SZ", "opera"
       "ErrorsDomain"="REG_SZ", "http://errors.newclientstaticsrv.com"
       "FullVersion"="REG_SZ", "1.35.9.16"
       "FullVersionForUrl"="REG_SZ", "1_35_09_16"
       "OsName"="REG_SZ", "7"
       "Params"="REG_SZ", "{   "source_id" : "002142",   "sub_id" : "0",   "uzid" : "0"}"
       "SrcId"="REG_SZ", "002142"
       "StatsDomain"="REG_SZ", "http://stats.newclientstaticsrv.com"
       "SubId"="REG_SZ", "0"
       "Time"="REG_SZ", "1411716116"
       "ZData"="REG_SZ", "0"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+\Manifest]
       "AddressbarURL"="REG_SZ", "NA"
       "BgVersion"="REG_SZ", "1"
       "ChangePrevious"="REG_SZ", "false"
       "Description"="REG_SZ", "Enhancing browsing experience"
       "DisableIe"="REG_SZ", "true"
       "EnableSearchIE"="REG_SZ", "false"
       "HomePageUrl"="REG_SZ", "NA"
       "IsButtonEnabled"="REG_SZ", "false"
       "Manifest"="REG_SZ", "NA"
       "ModeType"="REG_SZ", "production"
       "Name"="REG_SZ", "Browsers+_App+_Pro+"
       "PluginsManifestVersion"="REG_SZ", "4"
       "PublisherId"="REG_SZ", "21636"
       "PublisherName"="REG_SZ", "browser"
       "RunInFrame"="REG_SZ", "false"
       "SetNewTab"="REG_SZ", "false"
       "ThanksUrl"="REG_SZ", "NA"
       "UninstallerOfferAction"="REG_SZ", "NA"
       "UninstallerOfferUrl"="REG_SZ", "NA"
       "UpdateInterval"="REG_DWORD", 360
       "Version"="REG_SZ", "9"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Browsers+_App+_Pro+\Update]
       "LastCheck"="REG_DWORD", 1411716141
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider]
       "Bic"="REG_SZ", "5455FADC9B4940C2AEECEB157240C517IE"
       "Verifier"="REG_SZ", "9162205d0c70c2fe4587647b4e9e40a3"
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider\onBeforeNavigate]
       "65055"="REG_SZ", ""
    [HKEY_CURRENT_USER\Software\AppDataLow\Software\Crossrider\onRequest]
       "65055"="REG_SZ", ""
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\21636]
       "65055"="REG_SZ", "Browsers+_App+_Pro+"
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\21636\Status]
       "Installed"="REG_DWORD", 1
    [HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\browser]
       "65055"="REG_SZ", "Browsers+_App+_Pro+"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611501155}]
       "Flags"="REG_DWORD", 1024
 
Malwarebytes Anti-Malware log:
 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 9/26/2014
Scan Time: 9:31:01 AM
Logfile: mbamBrowser+App+Pro.txt
Administrator: Yes
 
Version: 2.00.2.1012
Malware Database: v2014.09.26.03
Rootkit Database: v2014.09.19.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Malwarebytes
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 269184
Time Elapsed: 3 min, 0 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 2
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\6dcefde1-2842-4b29-aaf4-8c23ede5723c.exe, 2624, Delete-on-Reboot, [ec4f10e25e1de650b18fcf70f90c6d93]
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\243b0fc7-b9e9-4275-8a66-adae7831cb12.exe, 2772, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779]
 
Modules: 6
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Interop.IWshRuntimeLibrary.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Newtonsoft.Json.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Common.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Core.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Protocol.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\WebSocket4Net.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
 
Registry Keys: 37
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611501155}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{44444444-4444-4444-4444-440644504455}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{55555555-5555-5555-5555-550655505555}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{66666666-6666-6666-6666-660666506655}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO.1, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{11111111-1111-1111-1111-110611501155}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\8d6c6b503bec4fef8265c6850bf8e3d80065055.BHO, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{11111111-1111-1111-1111-110611501155}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{11111111-1111-1111-1111-110611501155}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{22222222-2222-2222-2222-220622502255}, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox.1, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\8d6c6b503bec4fef8265c6850bf8e3d80065055.Sandbox, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowserApps.A, HKLM\SOFTWARE\CLASSES\CLSID\{11111111-1111-1111-1111-110611501155}\INPROCSERVER32, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.BrowsersApp.A, HKLM\SOFTWARE\Browsers+_App+_Pro+, Quarantined, [4dee07ebf18a290d8fbbe299867e4eb2], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE, Quarantined, [cd6efff3bfbca98d5fa8f226b74c43bd], 
PUP.Optional.CrossRider.A, HKLM\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, Quarantined, [201b7a782754c17525074be8fb0817e9], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=10, Quarantined, [88b3c42ec4b7082e7f87d7a2758f11ef], 
PUP.Optional.GlobalUpdate.A, HKLM\SOFTWARE\MOZILLAPLUGINS\@staging.google.com/globalUpdate Update;version=4, Quarantined, [5edd29c9c3b8ca6c3ccba2d7b64e8779], 
PUP.Optional.BrowsersApp.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Browsers+_App+_Pro+, Quarantined, [162582700c6f50e636128fecd133d729], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, Quarantined, [9ba06a88f9823402b561d793e91ba65a], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\21636, Quarantined, [b388b43e74076ccaddc06aa1bb48926e], 
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLEDBROWSEREXTENSIONS\browser, Quarantined, [f348d71bf08bfa3c3180899061a255ab], 
PUP.Optional.Superfish.A, HKU\S-1-5-21-4016700205-1717049133-1125222536-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\DOMSTORAGE\superfish.com, Quarantined, [0635b73bbcbfaa8c2a1bbebd9173da26], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdate, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\globalUpdatem, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\IMAGE FILE EXECUTION OPTIONS\GOOGLEUPDATE.EXE, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.OneClickCtrl.10, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5645E0E7-FC12-43BF-A6E4-F9751942B298}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\globalUpdate.Update3WebControl.4, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{CFC47BB5-5FB5-4AD0-8427-6AA04334A3FC}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\CLASSES\CLSID\{E0ADB535-D7B5-4D8B-B15D-578BDD20D76A}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.BrowsersApp.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Browsers+_App+_Pro+, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
 
Registry Values: 1
PUP.Optional.GlobalUpdate.T, HKLM\SOFTWARE\GLOBALUPDATE\UPDATE|path, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [cd6efff3bfbca98d5fa8f226b74c43bd]
 
Registry Data: 0
(No malicious items detected)
 
Folders: 21
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Download, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Install, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\Offline\{92B1F623-739F-42A5-800F-C636E5433ABF}, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\defaults, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\defaults\preferences, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\userCode, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\locale, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\locale\en-US, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
 
Files: 168
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\6dcefde1-2842-4b29-aaf4-8c23ede5723c.exe, Delete-on-Reboot, [ec4f10e25e1de650b18fcf70f90c6d93], 
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bho.dll, Quarantined, [f2495f93c8b31620142c49f6867f35cb], 
PUP.Optional.crossRider.A, C:\Users\{username}\Desktop\Browsers+_App+_Pro+.exe, Quarantined, [7ac11ed4bebd92a4ab6fe957a858e917], 
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-bg.exe, Quarantined, [1229fdf57a0148eeab951b240afb659b], 
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+-codedownloader.exe, Quarantined, [ed4ec032d4a77abc97a9ee51ed1857a9], 
PUP.Optional.CrossRider.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.exe, Quarantined, [6ecd0ae86c0fa88e39392b2ade22956b], 
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.exe, Quarantined, [f348a94974071f17132d1a251fe62dd3], 
PUP.Optional.CrossRider.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-4.exe, Quarantined, [c972638fdd9e3afcb2c13b1af30d768a], 
PUP.Optional.BrowserApps.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.exe, Quarantined, [b388ee04c7b48ea846faed52e71e9769], 
PUP.Optional.crossRider.A, C:\Program Files\Browsers+_App+_Pro+\utils.exe, Quarantined, [33082fc36318dd59819965db59a7728e], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1, Quarantined, [1d1e5d95a9d27abc0ef4d246bc47936d], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11, Quarantined, [59e2ad45b6c50d29966cfa1e9172b848], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2, Quarantined, [80bbf4fe007b91a59c66988049ba639d], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5, Quarantined, [41faf3ff8af1142232d0997f8f7430d0], 
PUP.Optional.CrossRider.T, C:\Windows\System32\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user, Quarantined, [2b10d41e9eddf54149b9bb5d699aad53], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-1.job, Quarantined, [3506be34106b979f3f40d1a57d874ab6], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-11.job, Quarantined, [51ea26cc2f4cee487c036214b74d936d], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-2.job, Quarantined, [83b88a68e6951a1c1867df97e222f40c], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5.job, Quarantined, [a09b51a10477e94da4db700645bf01ff], 
PUP.Optional.CrossRider.T, C:\Windows\Tasks\c8e9752e-1f56-48bd-94ed-9e8e7f17088e-5_user.job, Quarantined, [b4875a982b50c27496e986f0ca3a0000], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineCore.job, Quarantined, [3506ca28a5d64bebeaabd5a1a460a55b], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineCore, Quarantined, [85b6ad45611a54e24e480c6ae4209b65], 
PUP.Optional.GlobalUpdate.A, C:\Windows\Tasks\globalUpdateUpdateTaskMachineUA.job, Quarantined, [79c2ed05d4a72610920591e57292af51], 
PUP.Optional.GlobalUpdate.A, C:\Windows\System32\Tasks\globalUpdateUpdateTaskMachineUA, Quarantined, [aa9109e93b404bebfa9ef97d5ca8ed13], 
PUP.Optional.CrossRider.A, C:\Windows\Tasks\243b0fc7-b9e9-4275-8a66-adae7831cb12.job, Quarantined, [4eed619188f3181e768ea0d90df7c63a], 
PUP.Optional.CrossRider.A, C:\Windows\Tasks\6dcefde1-2842-4b29-aaf4-8c23ede5723c.job, Quarantined, [f04b866c2a5170c651b30f6ae2228080], 
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\243b0fc7-b9e9-4275-8a66-adae7831cb12, Quarantined, [8bb0539fbdbe54e229dc94e5ef1519e7], 
PUP.Optional.CrossRider.A, C:\Windows\System32\Tasks\6dcefde1-2842-4b29-aaf4-8c23ede5723c, Quarantined, [3407866ccead8aacc93cfa7f758fe818], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\GoogleUpdate.exe, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleCrashHandler.exe, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdate.exe, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateBroker.exe, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateHelper.msi, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\GoogleUpdateOnDemand.exe, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdate.dll, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\goopdateres_en.dll, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\npGoogleUpdate4.dll, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psmachine.dll, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.T, C:\Program Files\globalUpdate\Update\1.3.25.0\psuser.dll, Quarantined, [f4478a68f487d95de76d16df936f8878], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\GoogleCrashHandler.exe, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\GoogleUpdate.exe, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\GoogleUpdateBroker.exe, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\GoogleUpdateHelper.msi, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\GoogleUpdateOnDemand.exe, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\goopdate.dll, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\goopdateres_en.dll, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\npGoogleUpdate4.dll, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\psmachine.dll, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.GlobalUpdate.A, C:\Users\{username}\AppData\Local\Temp\comh.330176\psuser.dll, Quarantined, [77c4539f5b2058de115f1cd9cf333bc5], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\1293297481.mxaddon, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\243b0fc7-b9e9-4275-8a66-adae7831cb12.exe, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\370a7d99-2f01-48eb-b3c8-c263d28f13f5.crx, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\background.html, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Browsers+_App+_Pro+.ico, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e.crx, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\c8e9752e-1f56-48bd-94ed-9e8e7f17088e.xpi, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Interop.IWshRuntimeLibrary.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Newtonsoft.Json.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Common.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Core.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\SuperSocket.ClientEngine.Protocol.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\Uninstall.exe, Quarantined, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.BrowsersApp.A, C:\Program Files\Browsers+_App+_Pro+\WebSocket4Net.dll, Delete-on-Reboot, [c4775c967407aa8c2a59d434e1228779], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome.manifest, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\install.rdf, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\4cd360ae2df59f81730ab4090b77a454.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\5033b031a5c313d23f5cbae947bac791.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\5357b6dc680d82082ddd897c77ec8db9.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\92e55c2a0999512cda83b7709da0a1c5.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\b008b43012ebf7e0aca264dd1a173e04.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\background.html, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\browser.xul, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\dialog.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\fd49a4f376e8237d0984c43f80e0959e.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\ffCoreFilesIndex.txt, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\options.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\options.xul, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\search_dialog.xul, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\80b48fb854f24d1df3c0fe3fbd975237.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\065712e8b0a7afa96fd717f4154f4f4d.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\114edfc4de6c22e4c9f08974db133bfe.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\1462216b4c6248398bc2e33fd466d58f.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\473b2818fda9feda7007223997e8da6a.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\5eb7d9b76fdc393d3560b66372a0056b.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\5f0bbed5277fea9df8371f03fc949476.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\76c999a4ba447147984ee91ff44b99a0.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\7c1052564ee2c246ac1f570018144925.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\ae6e5517418b5dbaefb3a16935bde137.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\b6b8e084ecfc2c7b61067197a98b3dee.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\ba95cb8902764e01d81ed84ce79c1d14.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\bca1baba5d8519234d95a5f3e653818e.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\c5b9fd7bbffc0e6bd376a148b7f6f6cc.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\c9ed2eb70b8f116815a7dd5249966353.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\api\dd0de995b2389ae20faa6a191a683049.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\016c829e5e7e1f22f4684b3e3fcb3fc9.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\05644e28764f05155de302691158a0f7.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\249805d5c70ccd2eaa1224d7fb8ea372.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\33532a7bb262dbc0a9e14669f1916549.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\415c6630a950f1846e629ed2181672b9.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\42f88d73a83e5dced68a3d9f315f4df1.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\4fcf458d1042d52bd23adc727d4640a6.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\6adf1e1dc3e5f1552ee25a2e585e6b9c.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\6b8e57472dd2542ed24776827652d801.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\709f2fcaffff19a323934e309bc99fd3.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\74a5dc6cf4e5c8d93b758b3fcaa31db3.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\858d1b1c565de167b38ea0e836e07c0c.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\9a0b40fb9fffce0ae7c25a3e70c1a03b.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\9f00529aad1be65771a1e284165aba22.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\9ff0dadbb84ec080f38bd5d0412ba1cd.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\ad92549ac5ed89a618623f7c23238a16.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\b416d696febb690a88dc7bef2db284ae.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\c5b8387451c3e1029540520610808d0f.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\e3071e0bf2e86d1a2b2f170fccc3d90f.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\fa64bed55a03e6ad87a1fcfdb45ee653.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\chrome\content\core\installer.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\defaults\preferences\prefs.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\manifest.xml, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins.json, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\102.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\104.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\13.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\14.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\16.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\17.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\180.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\184.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\192.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\195.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\220.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\221.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\223.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\233.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\242.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\246.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\260.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\262.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\263.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\268.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\273.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\275.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\281.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\289.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\300.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\4.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\47.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\64.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\7.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\78.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\9.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\91.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\plugins\93.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\userCode\background.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\extensionData\userCode\extension.js, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\locale\en-US\translations.dtd, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\button1.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\button2.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\button3.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\button4.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\button5.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\crossrider_statusbar.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\icon128.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\icon16.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\icon24.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\icon48.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\panelarrow-up.png, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\popup.html, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\skin.css, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
PUP.Optional.CrossRider.A, C:\Users\{username}\AppData\Roaming\Mozilla\Firefox\Profiles\6qeoodjs.default-1401006518835\extensions\wrigtdamon@yahoo.com\skin\update.css, Quarantined, [77c427cbe398bd79bcef1bedc73c17e9], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
As mentioned before the full version of Malwarebytes Anti-Malware could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.