Jump to content

Welcome to Geeks to Go
Geeks to Go Welcome
Create Account Login to Account
Photo

Removal instructions for Seznam

- - - - -

  • Please log in to reply
No replies to this topic

#1
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 32,407 posts
Content is republished with permission from Malwarebytes.

What is Seznam?

The Malwarebytes research team has determined that Seznam is a bundler. These bundlers typically install potentially unwanted programs (PUPs) or adware on top of the desired software.

How do I know if my computer is affected by Seznam?

You may see these warnings during install:

warning1.png

warning2.png

warning3.png

and these entries in your list of installed Programs and Features:

warning4.png

You may see this type of warnings after the installation:

warning6.png

warning7.png

and this type of browser extensions if you allow them:

warning8.png

How did Seznam get on my computer?

Bundlers use different methods for distributing themselves. This particular one was offered by a software promoting site as a mediaplayer.

How do I remove Seznam?

Our program Malwarebytes can detect and remove this potentially unwanted program.
  • Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
Is there anything else I need to do to get rid of Seznam?
  • No, Malwarebytes removes Seznam completely.
  • If you wish to remove the installed programs and extensions you can use the normal procedure from the Windows Control Panel for the programs. This will also remove the browser extensions.
How would the full version of Malwarebytes help protect me?

We hope our application and this guide have helped you eradicate this bundler.

As you can see below the full version of Malwarebytes would have protected you against the Seznam bundler. It would have blocked the installer before it became too late.

protection1.png


Technical details for experts

Possible signs in FRST logs:
() C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\szndesktop.exe
() C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\listicka-x64.exe
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1069296 2018-03-27] ()
HKCU\...\Run: [cz.seznam.software.autoupdate] => C:\Users\{username}\AppData\Roaming\Seznam.cz\szninstall.exe [1069296 2018-03-27] ()
HKCU\...\Run: [cz.seznam.software.szndesktop] => C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe [109808 2018-03-27] ()
CHR Extension: (Seznam doplněk - Email) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2019-01-14]
CHR Extension: (Seznam doplněk - Esko) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2019-01-14]
CHR HKCU\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bgjpfhpjcgdppjbgnpnjllokbmcdllig] - hxxps://clients2.google.com/service/update2/crx
CHR HKCU\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [olfeabkoenfaoljndfecamgilllcpiak] - hxxps://clients2.google.com/service/update2/crx
C:\Users\{username}\AppData\Roaming\Seznam.cz
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
C:\Program Files\MPC-HC
C:\Program Files (x86)\Seznam.cz

MPC-HC 1.7.13 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.13 - MPC-HC Team)
Seznam Software (HKCU\...\SeznamInstall) (Version: 2.1.32 - Seznam.cz)
() C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\12599libfoxloader-x64.dll
() C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\lightspeed.dll
() C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\12595libfoxloader.dll
Significant changes made by the installer:
File system details [View: All details] (Selection)
---------------------------------------------------
    Adds the folder C:\Program Files (x86)\Seznam.cz\distribution
       Adds the file partner.conf"="1/14/2019 8:59 AM, 28 bytes, A
       Adds the file sources.inf"="1/14/2019 8:59 AM, 100 bytes, A
       Adds the file szninstall.exe"="3/27/2018 3:29 PM, 1069296 bytes, A
       Adds the file sznsetup.exe"="3/27/2018 2:51 PM, 2596080 bytes, A
    Adds the folder C:\Program Files (x86)\Seznam.cz\distribution\install
       Adds the file com.microsoft.msdn.msvcr100-10.0.40219.325-win32.zip"="2/8/2017 4:00 PM, 529195 bytes, A
       Adds the file com.microsoft.msdn.msvcr110-11.0.51106.1-win32.zip"="7/31/2017 4:22 PM, 631911 bytes, A
       Adds the file cz.seznam.software.autoupdate-1.0.8-win32.zip"="2/8/2017 4:00 PM, 849 bytes, A
       Adds the file cz.seznam.software.chromelisticka-2.0.4-win32.zip"="10/31/2017 1:54 PM, 1045 bytes, A
       Adds the file cz.seznam.software.ielisticka3-3.3.1-win32.zip"="11/22/2017 4:52 PM, 724 bytes, A
       Adds the file cz.seznam.software.libfoxcub-3.3.4-win32.zip"="11/22/2017 4:38 PM, 2203997 bytes, A
       Adds the file cz.seznam.software.libfoxcub64-3.3.4-win32.zip"="11/22/2017 4:42 PM, 1053805 bytes, A
       Adds the file cz.seznam.software.libfoxloader-3.2.7-win32.zip"="11/22/2017 4:40 PM, 42615 bytes, A
       Adds the file cz.seznam.software.libszndesktop-2.1.29-win32.zip"="11/13/2017 3:38 PM, 1033669 bytes, A
       Adds the file cz.seznam.software.lightspeed-1210-12.10.12-win32.zip"="2/8/2017 4:00 PM, 313182 bytes, A
       Adds the file cz.seznam.software.lightspeed-1210-12.10.17-win32.zip"="7/31/2017 4:22 PM, 288347 bytes, A
       Adds the file cz.seznam.software.pp-1.0.2-win32.zip"="2/8/2017 4:00 PM, 96329 bytes, A
       Adds the file cz.seznam.software.szndesktop-2.0.31-win32.zip"="7/31/2017 4:22 PM, 42736 bytes, A
       Adds the file cz.seznam.software.szninstall-1.1.14-win32.zip"="7/31/2017 4:22 PM, 413937 bytes, A
       Adds the file cz.seznam.software.sznsetup-1.2.6-win32.zip"="7/31/2017 4:22 PM, 1121056 bytes, A
       Adds the file packages.inf"="11/22/2017 4:58 PM, 12019 bytes, A
       Adds the file szn-software-base-1.0.0-win32.zip"="2/8/2017 4:00 PM, 719 bytes, A
       Adds the file szn-software-fflisticka-4.0.4-win32.zip"="10/31/2017 1:54 PM, 5209329 bytes, A
       Adds the file szn-software-listicka-3.0.0-win32.zip"="2/8/2017 4:00 PM, 1688 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz
       Adds the file install.log"="1/14/2019 8:59 AM, 52491 bytes, A
       Adds the file install_packages.log"="1/14/2019 8:59 AM, 1732 bytes, A
       Adds the file packages.inf"="1/14/2019 8:59 AM, 12828 bytes, A
       Adds the file partner.conf"="1/14/2019 8:59 AM, 28 bytes, A
       Adds the file sources.inf"="1/14/2019 8:59 AM, 45 bytes, A
       Adds the file szninstall.exe"="3/27/2018 3:29 PM, 1069296 bytes, A
       Adds the file sznsetup.exe"="3/27/2018 2:51 PM, 2596080 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\bin
       Adds the file 12595libfoxloader.dll"="11/13/2017 3:49 PM, 85200 bytes, A
       Adds the file 12599libfoxloader-x64.dll"="11/13/2017 3:46 PM, 92368 bytes, A
       Adds the file libfoxcub.dll"="2/20/2018 4:25 PM, 1880272 bytes, A
       Adds the file libfoxcub-x64.dll"="2/20/2018 4:25 PM, 2568400 bytes, A
       Adds the file lightspeed.dll"="2/21/2018 10:36 AM, 869584 bytes, A
       Adds the file listicka-x64.exe"="2/8/2017 12:39 PM, 80576 bytes, A
       Adds the file msvcp100.dll"="7/26/2012 11:44 AM, 421200 bytes, A
       Adds the file msvcp110.dll"="11/6/2012 2:20 AM, 535008 bytes, A
       Adds the file msvcr100.dll"="7/26/2012 11:44 AM, 773968 bytes, A
       Adds the file msvcr110.dll"="11/6/2012 2:20 AM, 875472 bytes, A
       Adds the file szndesktop.exe"="11/13/2017 3:38 PM, 506064 bytes, A
       Adds the file sznpp.exe"="5/2/2018 3:57 PM, 1605872 bytes, A
       Adds the file sznpp_64.exe"="1/14/2019 8:59 AM, 860400 bytes, A
       Adds the file sznpp_ch_nm.json"="1/14/2019 8:59 AM, 375 bytes, A
       Adds the file sznpp_ff_nm.json"="1/14/2019 8:59 AM, 312 bytes, A
       Adds the file unlockInstance.dll"="10/24/2012 4:42 PM, 247352 bytes, A
       Adds the file wszndesktop.exe"="3/27/2018 3:33 PM, 109808 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\conf
       Adds the file szndesktop.conf"="1/6/2015 3:17 PM, 334 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\conf\libfoxcub
       Adds the file foxcub.conf"="6/21/2016 8:10 AM, 251 bytes, A
       Adds the file regcfg.conf"="1/14/2019 8:59 AM, 22 bytes, A
       Adds the file remote.conf"="1/5/2017 10:26 AM, 11515 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\conf\szndesktop.d
       Adds the file installChrome.conf"="1/14/2019 8:59 AM, 190 bytes, A
       Adds the file libfoxcub.conf"="6/21/2016 8:10 AM, 1448 bytes, A
       Adds the file libfoxloader.conf"="1/14/2019 8:59 AM, 165 bytes, A
       Adds the file unlockInstance.conf"="10/22/2012 4:14 PM, 150 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\data
       Adds the file listickaconfig.webpak"="2/19/2018 1:12 PM, 71016 bytes, A
       Adds the file listickanastaveni.webpak"="3/28/2018 1:52 PM, 1075112 bytes, A
       Adds the file speeddial.webpak"="2/19/2018 1:12 PM, 989872 bytes, A
       Adds the file szndesktop.webpak"="5/26/2015 1:38 PM, 40568 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\data\fflisticka
       Adds the file control.ini"="4/3/2018 2:45 PM, 1045 bytes, A
       Adds the file install.bat"="4/3/2018 2:46 PM, 698 bytes, A
       Adds the file seznam_doplnek_email-4.2.1-an+fx-windows.xpi"="4/3/2018 1:26 PM, 3111317 bytes, A
       Adds the file [email protected]"="4/3/2018 1:26 PM, 2874639 bytes, A
       Adds the file uninstall.bat"="9/22/2017 4:24 PM, 448 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\install
       Adds the file com.microsoft.msdn.msvcr100-10.0.40219.325-win32.zip"="2/8/2017 4:00 PM, 529195 bytes, A
       Adds the file com.microsoft.msdn.msvcr110-11.0.51106.1-win32.zip"="7/31/2017 4:22 PM, 631911 bytes, A
       Adds the file cz.seznam.software.autoupdate-1.0.8-win32.zip"="2/8/2017 4:00 PM, 849 bytes, A
       Adds the file cz.seznam.software.chromelisticka-2.0.4-win32.zip"="10/31/2017 1:54 PM, 1045 bytes, A
       Adds the file cz.seznam.software.ielisticka3-3.3.1-win32.zip"="11/22/2017 4:52 PM, 724 bytes, A
       Adds the file cz.seznam.software.libfoxcub-3.3.4-win32.zip"="11/22/2017 4:38 PM, 2203997 bytes, A
       Adds the file cz.seznam.software.libfoxcub64-3.3.4-win32.zip"="11/22/2017 4:42 PM, 1053805 bytes, A
       Adds the file cz.seznam.software.libfoxloader-3.2.7-win32.zip"="11/22/2017 4:40 PM, 42615 bytes, A
       Adds the file cz.seznam.software.libszndesktop-2.1.29-win32.zip"="11/13/2017 3:38 PM, 1033669 bytes, A
       Adds the file cz.seznam.software.lightspeed-1210-12.10.12-win32.zip"="2/8/2017 4:00 PM, 313182 bytes, A
       Adds the file cz.seznam.software.lightspeed-1210-12.10.17-win32.zip"="7/31/2017 4:22 PM, 288347 bytes, A
       Adds the file cz.seznam.software.pp-1.0.2-win32.zip"="2/8/2017 4:00 PM, 96329 bytes, A
       Adds the file cz.seznam.software.szndesktop-2.0.31-win32.zip"="7/31/2017 4:22 PM, 42736 bytes, A
       Adds the file cz.seznam.software.szninstall-1.1.14-win32.zip"="7/31/2017 4:22 PM, 413937 bytes, A
       Adds the file cz.seznam.software.sznsetup-1.2.6-win32.zip"="7/31/2017 4:22 PM, 1121056 bytes, A
       Adds the file packages.inf"="11/22/2017 4:58 PM, 12019 bytes, A
       Adds the file szn-software-base-1.0.0-win32.zip"="2/8/2017 4:00 PM, 719 bytes, A
       Adds the file szn-software-fflisticka-4.0.4-win32.zip"="10/31/2017 1:54 PM, 5209329 bytes, A
       Adds the file szn-software-listicka-3.0.0-win32.zip"="2/8/2017 4:00 PM, 1688 bytes, A
    Adds the folder C:\Users\{username}\AppData\Roaming\Seznam.cz\uninstall
       Adds the file com_microsoft_msdn_msvcr100_10_0_40219_325.install.bat"="8/13/2012 6:58 PM, 56 bytes, A
       Adds the file com_microsoft_msdn_msvcr100_10_0_40219_325.uninstall.bat"="8/6/2012 1:48 PM, 42 bytes, A
       Adds the file com_microsoft_msdn_msvcr110_11_0_51106_1.install.bat"="4/30/2015 10:01 AM, 56 bytes, A
       Adds the file com_microsoft_msdn_msvcr110_11_0_51106_1.uninstall.bat"="4/30/2015 10:01 AM, 42 bytes, A
       Adds the file cz_seznam_software_autoupdate_1_0_8.install.bat"="2/4/2012 12:45 AM, 133 bytes, A
       Adds the file cz_seznam_software_autoupdate_1_0_8.uninstall.bat"="2/4/2012 12:42 AM, 104 bytes, A
       Adds the file cz_seznam_software_chromelisticka_2_0_4.install.bat"="9/7/2017 6:48 PM, 698 bytes, A
       Adds the file cz_seznam_software_chromelisticka_2_0_4.uninstall.bat"="9/7/2017 6:49 PM, 397 bytes, A
       Adds the file cz_seznam_software_ielisticka3_3_3_5.install.bat"="6/21/2016 8:10 AM, 26 bytes, A
       Adds the file cz_seznam_software_ielisticka3_3_3_5.uninstall.bat"="6/21/2016 8:10 AM, 26 bytes, A
       Adds the file cz_seznam_software_libfoxcub_3_3_8.install.bat"="11/22/2017 4:38 PM, 2513 bytes, A
       Adds the file cz_seznam_software_libfoxcub_3_3_8.uninstall.bat"="6/21/2016 8:10 AM, 447 bytes, A
       Adds the file cz_seznam_software_libfoxcub64_3_3_8.install.bat"="6/21/2016 8:10 AM, 479 bytes, A
       Adds the file cz_seznam_software_libfoxcub64_3_3_8.uninstall.bat"="6/21/2016 8:10 AM, 143 bytes, A
       Adds the file cz_seznam_software_libfoxloader_3_2_7.install.bat"="1/6/2015 3:17 PM, 665 bytes, A
       Adds the file cz_seznam_software_libfoxloader_3_2_7.uninstall.bat"="1/6/2015 3:17 PM, 117 bytes, A
       Adds the file cz_seznam_software_libszndesktop_2_1_32.install.bat"="6/14/2017 4:17 PM, 590 bytes, A
       Adds the file cz_seznam_software_libszndesktop_2_1_32.reconfigure.bat"="1/6/2015 3:17 PM, 90 bytes, A
       Adds the file cz_seznam_software_libszndesktop_2_1_32.uninstall.bat"="4/5/2017 1:38 PM, 321 bytes, A
       Adds the file cz_seznam_software_lightspeed_1210_12_10_18.install.bat"="1/6/2015 3:17 PM, 30 bytes, A
       Adds the file cz_seznam_software_lightspeed_1210_12_10_18.uninstall.bat"="1/6/2015 3:17 PM, 23 bytes, A
       Adds the file cz_seznam_software_pp_1_0_2.install.bat"="10/23/2012 2:40 PM, 166 bytes, A
       Adds the file cz_seznam_software_pp_1_0_2.uninstall.bat"="10/22/2012 4:12 PM, 106 bytes, A
       Adds the file cz_seznam_software_szndesktop_2_0_32.install.bat"="1/6/2015 3:17 PM, 290 bytes, A
       Adds the file cz_seznam_software_szndesktop_2_0_32.uninstall.bat"="1/6/2015 3:17 PM, 178 bytes, A
       Adds the file cz_seznam_software_szninstall_1_1_15.install.bat"="9/13/2012 12:47 PM, 908 bytes, A
       Adds the file cz_seznam_software_szninstall_1_1_15.uninstall.bat"="9/7/2012 3:00 PM, 181 bytes, A
       Adds the file cz_seznam_software_sznsetup_1_2_7.install.bat"="9/13/2012 10:39 AM, 90 bytes, A
       Adds the file cz_seznam_software_sznsetup_1_2_7.uninstall.bat"="9/7/2012 2:48 PM, 21 bytes, A
       Adds the file szn_software_base_1_0_0.install.bat"="1/5/2012 2:07 PM, 129 bytes, A
       Adds the file szn_software_base_1_0_0.uninstall.bat"="1/26/2012 3:50 PM, 32 bytes, A
       Adds the file szn_software_fflisticka_4_0_6.install.bat"="4/3/2018 2:46 PM, 698 bytes, A
       Adds the file szn_software_fflisticka_4_0_6.uninstall.bat"="9/22/2017 4:24 PM, 448 bytes, A
       Adds the file szn_software_listicka_3_0_0.install.bat"="6/12/2012 3:05 PM, 1326 bytes, A
       Adds the file szn_software_listicka_3_0_0.uninstall.bat"="3/15/2012 4:51 PM, 610 bytes, A

Registry details [View: All details] (Selection)
------------------------------------------------
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1]
       "Contact"="REG_SZ"", "https://mpc-hc.org/contact-us/"
       "DisplayIcon"="REG_SZ"", "C:\Program Files\MPC-HC\mpc-hc64.exe"
       "DisplayName"="REG_SZ"", "MPC-HC 1.7.13 (64-bit)"
       "DisplayVersion"="REG_SZ"", "1.7.13"
       "EstimatedSize"="REG_DWORD"", 48168
       "HelpLink"="REG_SZ"", "https://trac.mpc-hc.org/"
       "Inno Setup: App Path"="REG_SZ"", "C:\Program Files\MPC-HC"
       "Inno Setup: Deselected Components"="REG_SZ"", ""
       "Inno Setup: Deselected Tasks"="REG_SZ"", "desktopicon\common"
       "Inno Setup: Icon Group"="REG_SZ"", "MPC-HC x64"
       "Inno Setup: Language"="REG_SZ"", "en"
       "Inno Setup: Selected Components"="REG_SZ"", "main,mpciconlib,mpcresources"
       "Inno Setup: Selected Tasks"="REG_SZ"", "desktopicon,desktopicon\user"
       "Inno Setup: Setup Type"="REG_SZ"", "default"
       "Inno Setup: Setup Version"="REG_SZ"", "5.5.9 (u)"
       "Inno Setup: User"="REG_SZ"", "{username}"
       "InstallDate"="REG_SZ"", "20190114"
       "InstallLocation"="REG_SZ"", "C:\Program Files\MPC-HC\"
       "MajorVersion"="REG_DWORD"", 1
       "MinorVersion"="REG_DWORD"", 7
       "NoModify"="REG_DWORD"", 1
       "NoRepair"="REG_DWORD"", 1
       "Publisher"="REG_SZ"", "MPC-HC Team"
       "QuietUninstallString"="REG_SZ"", ""C:\Program Files\MPC-HC\unins000.exe" /SILENT"
       "Readme"="REG_SZ"", "C:\Program Files\MPC-HC\Readme.txt"
       "UninstallString"="REG_SZ"", ""C:\Program Files\MPC-HC\unins000.exe""
       "URLInfoAbout"="REG_SZ"", "https://mpc-hc.org/"
       "URLUpdateInfo"="REG_SZ"", "https://mpc-hc.org/"
       "VersionMajor"="REG_DWORD"", 1
       "VersionMinor"="REG_DWORD"", 7
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
       "seznam-listicka-distribuce"="REG_SZ"", ""C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate"
    [HKEY_CURRENT_USER\Software\Google\Chrome\NativeMessagingHosts\sznpp_nm]
       "(Default)"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\sznpp_ch_nm.json"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
       "cz.seznam.software.autoupdate"="REG_SZ"", ""C:\Users\{username}\AppData\Roaming\Seznam.cz\szninstall.exe" -c"
       "cz.seznam.software.szndesktop"="REG_SZ"", ""C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe"  -q"
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\SeznamInstall]
       "Comments"="REG_SZ"", "Vsechny aplikace spolecnosti Seznam.cz a.s."
       "DisplayIcon"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Seznam.cz\szninstall.exe,0"
       "DisplayName"="REG_SZ"", "Seznam Software"
       "DisplayVersion"="REG_SZ"", "2.1.32"
       "HelpLink"="REG_SZ"", "http://napoveda.seznam.cz/cz/software.html"
       "InstallLocation"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Seznam.cz"
       "ModifyPath"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Seznam.cz\szninstall.exe"
       "NoModify"="REG_DWORD"", 0
       "NoRepair"="REG_DWORD"", 1
       "Publisher"="REG_SZ"", "Seznam.cz"
       "UninstallString"="REG_SZ"", ""C:\Users\{username}\AppData\Roaming\Seznam.cz\szninstall.exe" -X"
       "URLInfoAbout"="REG_SZ"", "http://software.seznam.cz"
    [HKEY_CURRENT_USER\Software\Mozilla\NativeMessagingHosts\sznpp_nm]
       "(Default)"="REG_SZ"", "C:\Users\{username}\AppData\Roaming\Seznam.cz\bin\sznpp_ff_nm.json"
    [HKEY_CURRENT_USER\Software\Seznam.cz\distribution]
       "listicka"="REG_DWORD"", 1
    [HKEY_CURRENT_USER\Software\Seznam.cz\sznpp]
       "che_state"="REG_DWORD"", 32
       "chrv_state"="REG_DWORD"", 32
       "ff_state_email"="REG_DWORD"", 4
       "ff_state_sko"="REG_DWORD"", 4
       "lses"="REG_QWORD, ....
       "ssid"="REG_SZ"", "EF0E98B4-9BD9-40C7-A31A-864CBC4B2313"
Malwarebytes log:
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 1/14/19
Scan Time: 9:07 AM
Log File: 818c2f60-17d3-11e9-8212-00ffdcc6fdfc.json

-Software Information-
Version: 3.6.1.2711
Components Version: 1.0.482
Update Package Version: 1.0.8764
License: Premium

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: {computername}\{username}

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 236211
Threats Detected: 1
Threats Quarantined: 1
Time Elapsed: 2 min, 53 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
PUP.Optional.SeznamToolbar.NSIS, C:\USERS\{username}\DESKTOP\SETUP.EXE, Quarantined, [13850], [623610],1.0.8764

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)
As mentioned before the full version of Malwarebytes could have protected your computer against this threat.
We use different ways of protecting your computer(s):
  • Dynamically Blocks Malware Sites & Servers
  • Malware Execution Prevention
Save yourself the hassle and get protected.
  • 0

Advertisements





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured
Malware Removal How to Guides Windows 7 System Building Download Files Register welcome

Never used a forum? Learn how.