PUP Reports

1. Use PC TuneUp Maestro (sha256, ba7c3157b033be801ac7e0adaffb1f8c05be8de60610b4cc53dfb85a0dd1e6c1) w/ caution:

As for "WisdomEyes", you may want to read this tweet re 1278u0's Incident Response by Payload Security.

This "Fingerprint: Contains ability to lookup the windows [Windows] account name" is the problem.

2. WebDiscover Browser (85619d5d0380aa1c65ac6c82a68b7937245a2dd378104df1c01dbcffe904d037), the variant of Web Bar, contains built-in, hidden redirection & 'hijacker' safestsearches.com (site title, Tìm kiếm) - which (still) hosts the infamous conduit search (from ClientConnect Ltd)

20161018052810.png20161019051814.png20161019052903.png

 

 

 

Weather Hub & searchespro.com & Conduit Yahoo Search

20161226003747.png20161226001829.png

FAKE msg (HT201165) from alert apple error dot com

20161213130019.png

Can't uninstall avg free???

f782bf.dl.filessearcher.com & Cant_uninstall_avg_free_downloader.exe (sha256 = c716026c3661d338d7b2fa265ffa562169fde4c7141e2246ece20633109dbabb) & StroyLogistika OOOWS.Reputation.1

 

Potential hijacker@ hxxp://web-start.org/:

20161117193747.png

muzikfury.thewhizmarketing.com/ & MySearch.com & APN LLC & Ask.com Toolbar/Search

20161113033509.png

 

For Mac users:

  • securemacfix.com
  • browsesafemac.com
  • mac-app.store-secured.online

20161111045752.png

VirusTotal antivirus solutions sometimes are not exactly the same as the public commercial versions. Very often, antivirus companies parametrize their engines specifically for VirusTotal (stronger heuristics, cloud interaction, inclusion of beta signatures, etc.). Therefore, sometimes the antivirus solution in VirusTotal will not behave exactly the same as the equivalent public commercial version of the given product.