Quantcast
Channel: How to Remove Malware
Viewing all articles
Browse latest Browse all 38585

GS-Enabler\PSUPPORT.DLL is Adware PUP.Optional.SProtect.A

$
0
0

We received the file PSUPPORT.DLL and detected that PSUPPORT.DLL is not good.
PSUPPORT.DLL is Adware. You should remove the file PSUPPORT.DLL.
Kill the process PSUPPORT.DLL and remove PSUPPORT.DLL from Windows.

Malware Analysis of PSUPPORT.DLL
Full path on a computer: %Program Files%\GS-Enabler\psupport.dll

Detected by UnHackMe:

PSUPPORT.DLL
Default location: %Program Files%\GS-Enabler\psupport.dll

Removal Results: Success
Number of reboot: 1

PSUPPORT.DLL is known as:

Adware.PUP.Optional.SProtect.A, Adware.BL, Trojan.BGuard.cqshad, Adware.BGuard.42, Adware.BHO.Bprotector.12, BProtector, PUP.ADownloader, AdWare.BHO, Adware.BHO.40, a variant of Win32.SProtector.A

PSUPPORT.DLL hash:

  • MD5: 898bdcc577a2b49e8eacaf18ddbb3e7b
The file tries to connect to the dangerous web site.
How to quickly detect PSUPPORT.DLL presence?
Registry:
  • HKLM\Software\Classes\CLSID\{068A308B-E1A7-7E38-7228-D1484AE207FD}\InprocServer32\: “%Program Files%\SurFNakeeap\ZAUX.dll”
  • HKLM\Software\Classes\CLSID\{B4646CE2-1DA6-7C46-48CA-35CFF295DA03}\InprocServer32\: “%Program Files%\YoutubeAdblocker\egy_0w5.dll”
  • HKLM\Software\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}\InProcServer32\: “%SystemRoot%\system32\SHELL32.dll”
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Optimizer Pro: “%Program Files%\Optimizer Pro\OptProLauncher.exe”
  • HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs: “c:\progra~1\gs-ena~1\psupport.dll”
Folders:
  • %Program Files%\EZDownloader
  • %Program Files%\GS-Enabler
  • %Program Files%\Optimizer Pro
  • %Program Files%\SurFNakeeap
  • %Program Files%\YoutubeAdblocker
  • %SysDir%\AMD64
  • %SysDir%\X86
Files:
  • %Common Appdata%\QuickSet\GS-Enabler\299282477.ini
  • %Common Appdata%\QuickSet\GS-Enabler\GS-Enabler.exe
  • %Program Files%\EZDownloader\EZDownloader.Core.dll
  • %Program Files%\EZDownloader\EZDownloader.exe
  • %Program Files%\EZDownloader\EZDownloader.exe.config
  • %Program Files%\EZDownloader\EZDownloader.Extension.dll
  • %Program Files%\EZDownloader\EZDownloader.Spider.dll
  • %Program Files%\EZDownloader\ICSharpCode.SharpZipLib.dll
  • %Program Files%\EZDownloader\Interop.SHDocVw.dll
  • %Program Files%\EZDownloader\TabStrip.dll
  • %Program Files%\EZDownloader\unins000.dat
  • %Program Files%\EZDownloader\unins000.exe
  • %Program Files%\GS-Enabler\psupport.dll
  • %Program Files%\GS-Enabler\uninstall.exe
  • %Program Files%\Optimizer Pro\CookiesException.txt
  • %Program Files%\Optimizer Pro\English.ini
  • %Program Files%\Optimizer Pro\file_id.diz
  • %Program Files%\Optimizer Pro\HomePage.url
  • %Program Files%\Optimizer Pro\OptimizerPro.chm
  • %Program Files%\Optimizer Pro\OptimizerPro.exe
  • %Program Files%\Optimizer Pro\OptProGuard.exe
  • %Program Files%\Optimizer Pro\OptProLauncher.exe
  • %Program Files%\Optimizer Pro\OptProReminder.exe
  • %Program Files%\Optimizer Pro\OptProSchedule.exe
  • %Program Files%\Optimizer Pro\OptProSmartScan.exe
  • %Program Files%\Optimizer Pro\OptProStart.exe
  • %Program Files%\Optimizer Pro\OptProUninstaller.exe
  • %Program Files%\Optimizer Pro\scan.gif
  • %Program Files%\Optimizer Pro\sqlite3.dll
  • %Program Files%\Optimizer Pro\StartupList.txt
  • %Program Files%\Optimizer Pro\unins000.dat
  • %Program Files%\Optimizer Pro\unins000.exe
  • %Program Files%\Optimizer Pro\unins000.msg
  • %Program Files%\SurFNakeeap\ZAUX.dat
  • %Program Files%\SurFNakeeap\ZAUX.dll
  • %Program Files%\SurFNakeeap\ZAUX.tlb
  • %Program Files%\SurFNakeeap\ZAUX.x64.dll
  • %Program Files%\YoutubeAdblocker\egy_0w5.dat
  • %Program Files%\YoutubeAdblocker\egy_0w5.dll
  • %Program Files%\YoutubeAdblocker\egy_0w5.tlb
  • %Program Files%\YoutubeAdblocker\egy_0w5.x64.dll
  • %WinDir%\Tasks\GS-Enabler-S-299282477.job


Viewing all articles
Browse latest Browse all 38585

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>