PUP.BoBrowser

Threat Scorecard

Ranking: 4,058
Threat Level: 10 % (Normal)
Infected Computers: 60,120
First Seen: October 10, 2014
Last Seen: April 10, 2024
OS(es) Affected: Windows

File System Details

PUP.BoBrowser may create the following file(s):
# File Name MD5 Detections
1. 976dea09-70e4-46c4-be44-4abacd4f363c.exe d657be6cb7dd57784742aed0bc303bbb 944
2. c2646b6d-4adc-4d7e-96e9-4d4fce8f2602[1].exe c5d597dea24509ffa0c69e0dba391b01 326
3. claraupdater.exe 79fc37f692f76bd9762ab02f52ac0222 224
4. BoBrowser.exe 5574d740831fc0bc9b7b6c1f467c5733 37
5. ClaraUpdater.exe.vir 09faa5eb732d7d4e2b38ce791bc6212e 27
6. ClaraUpdater.exe f3ed947ff8e86faae4f40df0ab9853e2 15
7. bobrowser.exe ce8b9072e45ffe84115cdd953af468c6 14
8. BoBrowser.exe da00def6b85fde4f4e1ae98e1861bdc8 14
9. BoBrowser.exe 5300c9b559273485eb12e0d7678a0fa0 9
10. bobrowser.exe 425c32a10f274570b471689c53d80f59 8
11. bobrowser.exe ce136105ff83c1d84e3d1bdb93968850 8
12. BoBrowser.exe 4bcbb25dd5183fb09b03eb50c96d0e44 7
13. ClaraUpdater.exe 168da04499709371973dd1f1ab2b141b 7
14. bobrowser.exe 38a319645693f24474ce219c8eb28b8f 6
15. BoBrowser.exe 3e06a317d42c6c4433cdd7d0c6961599 6
16. BoBrowser.exe 776073bd991340dc6e383d72663e8255 6
17. bobrowser.exe 76c2030d8ee6ead3d9b66d3f5f894601 6
18. ClaraUpdater.exe 409664534ef352b12922b2c061752c2c 6
19. ClaraUpdater.exe e5644bb42932300cc79cfd345725aafe 5
20. ClaraUpdater.exe 1b7429689f6f66b422d5d0c020223a03 4
21. ClaraUpdater.exe 402bae43505f57eb0b80ea75b8555adb 2
22. ClaraUpdater.exe 70d5fdd21c8ac15c3ee8d2ab24e4e3cf 2
23. ClaraUpdater.exe 4e08024be03fd208d60b56ef2df103d9 1
24. ClaraUpdater.exe e1f5f59476e6c6603b3b98f313f8752d 1
25. ClaraUpdater.exe 21314c00cf45f75dd72d46d678c32003 1
26. ClaraUpdater.exe 3933bb4fe610af4c70c22d875d47eb4b 1
27. ClaraUpdater.exe af2ab20911d179e7c55aacd5146080c3 1
28. ClaraUpdater.exe b87c0decfdb9a20ac7e78061d39c1fca 1
More files

Registry Details

PUP.BoBrowser may create the following registry entry or registry entries:
CLSID
{19041B6B-8F97-4669-BA21-C17572737ED2}
File name without path
BoBrowser.lnk
claraInstaller.txt
http_isearch.bobrowser.com_0.localstorage
http_isearch.bobrowser.com_0.localstorage-journal
http_www.bobrowser.com_0.localstorage
http_www.bobrowser.com_0.localstorage-journal
Regexp file mask
%windir%\System32\Tasks\Run_Bobby_Browser
Software\BoBrowser
SOFTWARE\Classes\.htm\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.htm\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.html\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.html\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.shtml\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.shtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.webp\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.webp\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xht\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xht\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xhtml\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xhtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Classes\Applications\bobrowser.exe
Software\Classes\CLSID\19041B6B-8F97-4669-BA21-C17572737ED2
Software\Classes\Wow6432Node\CLSID\19041B6B-8F97-4669-BA21-C17572737ED2
SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\bobrowser.exe
SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\bobrowser.exe
SOFTWARE\Microsoft\Tracing\BoBrowser_RASAPI32
SOFTWARE\Microsoft\Tracing\BoBrowser_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\bobrowser.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ_http
SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ_https
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Run\BoBrowser
Software\Microsoft\Windows\CurrentVersion\Run\CrashService
SOFTWARE\RegisteredApplications\BoBrowser.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\bobrowser.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\bobrowser.exe
SOFTWARE\Wow6432Node\RegisteredApplications\BoBrowser.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SYSTEM\ControlSet001\services\ClaraUpdater
SYSTEM\ControlSet002\services\ClaraUpdater
SYSTEM\CurrentControlSet\services\ClaraUpdater

Directories

PUP.BoBrowser may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\BoBrowser
%COMMONPROGRAMFILES%\ClaraUpdater
%COMMONPROGRAMFILES(x86)%\ClaraUpdater
%LOCALAPPDATA%\BoBrowser
%LOCALAPPDATA%\BoBrowserUninstall
%PROGRAMFILES%\Bobrowsercm
%PROGRAMFILES(x86)%\Bobrowsercm
%TEMP%\BoBrowser
%UserProfile%\Local Settings\Application Data\BoBrowser

Trending

Most Viewed

Loading...