PUP.BoBrowser

Threat Scorecard

Ranking: 3,996
Threat Level: 10 % (Normal)
Infected Computers: 60,347
First Seen: October 10, 2014
Last Seen: June 2, 2025
OS(es) Affected: Windows

File System Details

PUP.BoBrowser may create the following file(s):
# File Name MD5 Detections
1. $R0EWC37.exe 05ad6dfec9d08f7b95a2b35c47a02f5b 3,787
2. ebf87fa7-b488-487f-9971-c96f16e9c35d.exe 27a97ec4bbd8987cb29f91c6e962542d 3,577
3. 64602c96-051b-4d8a-8830-268df7c6347d[1].exe fa8b58f49f253f326a45395c7d877f97 1,975
4. 5d28babe-55be-4a92-9019-4546fca07264.exe b623c528c20ec47dc4bf81c1216f4ef1 1,424
5. 976dea09-70e4-46c4-be44-4abacd4f363c.exe d657be6cb7dd57784742aed0bc303bbb 944
6. c2646b6d-4adc-4d7e-96e9-4d4fce8f2602[1].exe c5d597dea24509ffa0c69e0dba391b01 330
7. YR4OWd1nXIOtrnSM83Kt9Lxtz99OBYR4OWd1nXIOtrnSM83Kt9Lxtz99OB_bb.exe d8888771dcdea6b811d199c9b7193bcc 295
8. bobrowser_3010-10494ef2.exe 4d42a1035eff6126b2bd9c75310def8e 31
9. ClaraUpdater.exe.vir 09faa5eb732d7d4e2b38ce791bc6212e 27
10. BoBrowser.exe 5300c9b559273485eb12e0d7678a0fa0 9
11. BoBrowser(1).exe 9b8273408ac4d0b3b7d4ffbc9e7b8162 7
12. ClaraUpdater.exe 70d5fdd21c8ac15c3ee8d2ab24e4e3cf 2
More files

Registry Details

PUP.BoBrowser may create the following registry entry or registry entries:
CLSID
{19041B6B-8F97-4669-BA21-C17572737ED2}
File name without path
BoBrowser.lnk
claraInstaller.txt
http_isearch.bobrowser.com_0.localstorage
http_isearch.bobrowser.com_0.localstorage-journal
http_www.bobrowser.com_0.localstorage
http_www.bobrowser.com_0.localstorage-journal
Regexp file mask
%windir%\System32\Tasks\Run_Bobby_Browser
Software\BoBrowser
SOFTWARE\Classes\.htm\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.htm\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.html\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.html\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.shtml\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.shtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.webp\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.webp\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xht\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xht\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xhtml\OpenWithProgIds\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Classes\.xhtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Classes\Applications\bobrowser.exe
Software\Classes\CLSID\19041B6B-8F97-4669-BA21-C17572737ED2
Software\Classes\Wow6432Node\CLSID\19041B6B-8F97-4669-BA21-C17572737ED2
SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\bobrowser.exe
SOFTWARE\Microsoft\RADAR\HeapLeakDetection\DiagnosedApplications\bobrowser.exe
SOFTWARE\Microsoft\Tracing\BoBrowser_RASAPI32
SOFTWARE\Microsoft\Tracing\BoBrowser_RASMANCS
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Run_Bobby_Browser
SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\bobrowser.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ_http
SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ_https
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids\BoBrowsHTM.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\OpenWithProgids\BoBrowsHTML.NSJA6BHDA3NCFCFMXW3QSCUYUQ
Software\Microsoft\Windows\CurrentVersion\Run\BoBrowser
Software\Microsoft\Windows\CurrentVersion\Run\CrashService
SOFTWARE\RegisteredApplications\BoBrowser.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SOFTWARE\Wow6432Node\Microsoft\MediaPlayer\ShimInclusionList\bobrowser.exe
SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\bobrowser.exe
SOFTWARE\Wow6432Node\RegisteredApplications\BoBrowser.NSJA6BHDA3NCFCFMXW3QSCUYUQ
SYSTEM\ControlSet001\services\ClaraUpdater
SYSTEM\ControlSet002\services\ClaraUpdater
SYSTEM\CurrentControlSet\services\ClaraUpdater

Directories

PUP.BoBrowser may create the following directory or directories:

%APPDATA%\Microsoft\Windows\Start Menu\Programs\BoBrowser
%COMMONPROGRAMFILES%\ClaraUpdater
%COMMONPROGRAMFILES(x86)%\ClaraUpdater
%LOCALAPPDATA%\BoBrowser
%LOCALAPPDATA%\BoBrowserUninstall
%PROGRAMFILES%\Bobrowsercm
%PROGRAMFILES(x86)%\Bobrowsercm
%TEMP%\BoBrowser
%UserProfile%\Local Settings\Application Data\BoBrowser

Trending

Most Viewed

Loading...