Home Malware Programs Potentially Unwanted Programs (PUPs) Search Protect

Search Protect

Posted: July 7, 2014

Threat Metric

Ranking: 1,235
Threat Level: 5/10
Infected PCs: 386,901
First Seen: July 7, 2014
Last Seen: March 10, 2025
OS(es) Affected: Windows


Search Protect is a potentially unwanted program by Client Connect Ltd that could generate random ads and cause redirects to questionable sites. Use of the Search Protect ads or redirected sites may result in leading to an unwanted download or loading of a site that asks you to take part in a questionable action on the internet. Search Protect was once part of the conduit network of sites and generic search engines. Since then, Search Protect is used more as a means of changing your default home page to an unwanted site and advertising various sponsored links or ads so the creators of Search Protect can be get paid. Removal of the Search Protect program is necessary to prevent your home page from redirecting or other actions taking place on your web browser that interrupt you from surfing the internet in a normal fashion.

Aliases

Win64.Application.SearchProtect.AB@gen [GData]Artemis [McAfee-GW-Edition]Artemis!A2C9DD9C88B8 [McAfee]Generic.ABF [AVG]Riskware/ClientConnect [Fortinet]Adware.Conduit.298 [DrWeb]SearchProtect.1DD [AVG]Riskware/Searchprotect [Fortinet]PUP/Win32.SearchProtect [AhnLab-V3]Conduit Search Protect [Sophos]not-a-virus:RiskTool.Win32.SearchProtect.a [Kaspersky]Trojan ( 0049ef011 ) [K7AntiVirus]RiskTool.SearchProtect.r6 (Not a Virus) [CAT-QuickHeal]

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to Search Protect may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\ProgramData\{72C69A05-2244-4B83-93C2-3B014340E88F}\2.0.1.9\faci.dll File name: faci.dll
Size: 606.72 KB (606720 bytes)
MD5: 0941826430da4938a6745cd1f7256f62
Detection count: 890
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\ProgramData\{72C69A05-2244-4B83-93C2-3B014340E88F}\2.0.1.9\faci.dll
Group: Malware file
Last Updated: November 25, 2024
C:\Users\<username>\AppData\Local\avabvbxvh\avabvbxvh.exe File name: avabvbxvh.exe
Size: 2.13 MB (2135552 bytes)
MD5: f5126cc817a0638a77f1ef3ddfe22f8e
Detection count: 482
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\avabvbxvh\avabvbxvh.exe
Group: Malware file
Last Updated: March 31, 2023
C:\Windows\Temp\DAF4.tmp\avabvbyvyc.exe File name: avabvbyvyc.exe
Size: 2.13 MB (2135552 bytes)
MD5: f47af1d980bcfef7219d3c9c8b87555d
Detection count: 260
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\Temp\DAF4.tmp\avabvbyvyc.exe
Group: Malware file
Last Updated: November 4, 2022
%PROGRAMFILES(x86)%\SearchProtect\Main\bin\CltMngSvc.exe File name: CltMngSvc.exe
Size: 3.24 MB (3246864 bytes)
MD5: 50ce1e27440dc18eb5252955a74e62ec
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SearchProtect\Main\bin
Group: Malware file
Last Updated: February 13, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64LO~1.DLL File name: VC64LO~1.DLL
Size: 263.95 KB (263952 bytes)
MD5: 3fdf8b112abd4ac8d9eb805375117120
Detection count: 81
Mime Type: unknown/DLL
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: February 13, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64Loader.dll File name: VC64Loader.dll
Size: 277.26 KB (277264 bytes)
MD5: 1d135869fdf9f776318f20ec9484d530
Detection count: 63
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: March 1, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64LO~1.DLL File name: VC64LO~1.DLL
Size: 249.1 KB (249104 bytes)
MD5: c598cc2ada03e90b588957e9a2ff7715
Detection count: 46
Mime Type: unknown/DLL
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: March 1, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64Loader.dll File name: VC64Loader.dll
Size: 247.05 KB (247056 bytes)
MD5: c1d32b1462f6c92c507b157ea00caaba
Detection count: 44
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: February 13, 2016
\??\C:\Windows\system32\drivers\SPPD.sys File name: SPPD.sys
Size: 19.38 KB (19384 bytes)
MD5: 68d7304239069573a46d384cd71f5ec3
Detection count: 35
File type: System file
Mime Type: unknown/sys
Path: \??\C:\Windows\system32\drivers
Group: Malware file
Last Updated: February 10, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC32Loader.dll File name: VC32Loader.dll
Size: 219.92 KB (219920 bytes)
MD5: a0bbbd15e2b7f3c65c8dd26baaa8b316
Detection count: 30
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: February 13, 2016
%LOCALAPPDATA%\bvugqqrp.exe File name: bvugqqrp.exe
Size: 103.42 KB (103424 bytes)
MD5: 8694c0666ebc8818a1a8afbb3612cbcc
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: April 27, 2016
%LOCALAPPDATA%\bvyvavay\bvyvavay.exe File name: bvyvavay.exe
Size: 2.18 MB (2185216 bytes)
MD5: 3fecacabe8cd7a900ea2423d6765f040
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\bvyvavay
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC32Loader.dll File name: VC32Loader.dll
Size: 219.89 KB (219896 bytes)
MD5: 20a8b186142a0f70e3e89e04cf3c34ea
Detection count: 15
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: March 1, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64LO~1.DLL File name: VC64LO~1.DLL
Size: 247.05 KB (247056 bytes)
MD5: 0cf7da44b71d607966b2dc361e60245e
Detection count: 14
Mime Type: unknown/DLL
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: February 13, 2016
%LOCALAPPDATA%\bvxvdxvx\bvxvdxvx.exe File name: bvxvdxvx.exe
Size: 2.17 MB (2173440 bytes)
MD5: dd4fb04bfa36fd6aed06bcc4ddd2cfd4
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\bvxvdxvx
Group: Malware file
Last Updated: April 27, 2016
%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\cltmng.exe File name: cltmng.exe
Size: 4.25 MB (4256016 bytes)
MD5: 941663f8a1a09853bd7bb17116187e9f
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin
Group: Malware file
Last Updated: January 26, 2023

More files

Registry Modifications

The following newly produced Registry Values are:

CLSID{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}File name without pathOrbiterInstaller[1].exeRegexp file mask%PROGRAMFILES%\SearchProtect\Main\bin\CltMngSvc.exe%PROGRAMFILES%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll%PROGRAMFILES(x86)%\SearchProtect\Main\bin\CltMngSvc.exe%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\SPVC32Loader.dll%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\SPVC64Loader.dll%PROGRAMFILES(x86)%\SearchProtect\SearchProtect\bin\VC64Loader.dll%WINDIR%\AppPatch\AppPatch64\VCLdr64.dll%WINDIR%\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb%WINDIR%\AppPatch\Custom\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdb%WINDIR%\AppPatch\nbin\VC32Loader.dll%WINDIR%\system32\SearchProtectService.exe%WinDir%\System32\Tasks\avaavaevy[RANDOM CHARACTERS]%WinDir%\System32\Tasks\avaavxvyex%WinDir%\System32\Tasks\avabvbavad%WinDir%\System32\Tasks\avabvbxvh%WinDir%\System32\Tasks\avabvbyvyb%WinDir%\System32\Tasks\avabvbyvyc%WinDir%\System32\Tasks\avabvdxvy%WinDir%\System32\Tasks\avabvexvac%WINDIR%\System32\Tasks\avabvyxvdy%WINDIR%\System32\Tasks\avaxvavya%WinDir%\System32\Tasks\avaxvbxvgx%windir%\System32\Tasks\avayvaxvaa%WinDir%\System32\Tasks\bvxvaxxvyd%WinDir%\System32\Tasks\bvxvbvef%WinDir%\System32\Tasks\bvxvbxvd%WinDir%\System32\Tasks\bvxvbxxvaa%WinDir%\System32\Tasks\bvxvbyxvaa%WinDir%\System32\Tasks\bvxvcxxvaf%WinDir%\System32\Tasks\bvxvcyxvyy%WinDir%\System32\Tasks\bvxvdxvx%WinDir%\System32\Tasks\bvxvexvbg%WinDir%\System32\Tasks\bvxvgxvyy%WinDir%\System32\Tasks\bvxvyxvgy%WinDir%\System32\Tasks\bvxvyxxvcy%WinDir%\System32\Tasks\bvyvavay%WinDir%\System32\Tasks\bvyvbvhx%WinDir%\System32\Tasks\bvyvbvyb%WinDir%\System32\Tasks\bvyvbvyf%WINDIR%\SysWOW64\SearchProtectService.exe%WinDir%\Tasks\avaavxvyex[RANDOM CHARACTERS]%WinDir%\Tasks\avabvbxvh[RANDOM CHARACTERS]%WinDir%\Tasks\avaxvbxvgx[RANDOM CHARACTERS]%WinDir%\Tasks\bvxvcxxvaf.job%WinDir%\Tasks\bvxvdxvx[RANDOM CHARACTERS]HKEY..\..\..\..{RegistryKeys}Software\Conduit_Search_ProtectSoftware\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}Software\Microsoft\Internet Explorer\SearchScopes\{015DB5FA-EAFB-4592-A95B-F44D3EE87FA9}SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SearchProtectSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\chrome.exe\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\explorer.xxx\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\explorer.zza\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\firefox.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\iexplore.exe\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\Layers\VC32LdrSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\software_removal_tool.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\software_reporter_tool.exe\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}.sdbSOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exeSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaavxvyexSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbavadSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbxvhSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbyvybSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvbyvycSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvdxvySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvexvacSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avabvyxvdySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avaxvbxvgxSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvavcSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvaxxvydSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbvefSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxvdSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxxvaaSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbyxvaaSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvcxxvafSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvcyxvyySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvdxvxSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvexvbgSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvgxvyySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxvecSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxvgySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvyxxvcySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvavaySOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvhxSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvybSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvyvbvyfSOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost\ORBTRSOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sonocontrolSoftware\Microsoft\Windows\CurrentVersion\Run\SearchProtectSOFTWARE\ORBTRSoftware\SearchProtectSoftware\SearchProtectIN4TSoftware\SearchProtectINTSoftware\SearchProtectINT2Software\SearchProtectWSSOFTWARE\SPPDCOMSOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\ORBTRSOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\sonocontrolSOFTWARE\Wow6432Node\ORBTRSOFTWARE\Wow6432Node\SearchProtectSOFTWARE\Wow6432Node\SPPDCOMSYSTEM\ControlSet001\Enum\Root\LEGACY_SPPDSYSTEM\ControlSet001\services\CltMngSvcSYSTEM\ControlSet001\services\OrbiterSYSTEM\ControlSet001\services\SPPDSYSTEM\ControlSet001\services\SPSSYSTEM\ControlSet002\Enum\Root\LEGACY_SPPDSYSTEM\ControlSet002\services\CltMngSvcSYSTEM\ControlSet002\services\OrbiterSYSTEM\ControlSet002\services\SPPDSYSTEM\ControlSet002\services\SPSSYSTEM\CurrentControlSet\Enum\Root\LEGACY_SPPDSYSTEM\CurrentControlSet\services\CltMngSvcSYSTEM\CurrentControlSet\services\OrbiterSYSTEM\CurrentControlSet\services\SPPDSYSTEM\CurrentControlSet\services\SPSHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}SearchProtectSetup Support for SearchProtect{2AEF02C3-5159-4C81-A688-8D954F0DEE56}_NewSearch

Additional Information

The following directories were created:
%AppData%\SearchProtect%LOCALAPPDATA%\GuardboxEngine%LOCALAPPDATA%\NextSearch%LOCALAPPDATA%\avaavaevy%LOCALAPPDATA%\avaavxvyex%LOCALAPPDATA%\avabvbavad%LOCALAPPDATA%\avabvbxvh%LOCALAPPDATA%\avabvbyvyb%LOCALAPPDATA%\avabvbyvyc%LOCALAPPDATA%\avabvcxvyx%LOCALAPPDATA%\avabvdxvy%LOCALAPPDATA%\avabvexvac%LOCALAPPDATA%\avabvyxvdy%LOCALAPPDATA%\avaxvbxvgx%LOCALAPPDATA%\avayvaxxvae%LOCALAPPDATA%\avayvxvaxc%LOCALAPPDATA%\bvxvavc%LOCALAPPDATA%\bvxvaxxvyd%LOCALAPPDATA%\bvxvbvbh%LOCALAPPDATA%\bvxvbvef%LOCALAPPDATA%\bvxvbxvd%LOCALAPPDATA%\bvxvbxxvaa%LOCALAPPDATA%\bvxvbyxvaa%LOCALAPPDATA%\bvxvcxxvaf%LOCALAPPDATA%\bvxvcyxvyy%LOCALAPPDATA%\bvxvdxvx%LOCALAPPDATA%\bvxvexvbg%LOCALAPPDATA%\bvxvgxvyy%LOCALAPPDATA%\bvxvhxvh%LOCALAPPDATA%\bvxvyxvec%LOCALAPPDATA%\bvxvyxvgy%LOCALAPPDATA%\bvxvyxxvcy%LOCALAPPDATA%\bvyvavay%LOCALAPPDATA%\bvyvbvhx%LOCALAPPDATA%\bvyvbvyb%LOCALAPPDATA%\bvyvbvyf%LOCALAPPDATA%\bvyvcvbb%LOCALAPPDATA%\bvyvdvag%LOCALAPPDATA%\bvyvdvyh%LocalAppData%\SearchProtect%PROGRAMFILES%\GuardboxEngine%PROGRAMFILES%\NextSearch%PROGRAMFILES%\ORBTR%PROGRAMFILES%\Search-Protect%PROGRAMFILES%\SearchProtect%PROGRAMFILES%\Setup Support for SearchProtect%PROGRAMFILES(x86)%\GuardboxEngine%PROGRAMFILES(x86)%\NextSearch%PROGRAMFILES(x86)%\ORBTR%PROGRAMFILES(x86)%\Search-Protect%PROGRAMFILES(x86)%\SearchProtect%PROGRAMFILES(x86)%\Setup Support for SearchProtect%PROGRAMFILES(x86)%\sp-downloader%USERPROFILE%\Configuración local\Datos de programa\SearchProtect%USERPROFILE%\Configurações Locais\Dados de aplicativos\SearchProtect%USERPROFILE%\Impostazioni locali\Dati applicazioni\SearchProtect%USERPROFILE%\Local Settings\Application Data\avabvbxvh%USERPROFILE%\Lokale Einstellungen\Anwendungsdaten\SearchProtect%USERPROFILE%\Ustawienia lokalne\Dane aplikacji\SearchProtect%UserProfile%\Local Settings\Application Data\GuardboxEngine%UserProfile%\Local Settings\Application Data\SearchProtect%UserProfile%\Local Settings\Application Data\avaavaevy%UserProfile%\Local Settings\Application Data\avaavxvyex%UserProfile%\Local Settings\Application Data\avabvbavad%UserProfile%\Local Settings\Application Data\avabvexvac%UserProfile%\Local Settings\Application Data\avaxvbxvgx%UserProfile%\Local Settings\Application Data\avayvaxxvae%UserProfile%\Local Settings\Application Data\avayvxvaxc%UserProfile%\Local Settings\Application Data\bvxvbvef%UserProfile%\Local Settings\Application Data\bvxvdxvx%UserProfile%\Local Settings\Application Data\bvxvexvbg%UserProfile%\Local Settings\Application Data\bvxvgxvyy%UserProfile%\Local Settings\Application Data\bvxvhxvh%UserProfile%\Local Settings\Application Data\bvxvyxvec%UserProfile%\Local Settings\Application Data\bvxvyxxvcy%WINDIR%\SysWOW64\config\systemprofile\AppData\Local\SearchProtect%WINDIR%\System32\config\systemprofile\AppData\Local\SearchProtect%WinDir%\SysWOW64\SearchProtect%WinDir%\System32\SearchProtect

Related Posts

Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.