Malware Removal Instructions

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, 27 July 2012

Boxore Adware (Uninstall Guide)

Posted on 08:25 by Unknown
Today we came across another adware application called Boxore. It's distributed the old-fashioned way: people search for free online movie streaming sites where they could watch their favorite movies and TV shows without actually downloading them. Let's take The Dark Knight Rises as an example which stormed its way to the top of the US box office. There are many websites that allow you to watch this movie online and for free. Sounds good to be true? You betcha!

Most of the time, you either have to buy credits or download their "player" that is supposedly necessary to watch the movie. One of such streaming websites generated an error message claiming that we can't watch the movie because we don't have some fancy codecs installed on our machine. But that's not a problem, they immediately told us to download this free multimedia player called Player Plus which fixes everything right away. So, we did.

Surprisingly, the Player Plus setup wizard was in French even thought we were redirected from a video streaming site in English and the official download page was also in English. As you can see in the image below, we could choose not to install Boxore client and Babylon Toolbar but let's just say we were so excited or maybe inattentive and missed that option.



Everything went smoothly, we went back to the streaming site, clicked play button again and for our great disappointment we were able to watch The Dark Knight Rises trailer only, not the full movie. Darn scammers!

So, after all, we ended up with the Babylon toolbar and Boxore adware on our computer. You can read more about Babylon toolbar and Babylon search engine here. Now, let's have a look at Boxore client. There are two main components of this software: boxore.exe (client) and Update.exe (service). Both are set to start up automatically whenever you turn on your computer.

Going through boxore.exe file properties, comments section, quickly reveals what it's all about:
Get offers and recommendations matching with what you like (videos, games, music, ...)


The same information can be found at boxore.com. Furthermore, Boxore adware authors assure that their product is 100% safe, free and anonymous. It doesn't collect any information about the users. Boxore simply scans all the websites you visit searching for keywords that could help them determine what kind of topics you are interested in when browsing the net.

Boxore.exe sends ad requests regularly. If there's no ad available at that moment, it keeps monitoring your browsing habits. But we didn't have to wait very long for the first ad to show up. This advertisement (see the image below) was loaded after twenty or so minutes.



The ad came from openadserving.com. This website is currently ranking among 4000 most popular sites in the world. Even though, this data isn't very reliable we can still assume that Boxore network is serving ads to thousands of users each day.



And finally, one interesting fact about the multimedia player we downloaded: there are actually two versions of the Player Plus. If you download Player Plus from playerplus.com then you will get a clean version of this application. No toolbars, adware, etc. However, if you download Player Plus from a streaming site then you will get the evil version Player Plus X.



Last but but least, along with the Boxore adware came this Chrome extension called Smart Displat 1.1. We are not sure what it is, and we could find any information about this extension because it was removed from Chrome store. One way or another, this extension should be removed as well.

To remove Boxore adware and associated applications from your computer, please follow the removal instructions below. Good luck!

Source: http://deletemalware.blogspot.com


Boxore removal instructions:

1. First of all, download recommended anti-malware software and run a full system scan. It will detect and remove this infection from your computer. You may then follow the manual removal instructions below to remove the leftover traces of this browser hijacker. Hopefully you won't have to do that.





2. Go to the Start Menu. Select Control Panel → Add/Remove Programs.
If you are using Windows Vista or Windows 7, select Control Panel → Uninstall a Program.



3. Search for Boxore Client in the list. Select the program and click Remove button.

If you are using Windows Vista/7, click Uninstall up near the top of that window.



4. To remove Babylon toolbar and Babylon Search, please follow this removal guide.

5. Remove Smart Display 1.1 extension in Google Chrome.

 Click on Customize and control Google Chrome icon. Go to Tools → Extensions.



Select Smart Display 1.1 and click on the small recycle bin icon to remove the toolbar.



6. And finally, download recommended anti-malware software and run a full system scan to remove any associated malware or potentially unwanted applications from your computer.


Associated Boxore Adware files and registry values:

Files:
  • C:\Program Files\Boxore
  • C:\Program Files\Boxore\BoxoreClient
  • C:\Program Files\Boxore\BoxoreClient\boxore.exe
  • C:\Program Files\Boxore\BoxoreClient\COPYING
  • C:\Program Files\Boxore\BoxoreClient\index.dat
  • C:\Program Files\Boxore\BoxoreClient\rules.dat
  • C:\Program Files\Boxore\SmartDisplay\SmartExtensions\GoogleChrome\SmartDisplayExtension.crx
Registry values:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Boxore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Boxore\BoxoreClient
  • HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\jeaihkehdlhkocphopopahkfjcfcphef
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "Boxore Client"
Tell your friends:
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Adware | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Remove ShopperReports (Uninstall Guide)
    ShopperReports is defined as adware or a potentially unwanted program that displays marketing related results in a side pane of the browser...
  • Trojan.MBRlock, Внимание! Ваш компьютер заблокирован
    Trojan.MBRlock is a very disturbing piece of malicious code which infects the master boot record (MBR) and prevents Windows from starting. ...
  • Remove RiskTool.Win32.BitCoinMiner (Uninstall Guide)
    RiskTool.Win32.BitCoinMiner is a risk tool or potentially unwanted application that may use your computer's resources to generate bitco...
  • What is wrtc.exe and how to remove it?
    wrtc.exe - by Perion Network Ltd. What is wrtc.exe? wrtc.exe is a part of IncrediMail software, digitally signed by Perion Network Ltd. This...
  • Remove Rattlingsearchsystem.com (Uninstall Guide)
    Rattlingsearchsystem.com is a ZeroAccess/Sirefef rootkit-related browser hijacker that redirects users to shady websites while searching on...
  • False Positive: Ikarus and Comodo detecting TDSSKiller as a Trojan horse
    This awkward moment when you realize that your favorite rootkit removal utility is detected as malware. I probably wouldn't even have no...
  • Remove TR/ATRAPS.Gen2, removal instructions
    Cyber crooks and third parties that buy stolen data are increasingly using more and more sophisticated techniques, in a variety of different...
  • Remove Ask Search and Ask Toolbar (Uninstall Guide)
    Ask Search and Ask Toolbar are very often incorrectly classified as virus/spyware that may cause search redirects. The majority of us pref...
  • Remove Windows Attention Utility (Uninstall Guide)
    Windows Attention Utility is a rogue security application that generates misleading warnings about nonexistent viruses and attempts to lure...
  • Remove "System Check" (Uninstall Guide)
    System Check is malicious software posing as Windows system utility. Although, it may look like a real thing, it isn't! You are actuall...

Categories

  • Adware
  • Answers
  • Antivirus software
  • Browser Hijackers
  • Cloud Computing
  • Fake Alerts
  • Giveaways
  • Hoax
  • How-To
  • IaaS
  • Internet
  • Malicious websites
  • Malware
  • PaaS
  • Parental Controls
  • Passwords
  • Phishing
  • Process Information
  • Ransomware
  • Rogue programs
  • Rootkits
  • SaaS
  • Security Advisories
  • Spam
  • Spyware
  • Trojans
  • Viruses
  • Web Browsers
  • Worms

Blog Archive

  • ►  2013 (173)
    • ►  December (6)
    • ►  November (13)
    • ►  October (11)
    • ►  September (20)
    • ►  August (4)
    • ►  July (17)
    • ►  June (31)
    • ►  May (25)
    • ►  April (15)
    • ►  March (17)
    • ►  February (7)
    • ►  January (7)
  • ▼  2012 (86)
    • ►  November (2)
    • ►  October (4)
    • ►  September (6)
    • ►  August (6)
    • ▼  July (11)
      • Remove Windows Ultra Antivirus (Uninstall Guide)
      • SearchYa! Toolbar and Searchya.com (Uninstall Guide)
      • Boxore Adware (Uninstall Guide)
      • Remove Welcome to Nginx! (Uninstall Guide)
      • Remove Police Central e-crime Unit Virus (Uninstal...
      • Remove International Police Association (I.P.A.) V...
      • Remove MyStart by IncrediBar Search and Toolbar (U...
      • Apple Computers ARE Susceptible After All
      • Remove "File Recovery" Malware (Uninstall Guide)
      • Effective Network Internet Control for Effective S...
      • Remove FBI MoneyPak Ransomware (Uninstall Guide)
    • ►  June (1)
    • ►  May (5)
    • ►  April (7)
    • ►  March (7)
    • ►  February (17)
    • ►  January (20)
  • ►  2011 (239)
    • ►  December (8)
    • ►  November (18)
    • ►  October (21)
    • ►  September (24)
    • ►  August (28)
    • ►  July (32)
    • ►  June (16)
    • ►  May (23)
    • ►  April (15)
    • ►  March (16)
    • ►  February (9)
    • ►  January (29)
  • ►  2010 (2)
    • ►  December (2)
Powered by Blogger.

About Me

Unknown
View my complete profile