Logo_Malware
OneSoftPerDay is a software usually installs without your knowledge vith the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified the 08/15/2015.

Features:

– It belongs to a family of PUP (Potentially Unwanted Program).
– Vendor : PUP.Optional

Main actions :

– It installs as a process launched at startup of the system (RP),
– It settled in the Base of registers to be launched each time with the system (O4).
– It installs as a program (O42),
– It creates to many registry keys ‘Software’
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45).
– It creates multiple files users (O61),

ZHPDiag report:

[MD5.F2E7FB3408C580F1747BF407B0F17CF9] – (…) — C:\Users\Coolman\AppData\Local\ospd_us_013010061\upospd_us_013010061.exe [3313808] [PID.3316] [MD5.D99CF61126E4AED8A337B242FF8F6C4E] – (…) — C:\Program Files\ospd_us_013010061\ospd_us_013010061.exe [3982992] [PID.2844] O4 – HKLM\..\Run: [ospd_us_013010061] . (…) — C:\Program Files\ospd_us_013010061\ospd_us_013010061.exe
O4 – HKLM\..\RunOnce: [upospd_us_013010061.exe] . (…) — C:\Users\Coolman\AppData\Local\ospd_us_013010061\upospd_us_013010061.exe
O42 – Logiciel: OneSoftPerDay 025.013010061 – (.ONESOFTPERDAY.) [HKLM] — ospd_us_013010061_is1
HKLM\SOFTWARE\ONESOFTPERDAY
HKCU\SOFTWARE\onesoftperday
O43 – CFD: 2015/08/15 02:41:20 – [] D — C:\Program Files\ospd_us_013010061
O43 – CFD: 2015/08/15 02:41:20 – [] D — C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ONESOFTPERDAY
O43 – CFD: 2015/08/15 02:46:01 – [] D — C:\Users\Coolman\AppData\Local\ospd_us_013010061
O61 – LFC: 2015/08/14 19:14:57 A . (..) — C:\Users\Coolman\AppData\Local\ospd_us_013010061\upospd_us_013010061.exe [3313808] O61 – LFC: 2015/08/15 02:44:26 A . (..) — C:\Users\Coolman\AppData\Local\ospd_us_013010061\Download\myoffergroup_fr.exe [5044856]

Alias:

PUP.Optional.OneSoftPerDay.A [ Malwarebytes Antimalware ]

Remove:

– Remove software in Windows Configuration Panel,
Remove with ZHPcleaner
ZHPCleaner_EN2
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:22+00:00 Categories: PUP|Tags: |Comments Off on PUP.Optional.OneSoftPerDay