SimpleFiles is a software usually installed without your knowledge with the download of freeware. In fact some sites use the method of repackaging. This is an operation that is to redo the module software installation by adding download options. These options allow to add other software as for example toolbars browser, or potentially unwanted software. The addition of these new programs can decrease the performance of the system but also slow or redirect internet surfing. As a general rule, should focus on the author’s official site to download your software.
Identified :09/09/2015.

0_Features

– It belongs to a family of PUP (Potentially Unwanted Program).
– A polluteware is a software that pollutes storage and/or the Base of registers.
– An Adware is a program that adds other programs without the knowledge of the user.
– Vendor : PUP.Optional

0_Main_Actions

– It installs as a process launched at startup of the system (RP),
– It starts a task planned in automatic (O39),
– It installs as a program (O42),
– It creates to many registry keys ‘Software’,
– It creates additional folders (O43),
– It moved to the Windows prefetcher folder (O45),
– It installs as an Authorized Application Export Key (ECAA) (O47),
– It creates multiple files users (O61),
– It creates an active incoming connection in the application of the firewall Windows exceptions (O87),

0_Zhpdiag

[MD5.BC9E504665B1CB8BA8C2E17411D0E92F] – (.http://simple-files.com/ – SimpleFiles Updater Application.) — C:\Program Files (x86)\SimpleFiles\SFUpdater.exe [456248] [PID.2536] [MD5.50E4E988CB9E798DDF5CB541407CA54D] – (.http://simple-files.com/ – SimpleFiles Updater Application.) — C:\Program Files\SimpleFiles\SFUpdater.exe [270848] [PID.2584] [MD5.4192437A7200710DE05C038FFA765FBD] – (.http://simple-files.com/ – SimpleFiles Application.) — C:\Program Files\SimpleFiles\SimpleFiles.exe [2334720] [PID.1472] O39 – APT:Automatic Planified Task – C:\WINDOWS\Tasks\SimpleFilesUpdate.job [286] [MD5.BC9E504665B1CB8BA8C2E17411D0E92F] [APT] [SimpleFilesUpdate] (.http://simple-files.com/.) — C:\Program Files (x86)\SimpleFiles\SFUpdater.exe [456248] [MD5.50E4E988CB9E798DDF5CB541407CA54D] [APT] [SimpleFilesUpdate] (.http://simple-files.com/.) — C:\Program Files\SimpleFiles\SFUpdater.exe [270848] O42 – Logiciel: SimpleFiles – (.http://www.simple-files.com/.) [HKCU][64Bits] — SimpleFiles[HKLM\Software\Wow6432Node\SimpleFiles] [HKCU\Software\SimpleFiles] [HKLM\Software\SimpleFiles] O43 – CFD: 05/09/2013 – 15:46:04 – [10,070] —-D C:\Program Files (x86)\SimpleFiles
O43 – CFD: 05/09/2013 – 15:46:26 – [0,002] —-D C:\Users\Coolman\AppData\Roaming\SimpleFiles
O43 – CFD: 23/09/2013 – 09:03:57 – [0,002] —-D C:\Documents and Settings\Coolman\Application Data\SimpleFiles
O47 – AAKE:Key Export SP – “C:\Program Files\SimpleFiles\downloader.exe” [Enabled] .(.http://simple-files.com/.) — C:\Program Files\SimpleFiles\downloader.exe
O47 – AAKE:Key Export SP – “C:\Program Files\SimpleFiles\SimpleFiles.exe” [Enabled] .(.http://simple-files.com/.) — C:\Program Files\SimpleFiles\SimpleFiles.exe
O61 – LFC: 23/09/2013 – 07:47:23 —A- . (.http://www.simple-files.com/.) — C:\Users\Coolman\Downloads\installer.exe [5214880] [MD5.D0FF0A9D393D465FCDD2C37335759860] [SPRF][19/09/2013] (.http://www.simple-files.com/ – SimpleFiles.) — C:\Users\Coolman\AppData\Local\Temp\uninstall582970073.exe [5377352] [MD5.4192437A7200710DE05C038FFA765FBD] [SPRF][19/09/2013] (.http://simple-files.com/ – SimpleFiles Application.) — C:\Users\Coolman\AppData\Local\Temp\uninstall582988450.exe [2334720] [MD5.EA764A1E4602FEC339DFC06A3C2757F7] [SPRF][19/09/2013] (.http://simple-files.com/ – SimpleFiles Downloader Application.) — C:\Users\Coolman\AppData\Local\Temp\uninstall582988777.exe [1835520] [MD5.50E4E988CB9E798DDF5CB541407CA54D] [SPRF][19/09/2013] (.http://simple-files.com/ – SimpleFiles Updater Application.) — C:\Users\Coolman\AppData\Local\Temp\uninstall582988902.exe [270848] O87 – FAEL: “{9CDAA854-280D-4DA8-AA71-5C13F5F73612}” | In – Private – P6 – TRUE | .(.http://simple-files.com/ – SimpleFiles Downloader Application.) — C:\Program Files (x86)\SimpleFiles\downloader.exe
O87 – FAEL: “{CAA6B443-84FE-40B5-81F5-8A0F80F1BB67}” | In – Private – P17 – TRUE | .(.http://simple-files.com/ – SimpleFiles Downloader Application.) — C:\Program Files (x86)\SimpleFiles\downloader.exe
O87 – FAEL: “{FD280200-B9C3-4F51-8316-7191DF4DE149}” | In – Private – P6 – TRUE | .(.http://simple-files.com/ – SimpleFiles Application.) — C:\Program Files (x86)\SimpleFiles\SimpleFiles.exe
O87 – FAEL: “{5C7CE351-D3F6-4746-AE77-3B5876EB6072}” | In – Private – P17 – TRUE | .(.http://simple-files.com/ – SimpleFiles Application.) — C:\Program Files (x86)\SimpleFiles\SimpleFiles.exe[HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SimpleFiles] [HKLM\Software\Wow6432Node\SimpleFiles] [HKCU\Software\SimpleFiles] [HKLM\Software\SimpleFiles] C:\Program Files\SimpleFiles
C:\Program Files (x86)\SimpleFiles
C:\Program Files (x86)\SimpleFiles\SFUpdater.exe
C:\Documents and Settings\Coolman\Application Data\SimpleFiles
C:\Users\Coolman\AppData\Roaming\SimpleFiles

0_Alias

AVware Trojan.Win32.Generic!BT 20151113
Agnitum Riskware.Agent! 20151113
Avira PUA/EDownloader.Gen 20151113
Comodo Application.Win32.EDownload.WC 20151113
DrWeb Adware.Downware.10777 20151113
ESET-NOD32 a variant of Win32/ExpressFiles.C potentially unwanted 20151113
Fortinet Riskware/ExpressFiles 20151113
GData Win32.Application.Expressdownloader.I 20151113
K7AntiVirus Adware ( 004c1a9c1 ) 20151113
K7GW Adware ( 004c1a9c1 ) 20151113
Malwarebytes PUP.Optional.SimpleFiles 20151113
Sophos Generic PUA JF (PUA) 20151113
VIPRE Trojan.Win32.Generic!BT 20151114

Remove_Software

– Remove software in Windows Configuration Panel,
0_ZHPcleaner
Remove with ZHPcleaner
ZHPCleaner_EN2
0_Zhpdiag
Diagnose with ZHPDiag
ZHPDiag_2-300x220

2016-12-30T07:34:15+00:00 Categories: Adware, Polluteware, PUP|Tags: , , |Comments Off on PUP.Optional.SimpleFiles