{"id":6558,"date":"2017-02-08T11:10:08","date_gmt":"2017-02-08T19:10:08","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/08\/news-382\/"},"modified":"2017-02-08T11:10:08","modified_gmt":"2017-02-08T19:10:08","slug":"news-382","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/02\/08\/news-382\/","title":{"rendered":"Spigot browser hijackers"},"content":{"rendered":"<p>There is a large family of Spigot browser hijackers that all have a lot in common. So by giving you a description of them we hope this will help you to avoid any similar and new ones that might come along.<\/p>\n<h3><strong>Targeted browsers<\/strong><\/h3>\n<p>For some, but not all browser hijackers in this family there are extensions for Firefox and Google Chrome. In Internet Explorer they change the default Search Provider and the startpage. Trying to install the PUP on Edge will get you nothing but an \u201cUnsupported Browser\u201d notice.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16306\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/unsupported.png\" alt=\"\" width=\"449\" height=\"220\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/unsupported.png 449w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/unsupported-300x147.png 300w\" sizes=\"auto, (max-width: 449px) 100vw, 449px\" \/><\/p>\n<p>Recognizing the sites<br \/> The websites where these hijackers can be downloaded will show you the EULA &#8212;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16302\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/EULA.png\" alt=\"\" width=\"777\" height=\"579\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/EULA.png 777w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/EULA-300x224.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/EULA-600x447.png 600w\" sizes=\"auto, (max-width: 777px) 100vw, 777px\" \/><\/p>\n<p>&#8211;explaining to you, \u201cthe User\u201d, what the downside of installing \u201cthe Software\u201d might be.<\/p>\n<blockquote>\n<p>The Software is a free desktop application that offers you direct links to websites from your new preferred homepage and saves your new preferred home page and\/or new tab page. When we set your Browser&#8217;s settings using the Software, they will be saved automatically on Chrome\u2122, Firefox\u00ae, and Internet Explorer\u00ae. As part of the installation process of the Software, we may change your Internet Browser settings and\/or provide you with the ability to opt to make changes to your Internet Browser settings.<\/p>\n<\/blockquote>\n<h3><strong>Download locations<\/strong><\/h3>\n<p>Downloads typically come from proinstall-download[dot]com or report-download[dot]com (both blocked by our <a href=\"https:\/\/blog.malwarebytes.com\/101\/2016\/08\/explained-the-malwarebytes-website-protection-module\/\" target=\"_blank\">Web Protection module<\/a>). Both of these domains are registered with GoDaddy (no surprise there!). \u00a0The download location changed not too long ago.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16303\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/filedr08.png\" alt=\"\" width=\"611\" height=\"366\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/filedr08.png 611w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/filedr08-300x180.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/filedr08-600x359.png 600w\" sizes=\"auto, (max-width: 611px) 100vw, 611px\" \/><\/p>\n<p>It used to be secure[dot]fileldr08[dot]com and from the screenshot above you can see why we categorized these browser hijackers as PUP.Optional.Spigot. Worth noting is that after they switched away from the above download location, I was unable to install the extensions on Google Chrome. It failed to download and offer the extension. But this got fixed after a few weeks.<\/p>\n<h3><strong>The startpage<\/strong><\/h3>\n<p>The new startpage for the affected browser is a typical search page with a toolbar and some shortcuts, pointing to sites where you can find the information or functionality that the hijacker promised to provide, supplemented by local weather and social media links.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16305\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/startpage.png\" alt=\"\" width=\"800\" height=\"394\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/startpage.png 800w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/startpage-300x148.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/startpage-600x296.png 600w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/p>\n<h3><strong>Installation guidance<\/strong><\/h3>\n<p>Another typical behavior, that these hijackers copied from the likes of <a href=\"https:\/\/blog.malwarebytes.com\/detections\/pup-optional-mindspark\/\" target=\"_blank\">Mindspark<\/a>, is the right in your face installation guidance with huge green arrows pointing out what your next step should be.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-16304\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/pointedout.png\" alt=\"\" width=\"564\" height=\"312\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/pointedout.png 564w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/pointedout-300x166.png 300w\" sizes=\"auto, (max-width: 564px) 100vw, 564px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Removal guides<\/strong><\/p>\n<p>You can find some examples among the removal guides on our forums:<\/p>\n<ul>\n<li><a href=\"https:\/\/forums.malwarebytes.com\/topic\/193893-removal-instructions-for-my-email-xp\/\" target=\"_blank\">My Email XP<\/a><\/li>\n<li><a href=\"https:\/\/forums.malwarebytes.com\/topic\/194396-removal-instructions-for-your-television-now\/\" target=\"_blank\">Your Television Now<\/a><\/li>\n<li><a href=\"https:\/\/forums.malwarebytes.com\/topic\/195456-removal-instructions-for-easy-online-game-access\/\" target=\"_blank\">Easy Online Game Access<\/a><\/li>\n<li><a href=\"https:\/\/forums.malwarebytes.com\/topic\/195875-removal-instructions-for-getfitnow\/\" target=\"_blank\">GetFitNow<\/a><\/li>\n<\/ul>\n<h3><strong>Summary<\/strong><\/h3>\n<p>Spigot browser hijackers of this family are easy to recognize and in our opinion hardly worth installing because they add no more functionality than a few bookmarks. We hope this post helps you to avoid them in the future.<\/p>\n<p>As always: <strong>Save yourself the hassle and get protected.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<p><em>Pieter Arntz<\/em><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/puppum\/2017\/02\/spigot-browser-hijackers\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/puppum\/2017\/02\/spigot-browser-hijackers\/' title='Spigot browser hijackers'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/02\/headerSpigot.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>Spigot browser hijackers of this family are easy to recognize and in our opinion hardly worth installing because they add no more functionality then a few bookmarks. We hope this post helps you to avoid them in the future.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/puppum\/\" rel=\"category tag\">PUP\/PUM<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/browser-hijacker\/\" rel=\"tag\">browser hijacker<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pieter-arntz\/\" rel=\"tag\">Pieter Arntz<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/potentially-unwanted-programs\/\" rel=\"tag\">potentially unwanted programs<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/pup\/\" rel=\"tag\">PUP<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/spigot\/\" rel=\"tag\">Spigot<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/puppum\/2017\/02\/spigot-browser-hijackers\/' title='Spigot browser hijackers'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11278,10523,11279,10566,10557,11280],"class_list":["post-6558","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-browser-hijacker","tag-pieter-arntz","tag-potentially-unwanted-programs","tag-pup","tag-puppum","tag-spigot"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6558"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6558\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}