Adware.HPDefender is Malwarebytes' generic detection name for a family of adwaretargeting Windows systems.
Adware.HPDefender is spread by bundlers. Its main focus is browser hijacking, using many different methods, including manipulating your browser(s) to change your startpage or searchscopes so that the affected browser visits their site or one of their choice.Adware.HPDefender replaces many browser shortcuts and shows advertisements.
Malwarebytes can detect and remove Adware.HPDefender without further user interaction.
An example Malwarebytes removal log for a member of this family called QIPApp:
Malwarebyteswww.malwarebytes.com-Log Details-Scan Date: 6/1/17Scan Time: 9:11 AMLog File: mbamQIPApp.txtAdministrator: Yes-Software Information-Version: 3.1.2.1733Components Version: 1.0.122Update Package Version: 1.0.2064License: Premium-System Information-OS: Windows 7 Service Pack 1CPU: x64File System: NTFSUser:{computername}\{username}-Scan Summary-Scan Type: Threat ScanResult: CompletedObjects Scanned: 333477Threats Detected: 11Threats Quarantined: 11Time Elapsed: 1 min, 56 sec-Scan Options-Memory: EnabledStartup: EnabledFilesystem: EnabledArchives: EnabledRootkits: DisabledHeuristics: EnabledPUP: EnabledPUM: Enabled-Scan Details-Process: 1Adware.HPDefender, C:\USERS\{username}\APPDATA\ROAMING\QIPAPP\QIPAPP.EXE, Quarantined, [21], [403763],1.0.2064Module: 1Adware.HPDefender, C:\USERS\{username}\APPDATA\ROAMING\QIPAPP\QIPAPP.EXE, Quarantined, [21], [403763],1.0.2064Registry Key: 2PUP.Optional.ICLoader, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\QIPApp, Delete-on-Reboot, [652], [403803],1.0.2064Adware.QIPApp, HKCU\SOFTWARE\QIPApp, Delete-on-Reboot, [9346], [390812],1.0.2064Registry Value: 1Adware.HPDefender, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|QIPApp, Delete-on-Reboot, [21], [403763],1.0.2064Registry Data: 0(No malicious items detected)Data Stream: 0(No malicious items detected)Folder: 2Adware.HPDefender, C:\Users\{username}\AppData\Roaming\QIPApp\QIPApp, Delete-on-Reboot, [21], [396014],1.0.2064Adware.HPDefender, C:\USERS\{username}\APPDATA\ROAMING\QIPAPP, Delete-on-Reboot, [21], [396014],1.0.2064File: 4Adware.HPDefender, C:\USERS\{username}\APPDATA\ROAMING\QIPAPP\QIPAPP.EXE, Delete-on-Reboot, [21], [403763],1.0.2064PUP.Optional.ICLoader, C:\USERS\{username}\DESKTOP\4617463.EXE, Delete-on-Reboot, [652], [403803],1.0.2064PUP.Optional.ICLoader, C:\USERS\{username}\APPDATA\ROAMING\QIPAPP\UNINSTALLER.EXE, Delete-on-Reboot, [652], [403803],1.0.2064Adware.HPDefender, C:\Users\{username}\AppData\Roaming\QIPApp\QIPApp\qipApp8.exe, Delete-on-Reboot, [21], [396014],1.0.2064Physical Sector: 0(No malicious items detected)(end)Removal guides for other examples:
Select your language