PUP.Optional.GoMusix is the detection for a Chrome extension called MusicBoxSearch that hijacks the new tab and search results. This PUP is a hijacker and part of a family of similar hijackers sometimes referred to as BLPSearch, because of the name of their default search keyword, but in this extensions case the keyword is MusicBox.
the PUP takes over the Search engine settings oof Chrome
Users that had their browsers hijacked should have a look at our Restore Browser page to see if additional measures are needed.
Our program Malwarebytes can detect and remove this potentially unwanted program without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com
-Log Details- Scan Date: 2/6/18 Scan Time: 1:10 PM Log File: c1eff460-0b36-11e8-9439-080027750297.json Administrator: Yes
-Software Information- Version: 3.3.1.2183 Components Version: 1.0.262 Update Package Version: 1.0.3881 License: Premium
-System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username}
-Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 241535 Threats Detected: 52 Threats Quarantined: 52 Time Elapsed: 2 min, 29 sec
-Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect
-Scan Details- Process: 0 (No malicious items detected)
Module: 0 (No malicious items detected)
Registry Key: 0 (No malicious items detected)
Registry Value: 0 (No malicious items detected)
Registry Data: 0 (No malicious items detected)
Data Stream: 0 (No malicious items detected)
Folder: 12 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official\onesignal, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\_metadata, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\vertical, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GMCOGIOMGBBNMABKNLDEIKBKNAPOLPDE, Quarantined, [8314], [450916],1.0.3881
File: 39 PUP.Optional.GoMusix.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde\000003.log, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde\CURRENT, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde\LOCK, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde\LOG, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gmcogiomgbbnmabknldeikbknapolpde\MANIFEST-000001, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GMCOGIOMGBBNMABKNLDEIKBKNAPOLPDE\1.0.0_0\MANIFEST.JSON, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\material-icons.css, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.eot, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.ijmap, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.svg, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.ttf, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.woff, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\MaterialIcons-Regular.woff2, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\RobotoCondensed-Light.ttf, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\fonts\RobotoCondensed-Regular.ttf, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\css\style.css, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare\close.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare\rate.jpg, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare\rate1.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare\share.jpg, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\rateshare\share1.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\icon128.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\icon16.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\images\icon38.png, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official\onesignal\onesignal.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official\bootstrap.min.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official\jquery.min.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\official\material.min.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\base.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\init.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\js\main.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\vertical\440x280.jpg, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\vertical\init.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\vertical\pop.js, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\_metadata\computed_hashes.json, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\_metadata\verified_contents.json, Quarantined, [8314], [450916],1.0.3881 PUP.Optional.GoMusix.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde\1.0.0_0\popup.html, Quarantined, [8314], [450916],1.0.3881
Physical Sector: 0 (No malicious items detected)
(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
Possible signs in a FRST log:
CHR DefaultSearchURL: Default -> hxxp://music.eanswers.com/go/?category=web&s=21ds&vert=music&q={searchTerms} CHR DefaultSearchKeyword: Default -> MusicBox CHR DefaultSuggestURL: Default -> hxxp://sug.eanswers.com/search/index_sg.php?q={searchTerms} CHR Extension: (MusicBox Search) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmcogiomgbbnmabknldeikbknapolpde [2018-02-06]Domains: superappbox.com myfriendlyappz.com eanswers.com
Chrome extension ID: gmcogiomgbbnmabknldeikbknapolpde
Select your language