PUP.Optional.IEnjoyApps is Malwarebytes detection name for a large family of browser extensions that act as search hijackers and target the Chrome browser.
Users may notice prompts like this one during install:
and see that their default serach engine has changed.
PUP.Optional.IEnjoyApps hijacks the users' search results by changing the default search engine for the affected browser. Most of the extensions detected as PUP.Optional.IEnjoyApps can be downloaded from the domain ienjoyapps.com and are offered as search extensions specialized in a certain field like movies, games, etc.
Malwarebytes can detect and remove PUP.Optional.IEnjoyApps without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com-Log Details- Scan Date: 11/15/18 Scan Time: 10:48 AM Log File: a6c7b8fe-e8bb-11e8-ae27-00ffdcc6fdfc.json
-Software Information- Version: 3.6.1.2711 Components Version: 1.0.482 Update Package Version: 1.0.7855 License: Premium
-System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username}
-Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 237864 Threats Detected: 41 Threats Quarantined: 41 Time Elapsed: 2 min, 57 sec
-Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect
-Scan Details- Process: 0 (No malicious items detected)
Module: 0 (No malicious items detected)
Registry Key: 0 (No malicious items detected)
Registry Value: 1 PUP.Optional.IEnjoyApps.Generic, HKCU\SOFTWARE\GOOGLE\CHROME\PREFERENCEMACS\Default\extensions.settings|dmfdjkfpljiniadicampijngdedfppfh, Quarantined, [14284], [443085],1.0.7855
Registry Data: 0 (No malicious items detected)
Data Stream: 0 (No malicious items detected)
Folder: 9 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\official, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\_metadata, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\vertical, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\images, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\DMFDJKFPLJINIADICAMPIJNGDEDFPPFH, Quarantined, [14284], [443085],1.0.7855
File: 31 PUP.Optional.IEnjoyApps.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Preferences, Replaced, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\DMFDJKFPLJINIADICAMPIJNGDEDFPPFH\1.0.1_0\MANIFEST.JSON, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\material-icons.css, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.eot, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.ijmap, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.svg, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.ttf, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.woff, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\MaterialIcons-Regular.woff2, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\RobotoCondensed-Light.ttf, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\fonts\RobotoCondensed-Regular.ttf, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\css\style.css, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\images\icon128.png, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\images\icon16.png, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\images\icon38.png, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\official\bootstrap.min.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\official\jquery.min.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\official\material.min.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\base.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\init.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\js\main.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\vertical\440x280.jpg, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\vertical\init.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\vertical\pop.js, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\_metadata\computed_hashes.json, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\_metadata\verified_contents.json, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.IEnjoyApps.Generic, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh\1.0.1_0\popup.html, Quarantined, [14284], [443085],1.0.7855 PUP.Optional.SearchAlgo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [337], [454816],1.0.7855 PUP.Optional.SearchAlgo, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, Replaced, [337], [454816],1.0.7855
Physical Sector: 0 (No malicious items detected)
WMI: 0 (No malicious items detected)
(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
You may see these entries in FRST logs:
CHR DefaultSearchURL: Default -> hxxp://movix.searchalgo.com/go/?category=web&s=tidp&vert=movies&var=plus&q={searchTerms} CHR DefaultSearchKeyword: Default -> iTheatre CHR DefaultSuggestURL: Default -> hxxp://sug.searchalgo.com/search/index_sg.php?q={searchTerms} CHR Extension: (iTheatre Search Plus) - C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfdjkfpljiniadicampijngdedfppfh [2018-11-15]
Select your language