Related blog content
How to avoid potentially unwanted programs
How your business can avoid potentially unwanted programs
Adware the series, part 1 (browser extensions)
PUP.Optional.BrowserModule is the detection for a family of potentially unwanted browser hijackers that use extensions for browsers such as Chrome, Safari, Firefox, Opera, and Internet Explorer to show advertisements.
PUP.Optional.BrowserModule comes bundled with other software and uses browser extensions to show advertisements.
Malwarebytes protects users from PUP.Optional.BrowserModule by using real-time protection.
Malwarebytes blocks PUP.Optional.BrowserModule
Malwarebytes can detect and remove PUP.Optional.BrowserModule without further user interaction.
If you are using Opera, you may have to remove the Extension manually under Opera > Extensions. First, disable the extension and then click the x behind Tables and click OK in the prompt to confirm.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/18/17 Scan Time: 9:31 AM Logfile: mbamTablesExtensions.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.96 Update Package Version: 1.0.1751 License: Premium -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username} -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 327079 Time Elapsed: 1 min, 13 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 2 PUP.Optional.BrowserModule, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Advanced Module_is1, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, HKCU\SOFTWARE\BROWSERMODULE, Delete-on-Reboot, [2207], [389761],1.0.1751 Registry Value: 2 PUP.Optional.BrowserModule, HKCU\SOFTWARE\BROWSERMODULE|INSTEVENT, Delete-on-Reboot, [2207], [389761],1.0.1751 PUP.Optional.BrowserModule, HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ADVANCED MODULE_IS1|INNO SETUP: APP PATH, Delete-on-Reboot, [2207], [389764],1.0.1751 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 9 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\BROWSERMODULE, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\js, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\FNGMHNNPILHPLAEEDIFHCCCEOMCLGFBG, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\js, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\EGAFJHHPBIPCMPOIOMEGBCKLJBBBPHOJ, Delete-on-Reboot, [2207], [389743],1.0.1751 File: 19 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\BROWSERMODULE\UNINS000.DAT, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\BrowserModule\unins000.exe, Delete-on-Reboot, [2207], [389763],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\DESKTOP\MYSETUP.EXE, Delete-on-Reboot, [2207], [389737],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\FNGMHNNPILHPLAEEDIFHCCCEOMCLGFBG\78.0_0\MANIFEST.JSON, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon128.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon16.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon24.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\icon\icon32.png, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\js\background.js, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg\78.0_0\index.html, Delete-on-Reboot, [2207], [389742],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\CHROME\USERCONTENT.CSS, Delete-on-Reboot, [2207], [389741],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\{profile}\EXTENSIONS\669206@extcorp.com.xpi, Delete-on-Reboot, [2207], [389762],1.0.1751 PUP.Optional.BrowserModule, C:\USERS\{username}\APPDATA\ROAMING\OPERA SOFTWARE\OPERA STABLE\EXTENSIONS\EGAFJHHPBIPCMPOIOMEGBCKLJBBBPHOJ\1.1_0\MANIFEST.JSON, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon128.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon16.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon24.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\icon\icon32.png, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\js\background.js, Delete-on-Reboot, [2207], [389743],1.0.1751 PUP.Optional.BrowserModule, C:\Users\{username}\AppData\Roaming\Opera Software\Opera Stable\Extensions\egafjhhpbipcmpoiomegbckljbbbphoj\1.1_0\index.html, Delete-on-Reboot, [2207], [389743],1.0.1751 Physical Sector: 0 (No malicious items detected) (end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
The Exclusions tab includes a list of items to be excluded from scans. The items may include files, folders, websites, or applications that connect to the Internet, as well as previously detected exploits.
To access the exclusions in Malwarebytes:
Select your language