Should I remove PassShow?
What percent of users and experts removed it?
88% remove it12% keep it
What do people think about it?
(click star to rate)
How common is it?
Global Rank #6,049
United States Rank #4,523
Reach 0.0765%
Lifespan of installation (until removal)
< 5.38 days
158.57 days >
Average installed length: 83.32 days
Other programs by Revizer Technologies
Rankings
- #6,044 Sound Blaster Cinema 2 by Creative Technology Ltd
- #6,045 CDBurnerXP by Canneverbe Limited
- #6,046 Use the entry named LeapFrog Connect to uninstall (LeapFrog My Pals Plugin)
- #6,047 Intel PROSet/Wireless WiFi-Software
- #6,048 KMP Media Toolbar by APN
- #6,049 PassShow by Revizer Technologies
- #6,050 USB Network Driver
- #6,051 Adobe ExtendScript Toolkit CC
- #6,052 Visual CertExam Suite by Avanset
- #6,053 BrowserSafeguard by Adknowledge
- #6,054 Prise en charge du transfert VAIO by Sony
PassShow
from Revizer Technologies
What is PassShow?
PassShow is an adware program that integrates with the user's web browser (IE, Chrome and Firefox) and will hijack the normal home, search and new tab pages as well as redirections. In addition, it will display ads within the browser including banner, context and popup ads.
From the EULA:
"The Extension enables you to view the characters you enter on your keyboard in the password field when you login to any website or system. The Extension will enhance your online experience by adding features, functionality and content through your browser. The Extension is FREE of charge and sponsored by advertisements and commercial offers that may be displayed to you by Vendors.
To ensure continuous Service and proper functionality of the Extension we may operate in a proxy configuration. Proxy is a server that acts as an intermediary for requests from clients seeking resources from other servers. At your sole request you can manually revert back your proxy configuration to its original state or by completely uninstall the Extension."
About (from Revizer Technologies)
The Extension enables you to view the characters you enter on your keyboard in the password field when you login to any website/system. The use of the Extension is free of charge and sponsored by advertisements that would be served to you by Us, by Our affiliates or by third party vendors (“Vendors”) under their sole t... Read more
Overview
- Malware detected in the program
- Automatically starts with Windows
- Adds a toolbar to IE and an extension to Chrome and Firefox
- Installs a Windows Service
- Typically distributed through a pay-per-install bundle
- Injects advertisements unassociated with the underlying web page
- The experts agree, you should remove it!
Warning, multiple anti-virus scanners have detected possible malware in PassShow.
PsUP.exe (9d0a795cf9e2d500262ea7ed8dc64b63) has been flagged by the following 13 scanners: |
Anti-Virus software | Version | Detection |
Lavasoft Ad-Aware |
1120 |
Gen:Variant.Adware.Graftor.126142 |
AhnLab-V3 |
2014.01.04 |
Adware/Win32.AddLyrics |
avast! |
2014.9-140110 |
Win32:Agent-ASMU [PUP] |
Baidu-International |
4.0.3.14110 |
Adware.Win32.AddLyrics.77 |
Bitdefender |
1.0.20.50 |
Gen:Variant.Adware.Graftor.126142 |
Comodo Security |
17547 |
Application.Win32.AddLyrics.X |
Emsisoft Anti-Malware |
8.14.01.10.12 |
Gen:Variant.Adware.Graftor.126142 |
F-Secure |
11.2014-10-01_6 |
Gen:Variant.Adware.Graftor.126142 |
G Data |
14.1.22 |
Gen:Variant.Adware.Graftor.126142 |
IKARUS anti.virus |
t3scan.2.2.29 |
Win32.SuspectCrc |
MicroWorld-eScan |
15.0.0.30 |
Gen:Variant.Adware.Graftor.126142 |
Panda Antivirus |
14.01.10.12 |
Suspicious file |
TrendMicro-HouseCall |
7.2.10 |
TROJ_GEN.F47V1221 |
PassShow_wd.exe (14c0e8676457d02bcdca3e7ab8cb48ff) has been flagged by the following 12 scanners: |
Anti-Virus software | Software version | Detection |
avast! |
8.0.1489.320 |
Win32:Adware-BLC [PUP] |
AVG |
13.0.0.3169 |
Generic5.AREY |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AD150.B |
Comodo Security |
18095 |
Application.Win32.Adware.WDUnlocker.A |
ESET-NOD32 |
9670 |
a variant of Win32/AdWare.AD150.B |
Jiangmin |
16.0.100 |
Adware/Agent.jop |
McAfee |
6.0.4.564 |
Adware-AddLyrics!14C0E8676457 |
McAfee-GW-Edition |
2013 |
Adware-AddLyrics!14C0E8676457 |
Panda Antivirus |
10.0.3.5 |
Trj/Genetic.gen |
Symantec |
20131.1.5.61 |
WS.Reputation.1 |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.R0C1H06CI14 |
VIPRE Antivirus |
28212 |
Adware.AddLyrics |
PassShow157.exe (587362c43b7aa9ceeb0b55d9e32fef4d) has been flagged by the following 10 scanners: |
Anti-Virus software | Software version | Detection |
AhnLab-V3 |
None |
Trojan/Win32.Dropper |
avast! |
8.0.1489.320 |
Win32:Dropper-gen [Drp] |
AVG |
13.0.0.3169 |
Generic_r.JH |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AD150.B |
ESET-NOD32 |
9612 |
a variant of Win32/AdWare.AD150.B |
McAfee |
6.0.4.564 |
Artemis!587362C43B7A |
McAfee-GW-Edition |
2013 |
Artemis!587362C43B7A |
Qihoo-360 |
1.0.0.1015 |
Win32/Trojan.Dropper.c9f |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.F47V0328 |
VIPRE Antivirus |
27844 |
Trojan.Win32.Generic!BT |
154.dll (e376f6f63b9535937f4dce83db62689a) has been flagged by the following 7 scanners: |
Anti-Virus software | Software version | Detection |
AVG |
13.0.0.3169 |
Generic5.ANSH |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AddLyrics.gen |
IKARUS anti.virus |
T3.1.5.6.0 |
AdWare.Win32.AddLyrics |
K7 AntiVirus |
9.176.11311 |
Riskware ( 0040f01a1 ) |
K7GW |
9.176.11311 |
Riskware ( 0040f01a1 ) |
Microsoft Security Essentials |
1.10302 |
Adware:Win32/AddLyrics |
Trend Micro |
9.740-1012 |
BREX_ADDLYRICS.A |
PassShow158.exe (507cd9f774dc0d138f5c80e10d8b1630) has been flagged by the following 6 scanners: |
Anti-Virus software | Software version | Detection |
Antiy-AVL |
0.1.0.1 |
GrayWare[AdWare:not-a-virus]/Win32.Agent |
avast! |
8.0.1489.320 |
Win32:Adware-BMG [PUP] |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AddLyrics.AK |
ESET-NOD32 |
9725 |
a variant of Win32/AdWare.AddLyrics.AK |
Kaspersky |
12.0.0.1225 |
not-a-virus:AdWare.Win32.Agent.akhq |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.R0C9H07DN14 |
PassShowwd.exe (d91e199c6de67404b4229e6e3532215a) has been flagged by the following 5 scanners: |
Anti-Virus software | Software version | Detection |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AD150.B |
Comodo Security |
18015 |
Application.Win32.Adware.WDUnlocker.A |
ESET-NOD32 |
9612 |
a variant of Win32/AdWare.AD150.B |
Jiangmin |
16.0.100 |
Adware/Agent.jhs |
Panda Antivirus |
10.0.3.5 |
Trj/Genetic.gen |
PsUP..exe (dc800b9a3d7da0669e5f4894c281377d) has been flagged by the following 5 scanners: |
Anti-Virus software | Software version | Detection |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AddLyrics.AJ |
Dr.Web |
7.00.9.04080 |
Trojan.Lyrics.75 |
ESET-NOD32 |
9725 |
a variant of Win32/AdWare.AddLyrics.AJ |
Malwarebytes |
1.75.0001 |
PUP.Optional.AdLyrics.A |
Sophos |
4.98.0 |
AddLyrics |
PassShow155.exe (ece74a8b7bc72a632ff83041e41f49a3) has been flagged by the following 4 scanners: |
Anti-Virus software | Software version | Detection |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AD150.A |
Comodo Security |
17876 |
ApplicUnwnt |
ESET-NOD32 |
9492 |
a variant of Win32/AdWare.AD150.A |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.F47V0222 |
PsUPeg.exe (f321efd237b2efd32c2d0841b7217730) has been flagged by the following 4 scanners: |
Anti-Virus software | Software version | Detection |
Baidu-International |
3.5.1.41473 |
Adware.Win32.AddLyrics.AI |
ESET-NOD32 |
9633 |
a variant of Win32/AdWare.AddLyrics.AI |
Malwarebytes |
1.75.0001 |
PUP.Optional.AdLyrics.A |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.F47V0327 |
157.dll (5737282402ef67b5830e6cbb00f19a85) has been flagged by the following 2 scanners: |
Anti-Virus software | Software version | Detection |
Symantec |
20131.1.5.61 |
Adware.Popuppers |
TrendMicro-HouseCall |
9.700-1001 |
TROJ_GEN.R0C1H05D814 |
View all 68 all detections
PassShow has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.
Program details
Displayed publisher: PassShow Software
URL: passshow.com
Installation folder: C:\Program Files\passshow
Uninstaller: C:\Program Files\PassShow\Uninstall.exe
Estimated size: 1.14 MB
Files installed by PassShow
Program executable: | PsUP.exe (Malware detected) |
Path: | C:\Program Files\passshow\PsUP.exe |
MD5: | 9d0a795cf9e2d500262ea7ed8dc64b63 |
Additional files:
-
(Malware detected) PsUP.exe
-
Uninstall.exe
-
(Malware detected) PassShow_wd.exe
-
PassShow158.dll
-
PassShow158.exe
-
PsUP..exe
-
150.crx
-
150.dll
-
150.xpi
-
154.crx
-
(Malware detected) 154.dll
-
154.xpi
-
155.crx
-
155.xpi
-
(Malware detected) 157.dll
-
157.xpi
-
171.crx
-
171.xpi
-
(Malware detected) PassShow155.exe
-
(Malware detected) PassShow157.exe
-
(Malware detected) PassShowwd.exe
-
(Malware detected) PsUPeg.exe
-
Sqlite3.dll
Behaviors exhibited
3 Internet Explorer BHOs
- 157.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'PassShow' with the class of {4e1dfdc4-5474-47fc-bcaa-6f1f0c49bae2}.
- 154.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'PassShow' with the class of {0d97db6b-c9b0-4c07-98b7-818628ab37e2}.
- 150.dll is installed in Internet Explorer as a BHO (Browser Helper Object) under the name 'PassShow' with the class of {2d661e5b-7d7a-417c-b5b5-6479017bb314}.
5 Scheduled Tasks
- PsUP..exe is scheduled as a task named 'PassShow Update' (runs daily at 3:44 PM).
- PassShow_wd.exe is scheduled as a task named 'PassShow_wd' (runs daily at 3:55 PM).
- PsUPeg.exe is scheduled as a task named 'PassShow Update' (runs daily at 6:47 AM).
- PsUP.exe is scheduled as a task named 'PassShow Update' (runs daily at 4:23 PM).
- PassShowwd.exe is scheduled as a task named 'PassShow_wd' (runs daily at 4:34 PM).
5 Scheduled Tasks (Boot/Login)
- PsUP..exe is automatically launched at startup through a scheduled task named PassShow Update.
- PassShow_wd.exe is automatically launched at startup through a scheduled task named PassShow_wd.
- PsUPeg.exe is automatically launched at startup through a scheduled task named PassShow Update.
- PsUP.exe is automatically launched at startup through a scheduled task named PassShow Update.
- PassShowwd.exe is automatically launched at startup through a scheduled task named PassShow_wd.
3 Services
- PassShow158.exe runs as a service named 'PassShow' (PassShow).
- PassShow157.exe runs as a service named 'PassShow' (PassShow).
- PassShow155.exe runs as a service named 'PassShow' (PassShow).
How do I remove PassShow?
You can uninstall PassShow from your computer by using the Add/Remove Program feature in the Window's Control Panel.
- On the Start menu (for Windows 8, right-click the screen's bottom-left corner), click Control Panel, and then, under Programs, do one of the following:
- Windows Vista/7/8/10: Click Uninstall a Program.
- Windows XP: Click Add or Remove Programs.
- When you find the program PassShow, click it, and then do one of the following:
- Windows Vista/7/8/10: Click Uninstall.
- Windows XP: Click the Remove or Change/Remove tab (to the right of the program).
- Follow the prompts. A progress bar shows you how long it will take to remove PassShow.
- If for some reason uninstallation fails, please install Microsoft's uninstall fixer utility which will help fix problems with programs that can't be uninstalled at support.microsoft.com.
How do I reset my web browser?
If your web browser homepage and search settings have been modfied by PassShow you can restore them to their previous default settings.
Microsoft Internet Explorer
- Open Internet Explorer and click the Tools button, and then click Internet options.
- Click the Advanced tab, and then click Reset. Select the Delete personal settings check box if you would also like to remove search providers, Accelerators and home pages. When Internet Explorer finishes applying default settings, click Close, and then click OK.
- The changes will take effect the next time you open IE.
Mozilla Firefox
- At the top of the Firefox window, click the Firefox button, go over to the Help sub-menu and select Troubleshooting Information.
- To continue, click Reset Firefox in the confirmation window that opens. It will close and be reset.
- When it's done, a window will list the information that was imported. Click Finish and Firefox will open.
Google Chrome
- Open Chrome and click the Chrome menu on the browser toolbar.
- Select Settings. In the "Search" section, click Manage search engine. Check if (Default) is displayed next to your preferred search engine. If not, mouse over it and click Make default. Mouse over any other suspicious search engine entries that are not familiar and click X to remove them.
- When the "Show Home button" checkbox is selected, a web address appears below it. If you want the Homepage button to open up a different webpage, click Change to enter a link.
- Restart Google Chrome.
HOW IT RUNS
Windows Service? Yes
(Installs a service)
|
|
USER ACTIONS
|
Uninstall it 88%
Keep it 12%
|
|
|
GLOBAL RANK
#6,049
|
Windows
Which Windows OS versions does it run on?
Windows 7 |
58.42% |
|
Windows 10 |
29.97% |
|
Windows Vista |
6.10% |
|
Windows XP |
5.50% |
|
Which OS releases does it run on? |
Windows 7 Home Premium |
36.25% |
|
Windows 8.1 |
14.22% |
|
Windows 7 Professional |
10.15% |
|
Windows 7 Ultimate |
8.48% |
|
Windows 8 |
7.74% |
|
Microsoft Windows XP |
5.47% |
|
Geography
67.67% of installs come from the United States
Which countries install it?
United States |
67.67% |
United Kingdom |
5.50% |
Canada |
4.23% |
Australia |
3.63% |
Saudi Arabia |
2.86% |
Germany |
1.54% |
Italy |
1.54% |
United Arab Emirates |
1.37% |
IQ |
1.37% |
Netherlands |
1.21% |
Belgium |
0.82% |
Sweden |
0.82% |
France |
0.77% |
South Africa |
0.71% |
PC manufacturers
What PC manufacturers (OEMs) have it installed?
Hewlett-Packard |
30.43% |
|
Dell |
25.78% |
|
Acer |
13.18% |
|
ASUS |
8.44% |
|
Toshiba |
7.68% |
|
Samsung |
4.55% |
|
GIGABYTE |
4.08% |
|
Lenovo |
3.60% |
|
Intel |
1.61% |
|
Alienware |
0.66% |
|
Common models |
HP Pavilion dv6 Notebook ... |
5.94% |
|
HP Pavilion g6 Notebook P... |
5.23% |
|
HP 2000 Notebook PC |
3.56% |
|
HP Pavilion g7 Notebook P... |
3.56% |
|
Dell Inspiron N5110 |
3.09% |
|
Dell Inspiron 3521 |
2.61% |
|