Help with Panda Cloud Cleaner scan results

Page 1 of 2 12 LastLast

  1. Posts : 48
    Windows 7 Home Premium 64 bit
       #1

    Help with Panda Cloud Cleaner scan results


    I recently installed Panda Free Antivirus. When it was offered, I ran the Panda Cloud Cleaner and it found a few items. I was surprised as I had just scanned with the Panda Free, Eset Online, Malwarebytes and Comodo Cleaning Essentials and they found no threats. I posted the log on the Panda Forums, but they do not seem to be very active.

    Here is the log:

    FILE: C:\PROGRAMDATA\INSTALLMATE\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}\SETUP.EXE to be deleted..

    FILE: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol\Uninstall WinPatrol.lnk to be deleted.Suspicious Policy.

    POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[SHOWSUPERHIDDEN] to be changed to: 0Suspicious Policy.

    POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[SHOWSUPERHIDDEN] to be changed to: 0Suspicious Policy.

    POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[SUPERHIDDEN] to be changed to: 0Suspicious Policy.

    POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[SUPERHIDDEN] to be changed to: 0.

    REGKEY: HKLM\SOFTWARE\SPYWARE TERMINATOR. Key to be deleted.Malware.

    REGKEY: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER[NOFOLDEROPTIONS]. Value: NOFOLDEROPTIONS To be deleted.Malware.

    REGKEY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER[NOFOLDEROPTIONS]. Value: NOFOLDEROPTIONS To be deleted.Malware.

    REGKEY: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM[DISABLEREGISTRYTOOLS]. Value: DISABLEREGISTRYTOOLS To be deleted.Malware.

    REGKEY: HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM[DISABLETASKMGR]. Value: DISABLETASKMGR To be deleted.Malware.

    REGKEY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM[DISABLEREGISTRYTOOLS]. Value: DISABLEREGISTRYTOOLS To be deleted.Malware.

    REGKEY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM[DISABLETASKMGR]. Value: DISABLETASKMGR To be deleted..

    FOLDER: C:\PROGRAMDATA\SPYWARE TERMINATOR to be deleted

    Can any of you tell me if these are things I should be concerned about? I did not have the Cloud Cleaner clean them at the conclusion of the scan.
      My Computer


  2. Posts : 1,810
    Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
       #2

    You can go ahead and remove that. Panda will remove what is bad and reset what needs to be reset in your registry. I would perform a more thorough clean.

    In addition to what is already run, try the following:
    Make sure you run Malwarebytes with a custom, FULL scan. Checking the box for RootKits.
    Malwarebytes Anti-Malware Free

    Run AdwCleaner: AdwCleaner Download
    Run Superantispyware (link will start download instantly): SUPERAntiSpyware - Downloading File

    Run those programs and post the results here. You can simply attach the log file created after these finish.
      My Computer


  3. Posts : 48
    Windows 7 Home Premium 64 bit
    Thread Starter
       #3

    Sorry for the delay in getting back to you. I forgot this forum does not notify you of replies as they are received.

    I ran the Panda Cloud Cleaner again and allowed it to clean the items that it selected.

    The Malwarebytes scan was a custom scan of the C drive with the scan for rootkits checked. It took a bit longer than I anticipated.

    I ran AdwCleaner yesterday and it found 1 item. I cleaned it. However, after the reboot I had several hidden files showing on my desktop, as well as all drives appeared in the computer folder in Windows Explorer. I did a system restore, but still had to go into folder options to hide the files and get rid of the drive letters. The AdwCleaner scan done at your request shows the same item. I did not clean it.

    Attached are the logs you requested. I can provide a more detailed version of the Malwarebytes scan if you would like.
    Help with Panda Cloud Cleaner scan results Attached Files
      My Computer


  4. Posts : 1,810
    Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
       #4

    tjs999 said:
    Sorry for the delay in getting back to you. I forgot this forum does not notify you of replies as they are received.

    I ran the Panda Cloud Cleaner again and allowed it to clean the items that it selected.

    The Malwarebytes scan was a custom scan of the C drive with the scan for rootkits checked. It took a bit longer than I anticipated.

    I ran AdwCleaner yesterday and it found 1 item. I cleaned it. However, after the reboot I had several hidden files showing on my desktop, as well as all drives appeared in the computer folder in Windows Explorer. I did a system restore, but still had to go into folder options to hide the files and get rid of the drive letters. The AdwCleaner scan done at your request shows the same item. I did not clean it.

    Attached are the logs you requested. I can provide a more detailed version of the Malwarebytes scan if you would like.
    Everything looks good. Can you explain your other problem a little more? I've never had any experience with Adwcleaner making hidden files on the desktop. Can you upload a picture of it?

    Use the snipping tool
    How to Use the Snipping Tool in Vista
    Then post it here in your next post
    Screenshots and Files - Upload and Post in Seven Forums

    Now lets make sure whatever you had previously is completely removed.
    Download Autoruns from here:
    Autoruns for Windows

    Unzip the folder > Extract autoruns.exe to the desktop > Right-click > Run as administrator

    Delete all entries that are yellow. If you have red entries, please post the name of them in your next post
      My Computer


  5. Posts : 48
    Windows 7 Home Premium 64 bit
    Thread Starter
       #5

    There are entries that are more a pink color than red. Are these the ones you want the names of or am I looking for a bright red color?
      My Computer


  6. Posts : 1,810
    Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
       #6

    tjs999 said:
    There are entries that are more a pink color than red. Are these the ones you want the names of or am I looking for a bright red color?
    Yes sorry, pinkish red. Shouldn't be very many.
      My Computer


  7. Posts : 48
    Windows 7 Home Premium 64 bit
    Thread Starter
       #7

    I ran AdwCleaner again and found the same item. This time I had AdwCleaner clean it. When the re-boot was completed there were no hidden files on the desktop and only the installed drives were listed.

    Attached is the log of red/pink autorun entries. I counted 24.

    What did I have that you fixed?
    Help with Panda Cloud Cleaner scan results Attached Files
      My Computer


  8. Posts : 1,810
    Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
       #8

    OK everything looks good. You have a lot more unverified (what pink-red means) files than normal but they are all ok.

    Do you have any other problems?
      My Computer


  9. Posts : 48
    Windows 7 Home Premium 64 bit
    Thread Starter
       #9

    Not a problem, but I was wondering if some of the pink-red entries could be deleted? I use the 7Zip, mp3 tag and Bullzip, but I don't remember using the HP programs. It is probably bloatware that came with the computer. The Canon language entry is probably left over from when I had a Canon printer. I don't know what the Windows sidebar gadget is.

    Did I have malware?
      My Computer


  10. Posts : 1,810
    Dual Boot: Windows 8.1 & Server 2012r2 VMs: Kali Linux, Backbox, Matriux, Windows 8.1
       #10

    tjs999 said:
    Not a problem, but I was wondering if some of the pink-red entries could be deleted? I use the 7Zip, mp3 tag and Bullzip, but I don't remember using the HP programs. It is probably bloatware that came with the computer. The Canon language entry is probably left over from when I had a Canon printer. I don't know what the Windows sidebar gadget is.

    Did I have malware?
    You may have had some type of PUP (Potentially unwanted program) that may have changed some settings but I didn't see any malware.

    As far as those entries in Autoruns, they are harmless and you could possibly do more harm than good.

    If you really want to get rid of bloatware, make sure you Google the program first and make sure its not essential to Windows.

    If its not, feel free to uninstall it with Revo Uninstaller
    Download Revo Uninstaller Freeware - Free and Full Download - Uninstall software, remove programs, solve uninstall problems

    Make sure you change it to Advanced and delete all files and registry values when asked.

    After you remove the program, then run Autoruns and you can proceed to remove the entry. At this point however, it may have turned Yellow if revo removed the file linked to autoruns.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:21.
Find Us