AdwCleaner bad VirusTotal result 4/55

Page 1 of 3 123 LastLast

  1. Posts : 1,002
    XP Pro (x86) | 7 HP (x86) & (x64) | 7 Pro (x64)
       #1

    AdwCleaner bad VirusTotal result 4/55


    AdwCleaner has been recommended from several quarters.

    I have downloaded "adwcleaner_3.308.exe" from the author ...
    https://toolslib.net/downloads/viewd.../1-adwcleaner/

    But scans by VirusTotal and Metascan return negative results

    VirusTotal
    - fresh scan 31-Aug-2014
    https://www.virustotal.com/en/file/f...80b1/analysis/
    - found FOUR threats
    - 55 scan engines
    1. CMC | Trojan.Win32.Generic!O
    2. Cyren | W32/GenBl.9DED4724!Olympus
    3. Kingsoft | VIRUS_UNKNOWN
    4. Symantec | Trojan.Gen.SMH

    Metascan
    - historical scan 28-Aug-2014
    https://www.metascan-online.com/en/s...22572979e4b875
    - found ONE threat
    - 40 scan engines
    1. Filseclab | Trojan.Pirminay.aakt.xzed

    I find it so frustrating to find a recommendation (even on sevenforums.com) only to be confronted with added crapware.

    What gets me going is AdwCleaner is full of the crap that it boasts about detecting and removing

    OpenCandy is not alone as sneakware. Babylon(fs) does not like being uninstalled.

    Any ideas where I might find a clean adware detector and removal tool. Malwarebytes does not view "OpenCandy" as malware.

    Thank you
      My Computer


  2. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #2

    GrayGhost2 said:
    Malwarebytes does not view "OpenCandy" as malware.
    For me Malwarebytes (Ver 2) does detect and quarantine "OpenCandy".
    In Settings / Detection and Protection, set PUP protection to "Treat detections as malware".
      My Computer


  3. Posts : 1,102
    OEM Windows 7 Ult (x64) SP1
       #3

    Hi:

    To add to DavidW7ncus's excellent advice about MBAM...

    I suspect that the problem is not with AdwCleaner, but with the AV vendors who for many reasons (marketing/financial/etc) choose not to recognize many legitimate malware-removal tools from other sources. Essentially, the detection at VT would be considered a "False Positive".

    AdwCleaner is used thousands of times a day at many computer disinfection forums.
    And it is hosted at bleepingcomputer.com, which AFAIK, only hosts downloads that are "malware-free":
    AdwCleaner Download

    It sounds to me as if you might already be infected -- at least with PUPs/adware/junkware?
    You might want to get some free, expert cleanup help, either here or at another computer disinfection forum?

    <just a thought>

    Cheers,
      My Computer


  4. Posts : 1,049
    Windows 7 Pro 32
       #4

    A tip: Always check on herdProtect too because they say they're good at detecting false positives!

    Clean 0/68
    A number of engines detected this file but were erroneous detections (false positives).
    Malware scan of adwcleaner_3.308.exe 2b9afd04d0325d2cbaa3e3bf16a59b63e2ee35e1 - herdProtect
      My Computer


  5. Posts : 163
    Win7 64-bit, Vista 32-bit, XP 32-bit, W2K 32-bit (VM)
       #5

    @ GrayGhost2,

    I just downloaded AdwCleaner from here, both BC's and the authors site and both files offered were executables that downloaded straight to my desktop. You do not have to go through the install process which is where most of your crapware comes from during installation.

    AdwCleaner is a "portable software", and some AV software may detect malware removal tools.

    There is no crapware included in the executable downloads. Those are false positives and the AV databases need to be updated to prevent this.
      My Computer


  6. mjf
    Posts : 5,969
    Windows 7x64 Home Premium SP1
       #6

    The site
    AdwCleaner Download
    (CAUTION)
    has been given as a download site previously.
    and Norton quarantines it reporting Trojan "Trojan.Gen.SMH"

    so I'd agree with GrayGhost2 and don't think it should be recommended at this stage.
      My Computer


  7. Posts : 17,322
    Win 10 Pro x64
       #7

    mjf said:
    The site
    AdwCleaner Download
    (CAUTION)
    has been given as a download site previously.
    and Norton quarantines it reporting Trojan "Trojan.Gen.SMH"

    so I'd agree with GrayGhost2 and don't think it should be recommended at this stage.
    I doubt bleepingcomputer has any malicious content, it is a security based site.

    I think we are dealing with a false positive, probably based on what it takes for Adwcleaner to do it's job.

    Here's Norton's view on the site itself,

    https://safeweb.norton.com/report/sh...omputer.com%2F
      My Computer


  8. mjf
    Posts : 5,969
    Windows 7x64 Home Premium SP1
       #8

    Yes Norton does consider the site secure. I could imagine it is possible to be false positives (by a number of anti virus software). Still, there is a dilemma in deciding to use it given that it is just an additional safety check.
    Check a risk with a risk?
      My Computer


  9. Posts : 25,847
    Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
       #9

    It not a dilemma to me.

    I use the Bleeping Computer site because I trust them.

    I just downloaded it and scanned it with Malwarebytes, Super Anti Spyware, and Microsoft Security Essentials.
    No problems found.

    I do not use the authors site.
    I can't read that site and the last time I ended up with a bunch of trash.

    I have used Eset online scanner several times in the past when AdwCleaner was installed and it never flagged it.

    Like many sites have reported about fake anti virus, and Malwarebytes programs their is a good chance that their are fake AdwCleaner also.

    Seem like when a product works and becomes popular someone makes a fake.
      My Computer


  10. Posts : 17,322
    Win 10 Pro x64
       #10

    Here is the authors site,

    https://toolslib.net/downloads/viewd.../1-adwcleaner/

    Interesting to note, the last commenter says the same thing you did about Norton flagging it.

    I just tried to report this to Norton as a possible false positive but they want something from a log or clipboard and I don't have Norton.

    Would you mind submitting it Michael?

    https://submit.symantec.com/false_positive/standard/
      My Computer


 
Page 1 of 3 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 05:10.
Find Us