item found in Malwarebytes (from udemy.com?)

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 1,102
    OEM Windows 7 Ult (x64) SP1
       #11

    Thanks for the updates.

    I mean no disrespect, but I think we might be veering a bit off-topic?

    @Havoc originally reported the same PUP file detection on both MBAM and AdwCleaner scans.
    As I mentioned, a VT scan of the file may or may not be entirely insightful, as some of the VT scanners do not target PUPs.
    In order to determine if that PUP detection may or may not be a F/P for those 2 scanners, MBAM and AdwCleaner, one would need to follow the steps I already suggested to submit at least an MBAM scan log (or, preferably, the zipped file itself) in the F/P forum section at Malwarebytes forum.
    (There is a similar process for AdwCleaner HERE.)

    AFAIK, @Havoc reported a file detection, NOT an IP/website block, from MBAM for udemy.com.
    There's no harm submitting that URL to VT or another site for analysis, of course.
    But even if the site scans clean at VT, there still might be PUPs associated with the software available at that site. Checking the site, rather than the software itself, will yield different results.
    If the vendor bundles their software with PUPs, then the site may well be clean, even if the software is not.

    If, in fact, it is a legitimate PUP detection, and if it is being regenerated from your sync'd Chrome data, then getting rid of it will likely entail the steps I already mentioned. If it's coming from something on your system, then a bit of junkware/adware/malware cleanup may be needed.

    In order to reduce the guesswork and to have a bit of real data with which to work, @Havoc, perhaps you might please ATTACH to your next reply here in this thread both the MBAM scan log and the AdwCleaner scan logs. (Let us know if you need help finding and exporting those logs.)

    Just a suggestion,
    MM
    Last edited by MoxieMomma; 05 Jun 2016 at 14:04. Reason: typo
      My Computer


  2. Posts : 6,330
    Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
       #12

    I was just replying to "I thought it was related to udemy because of the ability to comment on videos that you watch"
    so the OP knows a URL can be scanned at VT.

    I'll drop off and watch.
      My Computer


  3. Posts : 1,442
    Windows 7 Professional 64bit
    Thread Starter
       #13

    I followed the directions in post #4 for resetting Chrome. I'm going to do some more browsing with Chrome tonight and see if the PUP returns. I'm able to find the logs and upload them if need be.

    I ran a full scan with MSE, and a scan with Malwarebytes and AdwCleaner, all three found nothing so far.
      My Computer


  4. Posts : 1,102
    OEM Windows 7 Ult (x64) SP1
       #14

    Hi, @Havoc:

    OK, sounds good.
    If it returns, seeing some scan logs and a bit of deeper digging may be needed.

    Cheers,
    MM

    {P.S. @DavidE: no offense intended. VT suggestions were excellent. Was just trying to keep the thread on-topic re: PUP file detection in MBAM and AdwCleaner scans, the most definitive means of ruling out a possible F/P, and likely explanations for the reappearance of the detection in multiple scans.}
      My Computer


  5. Posts : 1,442
    Windows 7 Professional 64bit
    Thread Starter
       #15

    I ran Malwarebytes and it isn't finding anything. I ran AdwCleaner and it found a couple items related to google.
    Attached Thumbnails Attached Thumbnails item found in Malwarebytes (from udemy.com?)-chatango.png   item found in Malwarebytes (from udemy.com?)-aol-ask.png  
      My Computer


  6. Posts : 1,102
    OEM Windows 7 Ult (x64) SP1
       #16

    Hi, @Havoc:

    I lack the official training to guide you through malware removal. That is best left to someone with more formal expertise in the matter. And I do not personally use Chrome, so I lack first-hand knowledge of the program.

    Unless you disabled Chrome sync before you reset it, you may be getting reinfected.

    However, the AdwCleaner detections you show seem to be different from the one originally reported in your original post about the PUP in MBAM. And AdwCleaner can have false positives.
    But it's hard to say for sure what is going on without seeing the LOGS, rather than a screenshot snippet.

    Until someone more expert comes along here at sevenforums, I suggest the following:

    • You may wish to report the AdwCleaner findings HERE. They will help you to determine if the AdwCleaner detections might be a false positive -- if they are not, they will direct you to the proper sub-forum for some guided malware cleanup.
    • Or, you may wish to post directly in one of several, reputable, dedicated computer disinfection fora (G2G, bleepingcomputer, Malwarebytes, etc.) and likewise get some guided help with cleanup. The expert help there is free. They will walk you through the proper scans in the correct sequence in order to find and remove malware and to help harden your defenses to prevent reinfections.

    Please let us know how it goes, so that we can all learn.


    Thank you,
    MM
      My Computer


  7. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #17

    Hi,
    Yep you did pick up some extra search engines
    They should show up as extensions I believe.
    Also review you're uninstall a program section for the listings.
      My Computer


  8. Posts : 1,442
    Windows 7 Professional 64bit
    Thread Starter
       #18

    Nothing in my add/remove programs for anything shown in the previous post.

    The computer isn't doing anything weird. I just did a scan last Sunday and that's when I saw the items in Malwarebytes, they haven't returned but I found these in AdwCleaner.
      My Computer


  9. Posts : 20,583
    Win-7-Pro64bit 7-H-Prem-64bit
       #19

    Hi,
    Go to Chrome settings and on the left column go to extensions see what is in there.
      My Computer


  10. Posts : 1,442
    Windows 7 Professional 64bit
    Thread Starter
       #20

    Just the default ones that come with Chrome.
    Attached Thumbnails Attached Thumbnails item found in Malwarebytes (from udemy.com?)-extensions.png  
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 23:50.
Find Us