Bitdefender Adware Removal Tool for PC – BETA

A Guy

Righteous Dude
Guru
VIP
SF Team
Local time
1:17 AM
Messages
33,044
Location
Bay Area
Bitdefender Adware Removal Tool for PC – BETA

Bitdefender Adware Removal Tool for PC – BETA

Test the new Bitdefender Adware Removal Tool for PC – Beta!

Bitdefender Adware Removal Tool for PC is a free app that identifies and removes unwanted apps such as adware, malicious hijacker programs, annoying toolbars and other browser add-ons. Keep the apps you like, get rid of the programs that bug you. The tool will only erase those apps that you wish to be removed. It scans your computer for adware, and produces a list of apps marked for removal.

Adware Remover | Bitdefender Labs

I D/L and ran it. I can't say how good it is as it found nothing as expected. It's fast, and Bitdefender has a good reputation. Probably not much use if you have adware protection. Worth a spin just to see. A Guy
 

My Computer My Computer

Computer type
PC/Desktop
OS
Windows 10 Home x64
CPU
INTEL Core i5-750 Quad-Core 3.37GHz
Motherboard
ASUS P7P55D
Memory
HyperX Fury Black Series 8GB (2 x 4GB) 1866Mhz
Graphics Card(s)
EVGA GeForce GTX 750 Superclocked 1GB 128-Bit GDDR5
Monitor(s) Displays
LG 32MA68HY 32" IPS
Screen Resolution
1920 x 1080
Hard Drives
Samsung 840 Evo 120GB, SEAGATE 500GB Barracuda® 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache
PSU
ANTEC TruePower New TP-550, 80 PLUS, 550W
Case
ANTEC Three Hundred Illusion
Cooling
COOLER MASTER Hyper 212 Plus, 4 x 120mm 1 x 140mm Noctua's
Internet Speed
85 + Mbps
Antivirus
Avast
Browser
Vivaldi
I tried Bitdefender's free AV once; the only problem is that as soon as it detects something, it's gone. Even if its a false positive, or something like a modified dll it's just gone and Windows gets screwed up in some cases. If I had an option for whitelisting some modified dlls I'd love to use BitDefender.

So it's good to see we get some choice in the matter with this app. Might give it a spin.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 Home Premium x64
CPU
Intel Core i5 2500K
Motherboard
MSI MS-7750
Memory
8GB DDR3
Graphics Card(s)
nVidia GeForce GTX650 Ti BOOST
Sound Card
Realtek
Monitor(s) Displays
21' Philips
Screen Resolution
Full HD
Hard Drives
1TB
PSU
500W
BitDefender Adware Removal Tool

I ran BitDefender Adware Removal Tool (Beta) too. It ran without issues but didn't detect anything. Personally I'll use anything that might pick up infections that were missed by other scanners!

Currently running my first scan with:

9-Lab Removal Tool Beta - not recommended for novice users.

This might be another one to keep an eye on.

Edit: Scan completed and 9-Lab Removal Tool seems to suffer from an unusually high number of false positive detections! Maybe they'll get things sorted eventually.

9-lab Removal Tool 1.0.0.25 BETA.jpg
 
Last edited:

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
False positive detections

Okay - it seems to be flagging up anything with 1-5 detections on VirusTotal - usually little known or used files that get a clean bill of health from the major AV's.

Example detection:

9-Lab:

9-lab Removal Tool Virus Detection.jpg

SigCheck:

SigcheckGUI.jpg

VirusTotal:

VT Results.jpg
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Malwarebytes' will most likely find "wwdc.exe" to be an infection too.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Malwarebytes doesn't flag it, at least not on Virustotal. But as you probably already know AV settings on Virustotal can be different from local settings with the same product (from Virustotal FAQ):

A given antivirus in VirusTotal detects a file and its equivalent commercial version does not

VirusTotal antivirus solutions sometimes are not exactly the same as the public commercial versions. Very often, antivirus companies parametrize their engines specifically for VirusTotal (stronger heuristics, cloud interaction, inclusion of beta signatures, etc.). Therefore, sometimes the antivirus solution in VirusTotal will not behave exactly the same as the equivalent public commercial version of the given product.

It can be a good idea to also check the VT tab "Additional information" and scroll down to Advanced heuristic and reputation engines.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
HP Elitebook 8540p
OS
Windows 7 Pro 32
CPU
Intel(R) Core(TM) i5 CPU M 540 @ 2.53GHz
Motherboard
Hewlett-Packard 1521
Memory
4,00 GB (Usable 2,98)
Graphics Card(s)
NVIDIA NVS 5100M
Sound Card
NVIDIA High Definition Audio
Screen Resolution
1600x900
Hard Drives
INTEL SSDSA2CW120G3
Antivirus
F-Secure Internet Security
Browser
IE, Firefox, Opera
Other Info
Sandboxie,
SRP (Software Restriction Policy),
EMET (Enhanced Mitigation Experience Toolkit),
WFC (Windows Firewall Control by BiniSoft),
Malwarebytes Premium
MBAM Detection

MBAM reports a clean machine.

So does SAS, CIS, Emsisoft Emergency Kit, Trend Micro Anti-Threat Toolkit (ATTK)

9-Lab reports the following (all clean according to MBAM)

Code:
9-lab Removal Tool 1.0.0.25 BETA
9-lab.com

Database version: 89.26159

Windows 7 Service Pack 1 (Version 6.1, Build 7601, 64-bit Edition)
Internet Explorer 9.11.9600.17420

21/11/2014 18:37:10
9lab-log-2014-11-21 (18-37-10).txt

Scan type: 
Objects scanned: 14747
Time Elapsed: 29 m 21 s

Files detected: 12

Malware.MPL.Gen.sm [c:\users\chris\appdata\roaming\SwiftSearch.exe]
Malware.Win32.Gen.3CBD.sm!ff [C:\Users\Chris\Desktop\exewatch.exe]
Malware.Win32.Gen.DA5A.sm!ff [C:\Users\Chris\Desktop\Toolbox\Close To Quit\CloseToQuit.exe]
Malware.Win32.Gen.bot [C:\Users\Chris\Desktop\Toolbox\Driver Signature Override\dseo13b.exe]
Rootkit.Win64.Gen.rc!i [C:\Users\Chris\Desktop\Toolbox\explorer++_1.3.4_x64\Explorer++_original.exe]
Rootkit.Win32.Gen.bot!i [C:\Users\Chris\Desktop\Toolbox\prefetch_parser\parse_prefetch_info_v1.5\parse_prefetch_info.exe]
Rootkit.Win32.Gen.bot!s2 [C:\Users\Chris\Desktop\Toolbox\Windows Worms Doors Cleaner\wwdc.exe]
Mal/Fraud!se-757 [C:\Users\Chris\Desktop\Toolbox\WinHex\setup.exe]
Malware.Win32.Gen.sm!s5 [C:\Users\Chris\Desktop\Toolbox 2\Bat_To_Exe_Converter\Windows (32 bit)\Bat_To_Exe_Converter.exe]
Malware.Win32.Gen.3CBD.sm!ff [C:\Users\Chris\Desktop\Toolbox 2\CtrlMouseWheelZoom\CtrlMouseWheelZoom.exe]
Malware.Win32.Gen.sm!s2 [C:\Users\Chris\Desktop\Toolbox 2\DDS\dds.com]
Malware.Win32.Gen.sm!s1 [C:\Users\Chris\Desktop\Toolbox 2\eicfg_removal_utility\eicfg_remover.exe]

So it's detecting some well known software including:

DDS
eicfg_removal_utility
explorer++

None of these have ever been flagged up by the extensive list of other scanners that I've run!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Back
Top