Solved PUP Files Everyday

bigmck

Very Senior Member
Guru
Gold Member
VIP
Local time
3:37 AM
Messages
4,745
Location
Houston, Texas
For the past two weeks or so I have been getting exactly 36 PUP files showing everyday from my Malwarebytes. It just seems strange that I am getting them everyday and the exact same number. I quarantine them and the next day I have 36 more. Does this seem strange to you or do you think I am making a big deal over nothing. Thanks,
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Hi Bigmck,

sounds to me like you installed/updated a program, 2 weeks ago, that has created an auto update or schuduled task (local).
The other possibility is malware via a view or from a new browser toolbar
Ring any bells??

run this, FRST, post the 2 reports i'll give a quick once over


Farbar Recovery Scan Tool Download


Roy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Or, Malwarebytes is fouled up. Ever since V2 came out, each new update has been buggier than a flophouse bed.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
Maybe picking them up again from the quarantine folder.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Dell Precision 15 7550 Workstation
OS
Windows 10 22H2 Pro
CPU
Intel(R) Xeon W-10885M
Motherboard
Dell
Memory
2x 32 GB DDR4 ECC memory (128 GB max)
Graphics Card(s)
Intel onboard GPU 1080p - Quadro RTX 5000 Max-Q GPU 4K
Hard Drives
500 GB Corsair T500 main M2 SSD
1 TB Intel storage M2 SSD (6 TB max)
Mouse
Logitech MX-25 Bluetooth
Internet Speed
slow
Antivirus
MS
Browser
Pale Moon 33.3.x x64 AVX2 build
Get Super Anti-Spyware (FREE) and run it. It will find and REMOVE PUPs. I don't like programs that Quarantine things. That leaves them on the HD..... I want them GONE!

I don't trust Malware Bytes for a lot. It's NOT an anti-virus program, regardless that some folks think it is. So if that's the only program you're using, you're in deep S**t!

I like Super Anti-Spyware so much that I got up off of my CC and bought it. And I don't BUY very much software. Now it updates and scans, daily, automatically.

So you get a few PUPs, Eh? How many Tracking Cookies are you getting per day? Do you know? Do you care? Well, Malware Bytes won't tell you, because it don't even look for them. S.A.S. Does!

Good Luck and Happy Computing!
TechnoMage :cool:
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Various
OS
Win 7 Pro, SP1, x86, Win-11/Pro/64
CPU
AMD
Motherboard
Various
Memory
8GB Crucial
Graphics Card(s)
Various
Sound Card
OnBoard
Monitor(s) Displays
Acer 21.5"
Hard Drives
Crucial SSD, 500 GB
PSU
OEM
Case
SFF Slim Line Case
Cooling
OEM
Keyboard
eMachines
Mouse
Logitech Wireless
Internet Speed
varies
Antivirus
Windows Defender/Super Anti-Spyware
Browser
Firefox
Get Super Anti-Spyware (FREE) and run it. It will find and REMOVE PUPs. I don't like programs that Quarantine things. That leaves them on the HD..... I want them GONE!...

Actually, putting something suspicious into quarantine is better than merely nuking it out right. First, whatever gets put into quarantine is rendered harmless and unable to function so you computer is safe from it. Second, antimalware programs are often overzealous in determining what they consider to be harmful; Malwarebytes 3 is notorious for that. If the antimalware program just nuked it, you would have to replace it if it turned out to be a false positive. With it being put in quarantine, you get a choice of telling the antimalware program that the file in quarantine is harmless and to put it back where it belongs and to leave it there (make an exception) or to nuke it to computer never never land.

Malwarebytes 3 is still a good program worth having, even though it's been buggier than a flophouse bed at times since v2 came out. It claims to be able to replace your Antivirus (AV) program but you can still run an AV with it, which I recommend. It does tend to be overzealous, which is a nuisance, but you can set it to allow files you know to be safe. The current bugs sometimes cause to be off after a reboot (the temporary fix is to exit Malwarebytes, then restart it; the permanent fix is to use the Malwarebytes removal tool to uninstall it, then do a clean install) and to use and excessive amount of CPU capacity when running a full scan that includes scanning for rootkits (I'm still using an earlier version that doesn't have that problem).
bigmck TechoMage2016 gave excellent advice on SuperAntiSpyware (SAS). As torchwood danced around, there may be an advertising cookie (or few) that are restoring the PUPs to your computer. The free version of SAS will do an excellent job of finding and removing those cookies, as well as known tracking cookies (even though Malwarebytes 3 will catch many of them, SAS does a better job). The free version has to be manually updated and run whereas the paid version will do that automatically. Otherwise, there is no difference between them.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
Hi Bigmck,

sounds to me like you installed/updated a program, 2 weeks ago, that has created an auto update or schuduled task (local).
The other possibility is malware via a view or from a new browser toolbar
Ring any bells??

run this, FRST, post the 2 reports i'll give a quick once over


Farbar Recovery Scan Tool Download


Roy

Thanks very much Roy.
 

Attachments

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Get Super Anti-Spyware (FREE) and run it. It will find and REMOVE PUPs. I don't like programs that Quarantine things. That leaves them on the HD..... I want them GONE!

I don't trust Malware Bytes for a lot. It's NOT an anti-virus program, regardless that some folks think it is. So if that's the only program you're using, you're in deep S**t!

I like Super Anti-Spyware so much that I got up off of my CC and bought it. And I don't BUY very much software. Now it updates and scans, daily, automatically.

So you get a few PUPs, Eh? How many Tracking Cookies are you getting per day? Do you know? Do you care? Well, Malware Bytes won't tell you, because it don't even look for them. S.A.S. Does!

Good Luck and Happy Computing!
TechnoMage :cool:

I also run MS Security Essentials as my anti-virus. == "So you get a few PUPs, Eh? How many Tracking Cookies are you getting per day? Do you know? Do you care?" SIGH
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
bigmck TechoMage2016 gave excellent advice on SuperAntiSpyware (SAS). As torchwood danced around, there may be an advertising cookie (or few) that are restoring the PUPs to your computer. The free version of SAS will do an excellent job of finding and removing those cookies, as well as known tracking cookies (even though Malwarebytes 3 will catch many of them, SAS does a better job). The free version has to be manually updated and run whereas the paid version will do that automatically. Otherwise, there is no difference between them.

Thanks very much.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Lady Fitz -- I thank you for the Malwarebytes heads up. Yeah, I had version 3 and I have been getting some goofy things lately now that I think about it. I just uninstalled it and am trying Super Spyware or what ever you called it. I will see how it works. Thanks,
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Lady Fitz -- I thank you for the Malwarebytes heads up. Yeah, I had version 3 and I have been getting some goofy things lately now that I think about it. I just uninstalled it and am trying Super Spyware or what ever you called it. I will see how it works. Thanks,

SuperAntiSpyware (SAS) and Malwarebytes 3 (MB3) do two completely things. I use both: the free version of SAS and the paid version of MB3 (I have four grandfathered lifetime licenses).

SAS looks for and removes cookies that either track your usage or inject advertising into your computer. MB3 looks for pretty much all other kinds of malware. MB3 does its job well but has some problems, most which can be fixed, although it's a pain in the neck to have to keep doing so with each new version. It's worthwhile to use MB3's user forum to keep track of the problems and fixes. I also recommend using MB3 with an antivirus even though MB3 claims you don't need one; MB3 also claims you can do so. I'm using Avast free with most of the extra features turned off with MB3.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
SuperAntiSpyware (SAS) and Malwarebytes 3 (MB3) do two completely things. I use both: the free version of SAS and the paid version of MB3 (I have four grandfathered lifetime licenses).

SAS looks for and removes cookies that either track your usage or inject advertising into your computer. MB3 looks for pretty much all other kinds of malware. MB3 does its job well but has some problems, most which can be fixed, although it's a pain in the neck to have to keep doing so with each new version. It's worthwhile to use MB3's user forum to keep track of the problems and fixes. I also recommend using MB3 with an antivirus even though MB3 claims you don't need one; MB3 also claims you can do so. I'm using Avast free with most of the extra features turned off with MB3.

I was under the impression that SuperAnti was an alternative to Malwarebytes, thanks for the heads up. I use MS Security Essentials for my AV. I like MalBytes but I get too many strange things. I have gone back to MalBytes V 2.2 What did you disable in V 3 that satisfied you?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
I was under the impression that SuperAnti was an alternative to Malwarebytes, thanks for the heads up. I use MS Security Essentials for my AV. I like MalBytes but I get too many strange things. I have gone back to MalBytes V 2.2 What did you disable in V 3 that satisfied you?

I just went back to an earlier update of v3.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
Hi bigmck,

nothing really sticking out as malware
Allthough there is a google policy restriction.
Im not a malware expert but i'll ask DonnaB to cast here expert eyes over it.
There are a couple weird files
the program compatabilty program is referencing Yahoo
and some odd data in your appdata temp files, Quarentine for one.


Both MBAM and MSE are having trouble connecting via your host files.


Roy
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
medionl/Aspire 6930G/acer x55a
OS
W7 home premium 32bit/W7HP 64bit/w10 tp insider ring
CPU
E5300 dual core
Motherboard
medion MS7366
Memory
3gb
Graphics Card(s)
Nvidia Geforce 7100 Nforce 630i
Monitor(s) Displays
avixc
Internet Speed
n (isp resticted to 72)
Antivirus
mse/pands
Browser
palemoon
Other Info
Belkin Fd7050 n USB using Railink RT2870 drivers, more upto date
Thanks for looking at the files Roy.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Hi everybody,

For the record, if I am not mistaken, MBAM3 is not an AV unless you have the paid version like Lady Fitzgerald has, otherwise it does not run in realtime and is only a second hand scanner that must be executed manually. The paid version is supposed to play well along side any other AV as a second layer of realtime protection.

I think I read that you uninstalled Malwarebytes? If not, please attach the logs so we can see the 36 PUP's that it has been finding.

bigmck? Did you download WeatherBug intentionally?
Task: {06F75BBE-8156-4B85-9EA0-97DDC91475B4} - System32\Tasks\{B6FFA501-E300-4C95-BC8D-3971D890F9EE} => C:\Windows\system32\pcalua.exe -a C:\Users\Jim\Desktop\WeatherBugSetup.exe -d C:\Users\Jim\Desktop
Task: {45E5D37F-0334-441E-853B-19014301465C} - System32\Tasks\{CC802FEB-6364-45B2-A2E9-B26FEAAE3700} => C:\Windows\system32\pcalua.exe -a D:\Downloads\WeatherBugSetup.exe -d D:\Downloads
WeatherBug is and ad serving software that is considered PUP/Adware because it is usually bundled along with legit software that is downloaded and can generate pop-up advertisements in the browser it attaches to. Back in the day SuperAntiSpyware used to target it as a threat, or was that Spyware Blaster. Sorry, my memory fails me since it has been quite some time since I uninstalled it.

The following two programs are severely outdated. Older versions of software have vulnerabilities that malware can use to infect your system. Now a days, your typical home computer user doesn't need Java installed, which at one time was desperately needed for websites to be displayed properly. That is no longer the case. I had uninstalled Java a few years ago and have since found no need for it, so the choice is yours if you would like to reinstall or not. If the need ever arises, you will be notified that Java is needed at which time you could install, or you could reinstall and just disable Java till the moment arises that it is needed.

Java 7 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.250 - Oracle)
Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)

If you decide that you do need Java, you can dowload the most recent version from here.

As for the Hosts file. Found the following in the FRST log:

Hosts: Hosts file not detected in the default directory

Any idea what might have happened to it? We'll do a search of the default location to see what's up. I am sure it will not be found but still want to see.

There are a few orphaned files etc that can be removed and we're going to empty those temp files. Please do as follows:


  • Open notepad (Start orb > type notepad into Start Search > chose notepad from list.
  • Please copy the entire contents of the code box below.
    (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
  • Save it to the same directory as frst.exe (or frst64.exe) as fixlist.txt.

    CreateRestorePoint:
    CloseProcesses:
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
    Toolbar: HKU\S-1-5-21-2284772-1736933989-2242282106-1000 -> No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File
    CHR HKLM\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
    S2 OutfoxTvService; C:\Program Files\OutfoxTV\OutfoxTvService.exe [X]
    S3 ALSysIO; \??\C:\Users\Jim\AppData\Local\Temp\ALSysIO.sys [X]
    S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
    S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
    S3 RTL8192su; system32\DRIVERS\RTL8192su.sys [X]
    CustomCLSID: HKU\S-1-5-21-2284772-1736933989-2242282106-1000_Classes\CLSID\{48AC0584-909B-42D6-BD5F-83124C096669}\InprocServer32 -> no filepath
    Folder: C:\WINDOWS\system32\drivers\etc
    EmptyTemp:
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
  • Run frst.exe (on 64bit, run frst64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you will find where you saved FRST. Please attach it to your reply. DO NOT paste into reply box. It might be too long.
 

My Computer

Computer type
Laptop
OS
Win7 64-bit, Vista 32-bit, XP 32-bit, W2K 32-bit (VM)
Antivirus
Avast, MSE
Browser
Firefox
Other Info
Multiple systems. Too many specs to name.
Hi everybody,

For the record, if I am not mistaken, MBAM3 is not an AV unless you have the paid version like Lady Fitzgerald has, otherwise it does not run in realtime and is only a second hand scanner that must be executed manually. The paid version is supposed to play well along side any other AV as a second layer of realtime protection...

True that. I should have been more clear about that.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
True that. I should have been more clear about that.

Yes, I am aware that MByte is not an AV. I run MSE for my AV. == I also have the Paid Version of MByte. Since I uninstalled MByte 3 and installed MByte 2 I don't get the Pup but I feel like it is not a good idea to run Version 2. I could be getting all kind of stuff. When I install a new program, which I haven't recently, I always look to see if anything is being added in addition to the program. == Lady Fitz, what do you disable in MByte 3 that works for you?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
...Lady Fitz, what do you disable in MByte 3 that works for you?

I installed an earlier version of Malwarebytes 3.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Win 7 Ultimate 64 bit
CPU
Intel i7-3930K
Motherboard
ASUS P9X79 WS
Memory
Kingston HyperX Genesis 32GB Kit (8x4GB Modules) 1600MHz DDR
Graphics Card(s)
MSI R7850 Twin Frozr 2GD5/OC Radeon HD 7850 2GB 256-bit GDDR
Sound Card
Asus Xonar Essence STX
Monitor(s) Displays
3x Asus VG248QE 24", Vizio 32" TV
Screen Resolution
1920 x 1080, ?
Hard Drives
Samsung 128GB 840 Pro SSD (1),
Samsung 4TB 850 EVO SSDs (4)
Samsung 4TB 850 EVO SSDs (16) external backup drives used in 2.5" hot swap bays in the computer.
PSU
Corsair HX750w
Case
Antec Two Hundred v2 (modified)
Cooling
Cooler Master GeminII S524 120mm (fan replaced with a 140mm)
Keyboard
Logitech G510s
Mouse
Logitech M525 (two in use)
Internet Speed
=< 32Mbps down, 8Mbps up
Antivirus
AVAST!, MBAM, SAS, Spybot S&D (all but MBAM free) Glary Util
Browser
IE11
Other Info
LSI 9211-8i HBA card (8 SATA III ports), 2.5" & 3.5" Hot Swap Bays, HooToo HT-CR001 PCI-E to USB 3.0 Internal Hub + 6 Slot Card Reader, and LG Model CH12LS28 BD-ROM Optical Drive. Also, ScanSnap S1500 ADF duplexing scanner, Canon 9000F flat bed scanner, Corsair SP2500 2.1 speakers, Samsung CLP 415nw laser color printer, Cyberpower PP2200SW UPS
@ bigmck

Take a look in msconfig Startup and Non Microsoft Services.

You might have a program in one of those that is doing a 'auto' update that is loading those PuP's.

I have the paid for version of Malwarebyte and MSE and have no problems on two systems.

I also use the stand alone free online scan with Eset. It's the only thing I have found that finds and removes the Google toolbar bundle.

Jack
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top