Windows PC Backup Wizard Setup - good or bad?

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Home Premium 32 bit
I found the culprit, and it's not picked up by most adware/virus cleaners as of yet.

The .exe launcher for this file is located in a folder called PCWDownloader in Program Files / Program Files (x86). Delete the PCWDownloader and PCWUpdated folders, remove references to them in the Registry and remove any scheduled tasks regarding these folders in the Task Scheduler.

As of the time of this post, you have to manually remove this particular pop-up.

Thank you, I haven't been able to get back to the client yet, but when I do I will try out these steps to see if it solves the issue.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Windows 7 Home Premium 32 bit
~~~
Also, the clients Symantec Endpoint Protection definitions were out of date by about 6 months (I had no control over this). When I mentioned this to my boss he said running a scan with up to date definitions wouldn't pick up anything if Malwarebytes didn't pick it up. I'm not sure if I buy that though.
~~~
Your boss is correct. Symantec Endpoint Protection does not even try to keep up with these types of programs.


~~~
There seems to be no way to close this box except by logging out of the user account (it's not in the Task Manager applications list).
~~~
I suggest that you start using Process Explorer and Autoruns for situations like these.

Drag the target from Process Explorer onto the popup window and it should highlight the process that created it. Open the properties for that process and copy the file name of the exe that created the window. Open Autoruns. After it populates, electronically search for the EXE that created the popup. (Ctrl + F and paste in the EXE). In this case, the EXE should show up in the scheduled task section.

You might also be interested in this: http://www.sevenforums.com/tutorial...er-virustotal-check-all-processes-50-avs.html



@shlack123,
Thanks for posting your findings.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
~~~
...there were about 130+ updates that I installed when I was there. Is it possible that the issue could go away after installing the updates? My guess is probably not.


~~~
...I haven't been able to get back to the client yet, but when I do I will try out these steps to see if it solves the issue.

Wow. On-site support. That has got to cost a pretty penny.

You might ask your boss about purchasing some remote control software. TeamViewer is very expensive, but at least you only pay once. There are several other remote control options out there. UltraVNC is free, but requires some work to use it in a secure fashion. i would not use the server mode for unattended remote access.


I wonder what the price of TV will be after today :-)
TV.PNG
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Employer provided Dell Latitude
OS
W7 Pro SP1 64bit
CPU
i7
Memory
8GB
Graphics Card(s)
Intel HD Graphics
Hard Drives
crappy SSD
Antivirus
Employer mandated Symantec Endpoint Protection
Browser
Pale Moon 64bit, IE11 64bit & Chrome 64bit
icloud

I was having the same problem. I back tracked to the last apps I downloaded. I deleted icloud I installed by Apple and I haven't seen the annoyance since.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 Ultimate
To be clear this is not my computer, I am a field technician and it is one of our clients computers. The client did not start receiving this message until a few days ago. It was definitely not installed intentionally.

I have not heard of AdwCleaner before. Do you think running this could pick up something that MalwareBytes may have missed?

Also, the clients Symantec Endpoint Protection definitions were out of date by about 6 months (I had no control over this). When I mentioned this to my boss he said running a scan with up to date definitions wouldn't pick up anything if Malwarebytes didn't pick it up. I'm not sure if I buy that though.

- Vet

And lastly the Windows automatic updates were set to manual (again, I had no control over this) and there were about 130+ updates that I installed when I was there. Is it possible that the issue could go away after installing the updates? My guess is probably not.

Have you looked in the Action Center (in Control Pane)? This should list the AV programs that are active. You may be able to disable it there and then find out where the offending program resides, then uninstall/delete it. CCleaner (Free) may be of help. I also use Revo Uninstaller Pro (not free) and find it very helpful in these cases. Sysinternals Process Explorer may help, but it's primarily for advanced users. Autostart Program Viewer may be of some help too.
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP-Pavilion
OS
Windows 7 Professional 64-bit (6.1, Build 7601)
CPU
AMD Athlon(tm) II X2 215 Processor (2 CPUs), ~2.7GHz
Motherboard
PEGATRON CORPORATION NARRA5, Phoenix - AwardBIOS v6.00PG
Memory
4,094 MB, Page File Size 8,000 MB, L2 Cache Size 1,024 KB
Graphics Card(s)
ATI All-in-Wonder HD, 512 MB RAM, 1920 x 1080 x 4294967296
Sound Card
On-board Realtek High Definition
Monitor(s) Displays
VIZIO 35" Smart HDTV; ATI All-in-Wonder HD card
Screen Resolution
1920 x 1080P x 60 Hz
Hard Drives
WDC WD50 00AAKS-65A7B SCSI 466 GB Disk, TSSTcorp CD/DVDW TS-H653R SCSI CD ROM, Compact 64 GB Flash USB2, MS/MS-Pro USB, SD/MMC USB, SM/xD-USB
PSU
The biggest I could afford.
Case
Midi Tower
Cooling
Fans
Keyboard
HP OEM
Mouse
Logitech Laser
Internet Speed
13 Mb/sec 12 Mb Down x 1 Mb Up
Antivirus
Primary - Nortone 360, Malwarebytes Anti-Malware, and others
Browser
Internet Explorer 11 v9.11.9600.17801
Other Info
Malwarebytes Anti-Rootkit, TDSS rootkit removal tool, Microsoft Windows Malicious Software Removal Tool, Windows Defender, Emsisoft Emergency Kit, CCleaner, Junkware Removal Tool, Auslogics Defrag
Back
Top