SHOP PRODUCTS
Houzz Logo Print
715rose

PupBundleinstall,Bad?

715rose
11 years ago

I put a trial Malwarebytes on my PC.I ran a scan & it found 1 nasty, PupBundleinstall .It was removed.So ran scan next day & there it is again.How nasty is this thing?

rose

Comments (11)

  • zep516
    11 years ago

    1 more scan, Don't delete anything just post the log it creates.
    **********************************************************
    Download AdwCleaner http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/2-adwcleaner
    Link below too for your convenience.

    Double click on AdwCleaner.exe to run the tool.
    ***Note: Windows Vista and Windows 7 users:

    Right click in the adwCleaner.exe and select "run as adminstrator"

    1 Click the Search button.

    2 A logfile will automatically open after the scan has finished.

    3 Please post the content of that logfile in your next reply.

    4 Or you can find the logfile at C:\AdwCleaner[R1].txt.

    Joe

    Here is a link that might be useful: AdwCleaner

  • zep516
    11 years ago

    After you post that log, do this below:

    DDS is a program that will scan your computer and create logs that can be used to display various startup, configuration, and file information from your computer.

    The program will also display information about the computer that will allow us to quickly ascertain whether or not malware may be running on your computer.

    To use DDS, simply download the executable and save it to your desktop or other location on your computer. You should then double-click on the DDS.scr icon to launch the program. DDS will then start to scan your computer and compile the information found into two log files. When DDS has finished it will launch the two Notepad windows that display the contents of these log files. The contents of these log files can then be attached to a reply.

    See link for download

    Here is a link that might be useful: DDS SCAN

  • 715rose
    Original Author
    11 years ago

    Hi Zep
    # AdwCleaner v2.005 - Logfile created 10/21/2012 at 20:50:04
    # Updated 14/10/2012 by Xplode
    # Operating system : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
    # User : User - USER-PC
    # Boot Mode : Normal
    # Running from : C:\Users\User\Downloads\adwcleaner(1).exe
    # Option [Search]

    ***** [Services] *****

    ***** [Files / Folders] *****

    Folder Found : C:\ProgramData\Ask
    Folder Found : C:\ProgramData\Babylon
    Folder Found : C:\ProgramData\InstallMate
    Folder Found : C:\ProgramData\Premium

    ***** [Registry] *****

    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)
    Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)
    Key Found : HKU\S-1-5-21-377911689-2964732372-2432028226-1000\Software\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.19328

    [OK] Registry is clean.

    -\\ Mozilla Firefox v15.0 (en-US)

    -\\ Google Chrome v [Unable to get version]

    *************************

    AdwCleaner[R1].txt - [1255 octets] - [21/10/2012 20:50:04]

    ########## EOF - C:\AdwCleaner[R1].txt - [1315 octets] ##########
    rose

  • zep516
    11 years ago

    Lets get rid of some of the adware.

    Please rescan with AdwCleaner.
    Double-click AdwCleaner.exe to run the tool.
    Click Delete.
    Everything that was found will be deleted.
    Save and open files and approve the reboot. A text file will open after the restart.
    Please post the contents of that logfile with your next reply.

  • 715rose
    Original Author
    11 years ago

    Zep,Here it is.Almost beyond my capabilities

    AdwCleaner v2.005 - Logfile created 10/21/2012 at 21:13:23
    # Updated 14/10/2012 by Xplode
    # Operating system : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)
    # User : User - USER-PC
    # Boot Mode : Normal
    # Running from : C:\Users\User\Downloads\adwcleaner(1).exe
    # Option [Delete]

    ***** [Services] *****

    ***** [Files / Folders] *****

    Deleted on reboot : C:\ProgramData\Ask
    Deleted on reboot : C:\ProgramData\Babylon
    Deleted on reboot : C:\ProgramData\InstallMate
    Deleted on reboot : C:\ProgramData\Premium

    ***** [Registry] *****

    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\(0633EE93-D776-472f-A0FF-E1416B8B2E3A)

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.19328

  • zep516
    11 years ago

    Ok. Good. Is there anyway you can post the Malwarebytes log that shows PupBundleinstall

    FYI.
    Pup prefix means Possible Unwanted Program, so it's not always a bad thing, but I'd still like to see the log if you have it. If you open Malwarebytes program, there's a tab that says logs, it would be in there.

    Joe

  • 715rose
    Original Author
    11 years ago

    Joe,Hope this helps.
    Rose
    bam-log-2012-10-18 (19-06-32).txt

    Scan type: Full scan (C:\:D:\:)
    Scan options enabled: Memory : Startup : Registry : File System : Heuristics/Extra : Heuristics/Shuriken : PUP : PUM
    Scan options disabled: P2P
    Objects scanned: 330972
    Time elapsed: 59 minute(s), 12 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Users\User\Downloads\video_downloader.exe (PUP.BundleInstaller.VG) -> No action taken.

    (end)

  • 715rose
    Original Author
    11 years ago

    Joe,Last one for tonight.
    This doesn't show it but I did remove that .Actually removed it twice.I thought.
    Thank you,
    Rose

  • 715rose
    Original Author
    11 years ago

    Joe,I couldn't resist doing a quick scan.Here is results.
    Rose
    bam-log-2012-10-21 (22-48-58).txt

    Scan type: Quick scan
    Scan options enabled: Memory : Startup : Registry : File System : Heuristics/Extra : Heuristics/Shuriken : PUP : PUM
    Scan options disabled: P2P
    Objects scanned: 195633
    Time elapsed: 2 minute(s), 59 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Users\User\Downloads\video_downloader.exe (PUP.BundleInstaller.VG) -> No action taken.

    (end)

    I clicked on "remove again".

  • zep516
    11 years ago

    Hi, Rose

    In the entry it says "No Action Taken" it looks You didn't take any action to remove the item,

    Make sure that everything is checked, and click Remove Selected.

    Then reboot the computer. See if that works.

    Joe

  • 715rose
    Original Author
    11 years ago

    Joe,Yes,I did click on the "remove" box in lower left. Then get small popup saying all items have been successfully removed.Haven't scanned again because a busy morning ahead.
    Thank you,
    Rose

0