-
March 24th, 2014, 03:01 PM
#1
uninstall softwarewatcher bundle
Today I was trying to install the free version of Avast onto my windows 8.1 computer and I ended up at a sight called software watcher. I thought it was like bleeping computer or cnet and activated the download. Well I wasn't paying close attention and instead it download something called softwarewatcher bundle. This this popped up in my malwarebytes scan. I still see softwarewatcher bundle in my programs list and when i click the uninstall, it says that is has already uninstalled and do i want to remove it from the list. I do not readily believe this information as I have never known this to be the case. Do you know of this software and can you recommend a next step?
-
March 24th, 2014, 03:32 PM
#2
daveandrita1--
"This this popped up in my malwarebytes scan"
What did you then do? Quarantine? Delete? Nothing?
Does Revouninstaller list it in the list of programs it can uninstall?
http://www.revouninstaller.com/revo_..._download.html
You could also run ADWCleaner
http://general-changelog-team.fr/en/...e/2-adwcleaner
If not in the Revouninstaller list, the bundle probably has been uninstalled and you can remove it from the Programs and Features list.
Last edited by Welshjim; March 24th, 2014 at 03:35 PM.
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
March 24th, 2014, 05:11 PM
#3
Originally Posted by Welshjim
I ran ADWCleaner first and removed all identified. Then I ran Malwarebytes; here is the log of what i deleted:
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\owner\AppData\Local\Microsoft\Windows\INetCache\IE\83VLEYP3\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\owner\AppData\Local\Microsoft\Windows\INetCache\IE\IIE4XLRW\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\owner\AppData\Local\Temp\nsl9FA0.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\owner\AppData\Local\Temp\nsm61F6.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
C:\Users\owner\AppData\Local\Temp\nso66D9.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
This computer has this strange hover feature that somehow caused me to leave the screen before I completed the deletion process in malwarebytes, so here is the log of items that did not get deleted and I don't know how to get back to the right spot to delete them:
Registry Keys Detected: 1
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> No action taken.
Registry Values Detected: 1
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 1523565508927280778 -> No action taken.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 1
C:\Users\owner\AppData\Local\Temp\CT3325809 (PUP.Optional.Conduit.A) -> No action taken.
Files Detected: 28
C:\Users\owner\AppData\Local\Temp\nsp9B2B.exe (PUP.Optional.SearchProtect.A) -> No action taken.
C:\Users\owner\AppData\Local\Temp\nsxC9DC\SpSetup.exe (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
C:\Users\owner\AppData\Local\Temp\CT3325809\ddt.csf (PUP.Optional.Conduit.A) -> No action taken.
-
March 24th, 2014, 05:23 PM
#4
Revo uninstall did find it. Am attempting uninstall now. Thanks for the recommendation
-
March 24th, 2014, 05:48 PM
#5
daveandrita1--
Restart PC. Run MalwareBytes from scratch. This should allow detection and deletion of items marked "No Action Taken".
Your logs above indicate that MBAM is detecting items in the ADWCleaner quarantine folder which have not been deleted.
PUP's are Potentially Unwanted Programs--not the worst of Malware but you will probably want to delete them.
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
March 24th, 2014, 07:42 PM
#6
Looks like revo successfully removed the program and I ran a new full scan with malwarebyte which seems to have removed everything. Do you know anything about her protect?
-
March 25th, 2014, 08:39 PM
#7
daveandrita1--
Glad to hear the good news.
"her protect" ???
Jim
WIN7 Ultimate SP1 64bit, IE 11, NTFS,
cable, MS Security Essentials, Windows 7 firewall
-
March 25th, 2014, 09:11 PM
#8
Herd protect - hate that auto fill feature sometimes
-
March 25th, 2014, 09:41 PM
#9
Don't bother unless you want to be their beta tester. MBAM is a much better choice.
-
March 25th, 2014, 10:07 PM
#10
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|