uninstall softwarewatcher bundle
Results 1 to 10 of 10

Thread: uninstall softwarewatcher bundle

  1. #1
    Join Date
    May 2011
    Posts
    113

    uninstall softwarewatcher bundle

    Today I was trying to install the free version of Avast onto my windows 8.1 computer and I ended up at a sight called software watcher. I thought it was like bleeping computer or cnet and activated the download. Well I wasn't paying close attention and instead it download something called softwarewatcher bundle. This this popped up in my malwarebytes scan. I still see softwarewatcher bundle in my programs list and when i click the uninstall, it says that is has already uninstalled and do i want to remove it from the list. I do not readily believe this information as I have never known this to be the case. Do you know of this software and can you recommend a next step?


  2. #2
    Join Date
    Jun 2001
    Location
    Albuquerque, NM USA
    Posts
    14,686
    daveandrita1--
    "This this popped up in my malwarebytes scan"
    What did you then do? Quarantine? Delete? Nothing?
    Does Revouninstaller list it in the list of programs it can uninstall?
    http://www.revouninstaller.com/revo_..._download.html

    You could also run ADWCleaner
    http://general-changelog-team.fr/en/...e/2-adwcleaner

    If not in the Revouninstaller list, the bundle probably has been uninstalled and you can remove it from the Programs and Features list.
    Last edited by Welshjim; March 24th, 2014 at 03:35 PM.
    Jim
    WIN7 Ultimate SP1 64bit, IE 11, NTFS,
    cable, MS Security Essentials, Windows 7 firewall

  3. #3
    Join Date
    May 2011
    Posts
    113
    Quote Originally Posted by Welshjim View Post
    daveandrita1--
    "This this popped up in my malwarebytes scan"
    What did you then do? Quarantine? Delete? Nothing?
    Does Revouninstaller list it in the list of programs it can uninstall?
    http://www.revouninstaller.com/revo_..._download.html

    You could also run ADWCleaner
    http://general-changelog-team.fr/en/...e/2-adwcleaner

    If not in the Revouninstaller list, the bundle probably has been uninstalled and you can remove it from the Programs and Features list.
    I ran ADWCleaner first and removed all identified. Then I ran Malwarebytes; here is the log of what i deleted:
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\Users\owner\AppData\Local\Microsoft\Windows\INetCache\IE\83VLEYP3\spstub[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\Users\owner\AppData\Local\Microsoft\Windows\INetCache\IE\IIE4XLRW\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
    C:\Users\owner\AppData\Local\Temp\nsl9FA0.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
    C:\Users\owner\AppData\Local\Temp\nsm61F6.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.
    C:\Users\owner\AppData\Local\Temp\nso66D9.exe (PUP.Optional.SearchProtect.A) -> Quarantined and deleted successfully.

    This computer has this strange hover feature that somehow caused me to leave the screen before I completed the deletion process in malwarebytes, so here is the log of items that did not get deleted and I don't know how to get back to the right spot to delete them:
    Registry Keys Detected: 1
    HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> No action taken.

    Registry Values Detected: 1
    HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: 1523565508927280778 -> No action taken.

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 1
    C:\Users\owner\AppData\Local\Temp\CT3325809 (PUP.Optional.Conduit.A) -> No action taken.

    Files Detected: 28
    C:\Users\owner\AppData\Local\Temp\nsp9B2B.exe (PUP.Optional.SearchProtect.A) -> No action taken.
    C:\Users\owner\AppData\Local\Temp\nsxC9DC\SpSetup.exe (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPTool64.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\Desktop\Cleaning tools\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir (PUP.Optional.Conduit.A) -> No action taken.
    C:\Users\owner\AppData\Local\Temp\CT3325809\ddt.csf (PUP.Optional.Conduit.A) -> No action taken.

  4. #4
    Join Date
    May 2011
    Posts
    113
    Revo uninstall did find it. Am attempting uninstall now. Thanks for the recommendation

  5. #5
    Join Date
    Jun 2001
    Location
    Albuquerque, NM USA
    Posts
    14,686
    daveandrita1--
    Restart PC. Run MalwareBytes from scratch. This should allow detection and deletion of items marked "No Action Taken".
    Your logs above indicate that MBAM is detecting items in the ADWCleaner quarantine folder which have not been deleted.
    PUP's are Potentially Unwanted Programs--not the worst of Malware but you will probably want to delete them.
    Jim
    WIN7 Ultimate SP1 64bit, IE 11, NTFS,
    cable, MS Security Essentials, Windows 7 firewall

  6. #6
    Join Date
    May 2011
    Posts
    113
    Looks like revo successfully removed the program and I ran a new full scan with malwarebyte which seems to have removed everything. Do you know anything about her protect?

  7. #7
    Join Date
    Jun 2001
    Location
    Albuquerque, NM USA
    Posts
    14,686
    daveandrita1--
    Glad to hear the good news.

    "her protect" ???
    Jim
    WIN7 Ultimate SP1 64bit, IE 11, NTFS,
    cable, MS Security Essentials, Windows 7 firewall

  8. #8
    Join Date
    May 2011
    Posts
    113
    Herd protect - hate that auto fill feature sometimes

  9. #9
    Join Date
    Mar 2009
    Location
    Arkham Asylum, Cell 13
    Posts
    11,686
    Herd protect
    Don't bother unless you want to be their beta tester. MBAM is a much better choice.

  10. #10
    Join Date
    May 2011
    Posts
    113
    Got it. Tnx

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •