Jump to content


Photo

(Resolved) PUP Removals ?


  • Please log in to reply
3 replies to this topic

#1 sesomnhoj

sesomnhoj

    New Member

  • Members
  • Pip
  • 3 posts

Posted 20 September 2013 - 06:33 AM

Hi, im not sure if im at the correct thread or page.

im new here but i need help in these PUP registry files, i hope you can tell me if its all safe to remove them

 

here's the log

 

Registry Keys Detected: 19
HKCR\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899} (PUP.Optional.WebCake.A) -> No action taken.
HKCR\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899} (PUP.Optional.WebCake.A) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA} (PUP.Optional.WebCake.A) -> No action taken.
HKCR\CrossriderApp0026766.BHO (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0026766.BHO.1 (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0026766.Sandbox (PUP.Optional.CrossRider.A) -> No action taken.
HKCR\CrossriderApp0026766.Sandbox.1 (PUP.Optional.CrossRider.A) -> No action taken.
HKCU\Software\1ClickDownload (PUP.Optional.1ClickDownload.A) -> No action taken.
HKCU\Software\Cr_Installer\26766 (PUP.Optional.CrossRider.A) -> No action taken.
HKCU\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> No action taken.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
HKCR\CLSID\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
HKCR\TypeLib\{44444444-4444-4444-4444-440244674466} (PUP.Optional.CrossRider.M) -> No action taken.
HKCR\Interface\{55555555-5555-5555-5555-550255675566} (PUP.Optional.CrossRider.M) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110211671166} (PUP.Optional.CrossRider.M) -> No action taken.
 
Registry Values Detected: 2
HKCU\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {79483C22-CE21-11E2-BCA3-00269E7D874A} -> No action taken.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {79483C22-CE21-11E2-BCA3-00269E7D874A} -> No action taken.
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 4
C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com (PUP.Optional.HDVidCodec.A) -> No action taken.
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> No action taken.
 
Files Detected: 8
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> No action taken.
C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\HDVidCodec.lnk (PUP.Optional.HDVidCodec.A) -> No action taken.
C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\hdvidcodec.com\Uninstall.lnk (PUP.Optional.HDVidCodec.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> No action taken.
C:\Program Files (x86)\Discount Buddy\Discount Buddy.dll (PUP.Optional.CrossRider.M) -> No action taken.


#2 sesomnhoj

sesomnhoj

    New Member

  • Members
  • Pip
  • 3 posts

Posted 20 September 2013 - 06:35 AM

hope you can help me, thanks in advance, sorry for the double post.  :unsure:



#3 Fatdcuk

Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 20,550 posts
  • Gender:Male
  • Location:127.0.0.1

Posted 20 September 2013 - 06:50 AM

hope you can help me, thanks in advance, sorry for the double post.  :unsure:

 

Hi,

 

If you do not recognize or use any of the names in the log or are unaware how they were installed in the first place it is safe to deem them as Potentially Unwanted Programs (PUP's)

 

They are safe to remove if you do not want them on your computer :)


Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4 sesomnhoj

sesomnhoj

    New Member

  • Members
  • Pip
  • 3 posts

Posted 21 September 2013 - 12:47 AM

thanks a lot! i love malwarebytes   ^_^






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users