• Can I delete AppData folders that draw these PUPS?

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Can I delete AppData folders that draw these PUPS?

    • This topic has 24 replies, 7 voices, and was last updated 10 years ago.
    Author
    Topic
    #499960

    Malwarebytes just found these PUPS on my W7 Pro PC. Can I delete these AppData folders, If not what can I do to avoid them. They all are tied to GOOGLE, ‘sould I be suprised’ ?
    I do not use Google browser or search engine, but do use Google Earth once in a while and some sites with Google maps inserts? Suggestions appreciated.
    [INDENT]1] PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, , [886770233f4b56e0ba466107679e0bf5],
    2] PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, ,
    3] PUP.Optional.MultiPlug.A, C:UsersXXX userAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166background.html, ,
    [/INDENT]

    Also, I want to “THANK” for the help I get, but I’ve looked all over the place to find THANKS.
    Common sense would indicate that you would thank the poster when you logged in to view the post.
    My years of training required that everyone who even offers to help, even if the offer is not succesfull earns a Thank you. You thank the offer not the result.

    Viewing 8 reply threads
    Author
    Replies
    • #1504643

      The thanks button is bottom left of the post – see attachment
      40610-thanks
      Afraid I can’t answer about the pups 🙁

      Eliminate spare time: start programming PowerShell

      • #1504651

        The thanks button is bottom left of the post – see attachment
        40610-thanks
        Afraid I can’t answer about the pups 🙁

        Thanks,

        Very easy to locate & see.
        However I’m now currently responding to you & looking to my lower left corner and there is no small med gray thank icon in sight.
        Once I respond to a post I’m gone as I have many other things to. Do I have to come back in to WS forum, locate my post to you answer?

        With today’s swipe go technology, that process seems dated??

        Thanks I appreciate you help.

        klx

        • #1504656

          Thanks,

          Very easy to locate & see.
          However I’m now currently responding to you & looking to my lower left corner and there is no small med gray thank icon in sight.
          Once I respond to a post I’m gone as I have many other things to. Do I have to come back in to WS forum, locate my post to you answer?

          With today’s swipe go technology, that process seems dated??

          Thanks I appreciate you help.

          klx

          It isn’t used in the “Reply” format. To use the Thanks button, locate the post that has the information for which you wish to thank the poster, and click the Thanks button at the bottom left of that post.

          You won’t see the Thanks button on any of your own posts, only on the posts of others.

          Always create a fresh drive image before making system changes/Windows updates; you may need to start over!
          We all have our own reasons for doing the things that we do with our systems; we don't need anyone's approval, and we don't all have to do the same things.
          We were all once "Average Users".

          • #1504768

            It isn’t used in the “Reply” format. To use the Thanks button, locate the post that has the information for which you wish to thank the poster, and click the Thanks button at the bottom left of that post.

            You won’t see the Thanks button on any of your own posts, only on the posts of others.

            bbearren,

            The business process:

            1] I post a question.
            2] I get a email response from poster from the forum.
            3] I read the posters answer to my question.
            4] I respond to the poster no matter whether his answer is relevant or not.
            5] And at that point I thank him for his response even though his response is may not relevant.

            Reasons:
            I have all posts with links on my PC in front of me.
            I dont have get back on the internet, go to WS lounge, log in, find the post so I can thank the poster.
            I use the KISS principle.
            Today’s business changes so fast & furious that it has to be conducted & completed in “nano seconds” The old days are gone at least at my position on the Bell Curve.

            EOS.

            PS, I will go back & thank you for clearing this matter up for me.

    • #1504644

      Yes, you can safely delete the Google folders in AppDataLocal if UAC will allow it. You might have to take ownership in order to delete them. They may or may not be tied in with Google Earth, but if you have a problem with Google Earth you can just reinstall it.

      However, that doesn’t mean that they will stay deleted. The same process that put them there can also put them there again.

      Always create a fresh drive image before making system changes/Windows updates; you may need to start over!
      We all have our own reasons for doing the things that we do with our systems; we don't need anyone's approval, and we don't all have to do the same things.
      We were all once "Average Users".

    • #1504645

      [Moved to Security and Scams]

    • #1504647

      First, it’s important to understand what PUPs are. They are not in the same category as viruses, or trojans or similar. So, although they are definitely unwanted and an annoyance, they aren’t necessarily evil.

      I also think that instead of fighting symptoms, your best bet is to prevent the disease from occurring again. The fact that the PUPs files are located in Chrome folders means that whoever is using the browser, is doing something that brings the PUPs along. Better check what it is that is being done and stop it. You can also try and get software that prevents PUP installation, if that bothers you that much.

      This said, you can delete the folders, but if whoever caused the PUPs to be downloaded in first place, does it again, other folders will be created and the PUPs will appear again. Thus, deleting the folders is pretty much useless as a PUP fighting strategy.

      • #1504657

        First, it’s important to understand what PUPs are. They are not in the same category as viruses, or trojans or similar. So, although they are definitely unwanted and an annoyance, they aren’t necessarily evil.

        I also think that instead of fighting symptoms, your best bet is to prevent the disease from occurring again. The fact that the PUPs files are located in Chrome folders means that whoever is using the browser, is doing something that brings the PUPs along. Better check what it is that is being done and stop it. You can also try and get software that prevents PUP installation, if that bothers you that much.

        This said, you can delete the folders, but if whoever caused the PUPs to be downloaded in first place, does it again, other folders will be created and the PUPs will appear again. Thus, deleting the folders is pretty much useless as a PUP fighting strategy.

        ruiib,

        I use: unchecky, SUPERAntispyware, Malwarebytes free, SpyBot, SpywareBlaster, Panda Anti virus daily some times several times a day.
        I rarely find PUPs and I know the’re an annoyance, but when I noticed GOOGLE, my antennas lit up.

        • #1504658

          ruiib,

          I use: unchecky, SUPERAntispyware, Malwarebytes free, SpyBot, SpywareBlaster, Panda Anti virus daily some times several times a day.
          I rarely find PUPs and I know the’re an annoyance, but when I noticed GOOGLE, my antennas lit up.

          Thanks, I’d like to close this issue as my quetion has been satisfactorly answered. And my wife is calling me.

        • #1504706

          ruiib,

          I use: unchecky, SUPERAntispyware, Malwarebytes free, SpyBot, SpywareBlaster, Panda Anti virus daily some times several times a day.
          I rarely find PUPs and I know the’re an annoyance, but when I noticed GOOGLE, my antennas lit up.

          To prevent PUPs from installing, you’d need to use something that detects them in real time. This means you need to use an active component to prevent their installation. I am not sure if the Malwarebytes paid version would do it. My AV detects PUPs (if I so choose), but it’s not on your list of used apps.

    • #1504650

      unchecky from unchecky.com is one of the best upfront PUP fighters. Ditto on not deleting appdata folders, such will not work in the long-run. SUPERAntispyware, Malwarebytes AM, SpyBot, SpywareBlaster, just to name a few, pick or two.
      Many anti-virus include anti-PUP scans — again, find one or two to run scheduled scans, remember only one anti-virus can have it real time protection shields on.

      "Take care of thy backups and thy restores shall take care of thee." Ben Franklin, revisted

    • #1504659

      Can you attach the Malwarebytes log file, please?

    • #1504804

      I just read your email, it looks like Malwarebytes didn’t quarantine anything?

      Try the following cleanup routine:
      Download and run ADWCleaner – http://www.bleepingcomputer.com/download/adwcleaner/

      Then run JRT – the URL is on the same page as above, lower down.

      Update and run Malwarebytes again, Quarantine anything listed.

      Reset Chrome – https://support.google.com/chrome/answer/3296214?hl=en

      When done, please reply here and attach or copy/paste the logs from the 3 tools above.

      • #1504875

        I just read your email, it looks like Malwarebytes didn’t quarantine anything?

        Try the following cleanup routine:
        Download and run ADWCleaner – http://www.bleepingcomputer.com/download/adwcleaner/

        Then run JRT – the URL is on the same page as above, lower down.

        Update and run Malwarebytes again, Quarantine anything listed.

        Reset Chrome – https://support.google.com/chrome/answer/3296214?hl=en

        When done, please reply here and attach or copy/paste the logs from the 3 tools above.

        I’ll send logs tomorrow. I’ve been working on these PCs since early morn and

        its 11:18 pm. Im old & tired

        • #1504943

          I’ll send logs tomorrow. I’ve been working on these PCs since early morn and

          its 11:18 pm. Im old & tired

          satrow,

          Logs you requested. Have a good read ha ha, and thanks for you interest & help. thanks for the tip on JRT.

          LOG FILES FRPM FROM MWB & ADW as requested.

          Please make sure you match the date of my orig to the MWB log as I included the day before & the day after MWB scans. The day before I posted, MWB found NO PUPS. Nets day I ran MWB and it FOUND & CLEARED all the pups I mentioned in my post.

          My refrence to GOOGLE was my concern. How did they get there? I have known about PUPs for quite a while, buy when so many and with GOOGLE’S name attached. That got my SHIELDS up.

          Below are MALWAREBYTES ANTI-MALWARE, ADWCLEANER, & JUNKWARE REMOVAL TOOL log files, hope this helps:

          Malwarebytes Anti-Malware
          http://www.malwarebytes.org

          Scan Date: 5/14/2015
          Scan Time: 1:01:10 PM
          Logfile: MWB 5-14-15.txt
          Administrator: Yes

          Version: 2.00.4.1028
          Malware Database: v2015.05.14.04
          Rootkit Database: v2015.04.21.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows 7 Service Pack 1
          CPU: x86
          File System: NTFS
          User: klxdrt

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 407285
          Time Elapsed: 20 min, 50 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)

          (end)

          ========
          Malwarebytes Anti-Malware
          http://www.malwarebytes.org

          Scan Date: 5/15/2015
          Scan Time: 9:48:10 AM
          Logfile: MWB 5-15-15.txt
          Administrator: Yes

          Version: 2.01.6.1022
          Malware Database: v2015.05.15.03
          Rootkit Database: v2015.05.14.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows 7 Service Pack 1
          CPU: x86
          File System: NTFS
          User: klxdrt

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 401108
          Time Elapsed: 22 min, 11 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 8
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],

          Files: 20
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166background.html, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166content.js, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166m2.js, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersAdministratorAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166manifest.json, Quarantined, [886770233f4b56e0ba466107679e0bf5],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166background.html, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166content.js, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166m2.js, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersGuestAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166manifest.json, Quarantined, [628d751e395183b338c8bfa9f60f20e0],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166background.html, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166content.js, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166m2.js, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHerbAppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166manifest.json, Quarantined, [2ec18c07dfab6dc9758b92d63cc95fa1],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166lsdb.js, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166background.html, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166content.js, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166m2.js, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],
          PUP.Optional.MultiPlug.A, C:UsersHomeGroupUser$AppDataLocalGoogleChromeUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga166manifest.json, Quarantined, [6986fa99dcaea69001ffd494c5400bf5],

          Physical Sectors: 0
          (No malicious items detected)

          (end)

          =========
          Malwarebytes Anti-Malware
          http://www.malwarebytes.org

          Scan Date: 5/16/2015
          Scan Time: 10:08:36 AM
          Logfile: MWB 5-16-15.txt
          Administrator: Yes

          Version: 2.01.6.1022
          Malware Database: v2015.05.16.02
          Rootkit Database: v2015.05.14.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows 7 Service Pack 1
          CPU: x86
          File System: NTFS
          User: klxdrt

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 401434
          Time Elapsed: 21 min, 47 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)

          (end)
          ========

          # AdwCleaner v4.204 – Logfile created 16/05/2015 at 10:03:15
          # Updated 12/05/2015 by Xplode
          # Database : 2015-05-12.2 [Server]
          # Operating system : Windows 7 Professional Service Pack 1 (x86)
          # Username : KLXDRT – DESKTOP-PC
          # Running from : C:Program FilesPORTABLEadwcleaner_4.204.exe
          # Option : Cleaning

          ***** [ Services ] *****

          ***** [ Files / Folders ] *****

          Folder Deleted : C:UsersAdministratorAppDataLocalComodoDragonUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersGuestAppDataLocalComodoDragonUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersHerbAppDataLocalComodoDragonUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersHomeGroupUser$AppDataLocalComodoDragonUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersAdministratorAppDataLocalGoogleChrome SxSUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersGuestAppDataLocalGoogleChrome SxSUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersHerbAppDataLocalGoogleChrome SxSUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga
          Folder Deleted : C:UsersHomeGroupUser$AppDataLocalGoogleChrome SxSUser DataDefaultExtensionsnedjejdfkkjgebciefdfofjhmeogiaga

          ***** [ Scheduled tasks ] *****

          ***** [ Shortcuts ] *****

          ***** [ Registry ] *****

          ***** [ Web browsers ] *****

          -\ Internet Explorer v11.0.9600.17801

          -\ Mozilla Firefox v37.0.2 (x86 en-US)

          -\ Google Chrome v

          -\ Comodo Dragon v

          -\ Chrome Canary v

          *************************

          AdwCleaner[R0].txt – [1855 bytes] – [02/04/2015 12:07:16]
          AdwCleaner[R1].txt – [1914 bytes] – [02/04/2015 12:10:57]
          AdwCleaner[R2].txt – [1973 bytes] – [02/04/2015 12:13:10]
          AdwCleaner[R3].txt – [2089 bytes] – [16/05/2015 10:01:24]
          AdwCleaner[S0].txt – [2066 bytes] – [02/04/2015 12:14:06]
          AdwCleaner[S1].txt – [2030 bytes] – [16/05/2015 10:03:15]

          ########## EOF – C:AdwCleanerAdwCleaner[S1].txt – [2089 bytes] ##########

          =======================

          Junkware Removal Tool (JRT) by Thisisu
          Version: 6.7.2 (05.15.2015:1)
          OS: Windows 7 Professional x86
          Ran by klxdrt on Sat 05/16/2015 at 11:08:12.56
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          ~~~ Services

          ~~~ Tasks

          ~~~ Registry Values

          ~~~ Registry Keys

          Successfully deleted: [Registry Key] HKEY_CLASSES_ROOTCLSID{10921475-03CE-4E04-90CE-E2E7EF20C814}
          Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerBrowser Helper Objects{10921475-03CE-4E04-90CE-E2E7EF20C814}

          ~~~ Files

          Successfully deleted: [File] C:Windowswininit.ini

          ~~~ Folders

          Successfully deleted: [Empty Folder] C:Usersklxdrtappdatalocal{FDA42A9B-3CFA-4F7F-9DBC-AEC8158DA4C6}
          Successfully deleted: [Folder] C:Usersklxdrtlocal settingsapplication datacre
          Successfully deleted: [Folder] C:Usersklxdrtlocal settingsapplication datastronghold_llc
          Successfully deleted: [Folder] C:WindowsSystem32ai_recyclebin

          ~~~ FireFox

          Emptied folder: C:UsersklxdrtAppDataRoamingmozillafirefoxprofiles8thfgekm.default-1419282686943minidumps [1 files]

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Sat 05/16/2015 at 11:11:16.13
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

          • #1504946

            ***** [ Web browsers ] *****

            -\ Internet Explorer v11.0.9600.17801

            -\ Mozilla Firefox v37.0.2 (x86 en-US)

            -\ Google Chrome v

            -\ Comodo Dragon v

            -\ Chrome Canary v

            May I suggest uninstalling some of the web browsers you don’t use?

            (Or does a different user normally use a different browser from you?)

            • #1504948

              May I suggest uninstalling some of the web browsers you don’t use?

              (Or does a different user normally use a different browser from you?)

              BruceR

              Im the only user and I use 1 browser FF 37.
              IE is only for a few critical sites that don’t like FF.

              Thanks for your response.

            • #1504951

              Im the only user and I use 1 browser FF 37.
              IE is only for a few critical sites that don’t like FF.

              In that case, I suggest uninstalling Google Chrome, Commodo Dragon and Chrome Canary.

              This will avoid issues like your PUPs in post #1, which were all Google Chrome Extensions.

            • #1504953

              In that case, I suggest uninstalling Google Chrome, Commodo Dragon and Chrome Canary.

              This will avoid issues like your PUPs in post #1, which were all Google Chrome Extensions.

              BruceR,

              Thanks for your respose, but I don’t have nor ever had those above mentioned browsers on my PC. I use only FF & IE.

    • #1504958

      It looks like those PUPS might be the result of having had Comodo and IObit installed at some point. Perhaps toolbars/BHOs designed to send your browsing URLs for checking?

      What software have you got/had by either of those companies?

      • #1504960

        It looks like those PUPS might be the result of having had Comodo and IObit installed at some point. Perhaps toolbars/BHOs designed to send your browsing URLs for checking?

        What software have you got/had by either of those companies?

        satrow,

        I only have IObit uninstaller & Advanced System care 8.2 which I think is by IObit. I don’t know what Comodo is, Comodo Browser?? Have had both since fall, never showed up before. Both SW prog
        worked well and were useful.

        You have be so helpful, I asked my lovely wife to bake some cookies for. Maybe I’ll be able to get off this #(&^% PC and spend more time with her.
        Hope you enjoy them.

    • #1504965

      We’d better let Rui have the first choice of cookies, he needs the strength to keep us in line 🙂

      To check the current range of Comodo offerings, look here and also hover your mouse over the Home and Home Office tab, there might also be software of theirs that’s bundled by a partner company under a different name.

      IObit haven’t had the best reputation in the past, I’m not sure that I’d fully trust them now.

      • #1505000

        We’d better let Rui have the first choice of cookies, he needs the strength to keep us in line 🙂

        To check the current range of Comodo offerings, look here and also hover your mouse over the Home and Home Office tab, there might also be software of theirs that’s bundled by a partner company under a different name.

        IObit haven’t had the best reputation in the past, I’m not sure that I’d fully trust them now.

        I know yo have to watch when you install any IObit SW, or any of their FREE pron, I remove what I don’t want, a nuisance. The uninstaller seems to get rid of more crap and since running ASC 8.2 my desktop icons pop rite up rather that straggling. My XP Pro routinely kicked out of “adjust for speed mode” [rt clk My Computer], it hasn’t done this since I inst ASC 8.2. And all their products try to trick/huck you to buy their SW. Just like MS sends me updates daily, esp for Defender.

        Again thaks for all your friendly help as the PUP situation is resolved as far as I’m concerned. I wouid your comments about IObit products as I have been wary for while.

      • #1505001

        We’d better let Rui have the first choice of cookies, he needs the strength to keep us in line 🙂

        To check the current range of Comodo offerings, look here and also hover your mouse over the Home and Home Office tab, there might also be software of theirs that’s bundled by a partner company under a different name.

        IObit haven’t had the best reputation in the past, I’m not sure that I’d fully trust them now.

        I know you have to watch when you install any IObit SW, or any of their FREE prog, I remove what I don’t want, a nuisance. The uninstaller seems to get rid of more crap and since running ASC 8.2 my desktop icons pop rite up rather that straggling. My XP Pro routinely kicked out of “adjust for speed mode” [rt clk My Computer], it hasn’t done this since I inst ASC 8.2. And all their products try to trick/huck you to buy their SW. Just like MS sends me updates daily, esp for Defender.

        Again thaks for all your friendly help as the PUP situation is resolved as far as I’m concerned. I wouid your comments about IObit products as I have been wary for while.

    Viewing 8 reply threads
    Reply To: Can I delete AppData folders that draw these PUPS?

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: