Malwarebytes can't removed a PuP found during scan.

mv52

Reputable
Aug 3, 2014
1
0
4,510
I have deleted the PuP but it seems to keep reappearing each time i scan my PC the only time when it does not appear is when i have left it quarantine. The following programs have been used to scan my PC. Malwarebytes, Spybot S&D, and TDSSKiller.

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/2/2014
Scan Time: 11:49:55 PM
Logfile:
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.08.03.01
Rootkit Database: v2014.08.01.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Abraham

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 345916
Time Elapsed: 12 min, 22 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 1
PUP.Optional.SearchNet, HKU\S-1-5-21-2347560423-1969051893-1687657924-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}, Quarantined, [cc6121a188f348ee87b4560ade24629e],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

Spybot S&D log:

14-08-02 23:46:13
14-08-02 23:46:13 Product Freecause.ShoppingBHO
[+] 14-08-02 23:46:13 Moving into quarantine HKEY_USERS\S-1-5-21-2347560423-1969051893-1687657924-1000\Software\AppDataLow\Software\Freecause
[+] 14-08-02 23:46:13 Successfully cleaned HKEY_USERS\S-1-5-21-2347560423-1969051893-1687657924-1000\Software\AppDataLow\Software\Freecause
14-08-02 23:46:13
14-08-02 23:46:13 Product Widgi.Toolbar
[+] 14-08-02 23:46:13 Moving into quarantine HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files (x86)\Common Files\Spigot\
[+] 14-08-02 23:46:13 Moving into quarantine C:\Program Files (x86)\Common Files\Spigot\
[+] 14-08-02 23:46:13 Successfully cleaned HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files (x86)\Common Files\Spigot\
[+] 14-08-02 23:46:13 Successfully cleaned C:\Program Files (x86)\Common Files\Spigot\
14-08-02 23:46:13
14-08-02 23:46:13 Product Systweak.RegCleanPro
[+] 14-08-02 23:46:13 Moving into quarantine C:\Program Files (x86)\RegClean Pro\
[+] 14-08-02 23:46:13 Successfully cleaned C:\Program Files (x86)\RegClean Pro\
14-08-02 23:46:13
14-08-02 23:46:13 Product Win32.Downloader.gen
[+] 14-08-02 23:46:13 Moving into quarantine C:\Users\Abraham\AppData\Local\Conduit\
[+] 14-08-02 23:46:13 Successfully cleaned C:\Users\Abraham\AppData\Local\Conduit\
14-08-02 23:46:13
14-08-02 23:46:13 Product Cookie
[+] 14-08-02 23:46:13 Moving into quarantine Internet Explorer (User) (Abraham)Cookies
[+] 14-08-02 23:46:13 Moving into quarantine Firefox (PE_C_DEFAULTAPPPOOL (default))Cookies
[+] 14-08-02 23:46:13 Moving into quarantine Google Chrome (Default)Cookies
[+] 14-08-02 23:46:13 Successfully cleaned Internet Explorer (User) (Abraham)Cookies
[+] 14-08-02 23:46:13 Successfully cleaned Firefox (PE_C_DEFAULTAPPPOOL (default))Cookies
[+] 14-08-02 23:46:13 Successfully cleaned Google Chrome (Default)Cookies
14-08-02 23:46:13
14-08-02 23:46:13 Product Cache
[+] 14-08-02 23:46:13 Moving into quarantine Internet Explorer (User) (Abraham)Cache
[+] 14-08-02 23:46:13 Successfully cleaned Internet Explorer (User) (Abraham)Cache
14-08-02 23:46:13
14-08-02 23:46:13 Product History
[+] 14-08-02 23:46:13 Moving into quarantine Internet Explorer (User) (Abraham)History
[+] 14-08-02 23:46:13 Moving into quarantine Google Chrome (Default)History
[+] 14-08-02 23:46:13 Successfully cleaned Internet Explorer (User) (Abraham)History
[+] 14-08-02 23:46:13 Successfully cleaned Google Chrome (Default)History
14-08-02 23:46:13
14-08-02 23:46:13 Summary
14-08-02 23:46:13 Errors while cleaning 0
14-08-02 23:46:13 Files moved into quarantine 11
14-08-02 23:46:13 Files successfully cleaned 11




(end)
TSDKiller came out clean.
 
Solution
That's probably because the program that uses it is still running. You can do a clean boot and then run your scanners or you can get a great little program called UVK (ultra virus killer). If you run your scans through UVK there is an option to kill all non-system programs before you start. Saves time.

Good Luck,
Jim
That's probably because the program that uses it is still running. You can do a clean boot and then run your scanners or you can get a great little program called UVK (ultra virus killer). If you run your scans through UVK there is an option to kill all non-system programs before you start. Saves time.

Good Luck,
Jim
 
Solution