LandzDown Forum

Security => Security Software Programs => Topic started by: ky331 on June 26, 2014, 10:56:06 AM

Title: AdwCleaner FP of WinPatrol
Post by: ky331 on June 26, 2014, 10:56:06 AM
AdwCleaner is now flagging several registry entries created by WinPatrol.   These appear to be False Positives, and should NOT be removed.

http://www.wilderssecurity.com/threads/win-patrol.365331/
Title: Re: AdwCleaner FP of WinPatrol
Post by: LilBambi on June 26, 2014, 01:42:32 PM
Shoot.. why add WinPatrol entries to AdwCleaner...sigh...
Title: Re: AdwCleaner FP of WinPatrol
Post by: Corrine on June 26, 2014, 02:31:57 PM
I've reported the f/p to Xplode and let Bill know.
Title: Re: AdwCleaner FP of WinPatrol
Post by: LilBambi on June 26, 2014, 07:25:41 PM
Thanks Corrine! Hopefully he will get in touch with the developers of AdwCleaner so they know those are WinPatrol's stuff.  :hug:

:mitch:
Title: Re: AdwCleaner FP of WinPatrol
Post by: winchester73 on June 26, 2014, 07:47:12 PM
Quote from: LilBambi on June 26, 2014, 07:25:41 PM
Hopefully he will get in touch with the developers of AdwCleaner so they know those are WinPatrol's stuff. 

Xplode is the author of AdwCleaner   :cool:

For others reading this, there is a reason why it is suggested that you click "Report" at the end of a scan and not "Clean".  A review of the logfile that opens in Notepad will help spot any false positives (or certain items that you wish to allow).  AdwCleaner does not create a backup but does contain a quarantine file from which files can be de-quarantined.
Title: Re: AdwCleaner FP of WinPatrol
Post by: Corrine on June 26, 2014, 07:48:29 PM
Also, keep in mind that f/p's can be restored from the AdwCleaner quarantine.  To restore a file:
Of course, it would be better to review the findings prior to removal.  When the AdwCleaner scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if unsure or further review is needed.   

Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked.


Title: Re: AdwCleaner FP of WinPatrol
Post by: LilBambi on June 28, 2014, 01:36:12 PM
That's great news Corrine!

Title: Re: AdwCleaner FP of WinPatrol
Post by: ky331 on June 30, 2014, 11:09:26 AM
AdwCleaner 3.214 has been released, fixing (i.e., removing) the F/P of WinPatrol.
Title: Re: AdwCleaner FP of WinPatrol
Post by: LilBambi on June 30, 2014, 05:26:15 PM
Excellent, downloading now!
Title: Re: AdwCleaner FP of WinPatrol
Post by: siljaline on July 01, 2014, 02:16:22 AM
AdwCleaner is flagging WinPatrol, see:
http://www.wilderssecurity.com/threads/win-patrol.365331/
Title: Re: AdwCleaner FP of WinPatrol
Post by: JDBush61 on July 01, 2014, 02:34:38 AM
Quote from: siljaline on July 01, 2014, 02:16:22 AM
AdwCleaner is flagging WinPatrol, see:
http://www.wilderssecurity.com/threads/win-patrol.365331/

Similar to what is posted in Siljaline's link above, I've noticed the following WinPatrol FPs (?) with Adwcleaner:

adwcleaner_3.213.exe
# Option : Scan

Key Found : HKCU\Software\BillP Studios
Key Found : [x64] HKCU\Software\BillP Studios
Key Found : [x64] HKLM\SOFTWARE\BillP Studios

I guess I'll try updating to AdwCleaner 3.214 and see if that solves the issue.

Best wishes to Bill P. and the new owner.
Title: Re: AdwCleaner FP of WinPatrol
Post by: JDBush61 on July 01, 2014, 02:49:08 AM
Just an update regarding AdwCleaner / WinPatrol issue. I trashed AdwCleaner 3.213 and downloaded 3.214, and now it does not seem to have the WinPatrol registry key FPs. However, it does flag a new key (which I deleted ... gulp!...), and something related to Firefox (which I also deleted. Also a "gulp!").

I realize that this is a WinPatrol thread, yet if someone would kindly tell me what AdwCleaner found and cleaned it would be greatly appreciated.

AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Users\Administrator Bush\AppData\Roaming\Mozilla\Firefox\Profiles\ywmg8h0l.default\prefs.js ]
Title: Re: AdwCleaner FP of WinPatrol
Post by: siljaline on July 01, 2014, 04:00:43 AM
Per notes from Corrine:
Quote
-- Launch AdwCleaner and click Tools > Click Quarantine manager.
-- Place a check in the box next to the file(s) to be restored.
-- Click Restore (a logfile will open).

You can also uncheck elements you don't want to remove:

When the scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if you want to keep them. Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked. 

Title: Re: AdwCleaner FP of WinPatrol
Post by: JDBush61 on July 01, 2014, 05:04:30 AM
Quote from: siljaline on July 01, 2014, 04:00:43 AM
Per notes from Corrine:
Quote
-- Launch AdwCleaner and click Tools > Click Quarantine manager.
-- Place a check in the box next to the file(s) to be restored.
-- Click Restore (a logfile will open).

You can also uncheck elements you don't want to remove:

When the scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if you want to keep them. Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked. 

Thanks Siljaline, but I'm still at square one. I followed Corrine's instructions (i.e., Tools > Quarantine manager), and AdwCleaner stated "Quarantine empty".

So back to my original question:

Any idea what AdwCleaner cleaned / did (shown below), and why?

AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Users\Administrator Bush\AppData\Roaming\Mozilla\Firefox\Profiles\ywmg8h0l.default\prefs.js ]
Title: Re: AdwCleaner FP of WinPatrol
Post by: siljaline on July 01, 2014, 05:13:29 AM
The CLSID - best as I could determine is Skype.
http://www.systemlookup.com/CLSID/66064-skypeieplugin_dll_skypeieplugin4_dll.html
(read full citation before deciding if you want to recover the item)

The Firefox script has been falsely flagged forever but it covers regardless if it's removed.

Please note that I'm not an expert in what the tool can and can't do as I've stopped using it.

Title: Re: AdwCleaner FP of WinPatrol
Post by: JDBush61 on July 01, 2014, 06:09:33 AM
Thanks a bunch for the prompt and detailed reply, siljaline. Most appreciated.

John
Title: Re: AdwCleaner FP of WinPatrol
Post by: Corrine on July 01, 2014, 01:41:19 PM
Note:  Posts regarding WinPatrol and AdwCleaner split from WinPatrol: Changing of the Guard (http://www.landzdown.com/winpatrol-help-information/winpatrol-changing-of-the-guard/).

Hi, John. 

Anything "detected" by AdwCleaner can be reviewed after scanning in the various tabs.  Items detected that you wish to research further or know to be safe can be unchecked prior to removal except anything shown in the the Firefox and Chrome folders.  They are viewable but can NOT be unchecked.
Title: Re: AdwCleaner FP of WinPatrol
Post by: siljaline on July 01, 2014, 01:42:34 PM
You are most welcome, John - glad to help. System Lookup (http://www.systemlookup.com/) is an excellent tool for toolbar searches and the like.  For someone that does malware (http://en.wikipedia.org/wiki/Malware) removal.
Title: Re: AdwCleaner FP of WinPatrol
Post by: siljaline on July 01, 2014, 02:05:27 PM
For those that are socially inclined, you may reach out to the AdwCleaner Team via Twitter (https://twitter.com/gchangelog)