AdwCleaner FP of WinPatrol

Started by ky331, June 26, 2014, 10:56:06 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

ky331

AdwCleaner is now flagging several registry entries created by WinPatrol.   These appear to be False Positives, and should NOT be removed.

http://www.wilderssecurity.com/threads/win-patrol.365331/

LilBambi

Shoot.. why add WinPatrol entries to AdwCleaner...sigh...
Bambi
AKA Fran
Jim-Fran.com

Corrine

I've reported the f/p to Xplode and let Bill know.


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

LilBambi

Thanks Corrine! Hopefully he will get in touch with the developers of AdwCleaner so they know those are WinPatrol's stuff.  :hug:

:mitch:
Bambi
AKA Fran
Jim-Fran.com

winchester73

Quote from: LilBambi on June 26, 2014, 07:25:41 PM
Hopefully he will get in touch with the developers of AdwCleaner so they know those are WinPatrol's stuff. 

Xplode is the author of AdwCleaner   :cool:

For others reading this, there is a reason why it is suggested that you click "Report" at the end of a scan and not "Clean".  A review of the logfile that opens in Notepad will help spot any false positives (or certain items that you wish to allow).  AdwCleaner does not create a backup but does contain a quarantine file from which files can be de-quarantined.
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member

Corrine

Also, keep in mind that f/p's can be restored from the AdwCleaner quarantine.  To restore a file:

  • Launch AdwCleaner and click Tools > Click Quarantine manager.
  • Place a check in the box next to the file(s) to be restored.
  • Click Restore (a logfile will open).
Of course, it would be better to review the findings prior to removal.  When the AdwCleaner scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if unsure or further review is needed.   

Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked.




Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

LilBambi

Bambi
AKA Fran
Jim-Fran.com

ky331

AdwCleaner 3.214 has been released, fixing (i.e., removing) the F/P of WinPatrol.

LilBambi

Bambi
AKA Fran
Jim-Fran.com

siljaline

siljaline
MVPS Hosts . MBAM . Why ESET

JDBush61

Quote from: siljaline on July 01, 2014, 02:16:22 AM
AdwCleaner is flagging WinPatrol, see:
http://www.wilderssecurity.com/threads/win-patrol.365331/

Similar to what is posted in Siljaline's link above, I've noticed the following WinPatrol FPs (?) with Adwcleaner:

adwcleaner_3.213.exe
# Option : Scan

Key Found : HKCU\Software\BillP Studios
Key Found : [x64] HKCU\Software\BillP Studios
Key Found : [x64] HKLM\SOFTWARE\BillP Studios

I guess I'll try updating to AdwCleaner 3.214 and see if that solves the issue.

Best wishes to Bill P. and the new owner.
"In an age when mass society has rendered obsolete the qualities of individual courage and independent thought, the oceans of the world still remain, vast and uncluttered, beautiful but unforgiving, awaiting those who will not submit. Their voyages are not an escape, but a fulfillment."

~ THE SLOCUM SOCIETY ~

JDBush61

Just an update regarding AdwCleaner / WinPatrol issue. I trashed AdwCleaner 3.213 and downloaded 3.214, and now it does not seem to have the WinPatrol registry key FPs. However, it does flag a new key (which I deleted ... gulp!...), and something related to Firefox (which I also deleted. Also a "gulp!").

I realize that this is a WinPatrol thread, yet if someone would kindly tell me what AdwCleaner found and cleaned it would be greatly appreciated.

AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Users\Administrator Bush\AppData\Roaming\Mozilla\Firefox\Profiles\ywmg8h0l.default\prefs.js ]
"In an age when mass society has rendered obsolete the qualities of individual courage and independent thought, the oceans of the world still remain, vast and uncluttered, beautiful but unforgiving, awaiting those who will not submit. Their voyages are not an escape, but a fulfillment."

~ THE SLOCUM SOCIETY ~

siljaline

Per notes from Corrine:
Quote
-- Launch AdwCleaner and click Tools > Click Quarantine manager.
-- Place a check in the box next to the file(s) to be restored.
-- Click Restore (a logfile will open).

You can also uncheck elements you don't want to remove:

When the scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if you want to keep them. Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked. 

siljaline
MVPS Hosts . MBAM . Why ESET

JDBush61

Quote from: siljaline on July 01, 2014, 04:00:43 AM
Per notes from Corrine:
Quote
-- Launch AdwCleaner and click Tools > Click Quarantine manager.
-- Place a check in the box next to the file(s) to be restored.
-- Click Restore (a logfile will open).

You can also uncheck elements you don't want to remove:

When the scan completes, all elements will be listed in each tab. Findings in the tabs Folders, Files, Shortcuts, Registry, Products and Internet Explorer can be unchecked if you want to keep them. Note: Elements in the Firefox and Chrome folders are viewable but can NOT be unchecked. 

Thanks Siljaline, but I'm still at square one. I followed Corrine's instructions (i.e., Tools > Quarantine manager), and AdwCleaner stated "Quarantine empty".

So back to my original question:

Any idea what AdwCleaner cleaned / did (shown below), and why?

AdwCleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
***** [ Shortcuts ] *****
***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}

***** [ Browsers ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v29.0.1 (en-US)

[ File : C:\Users\Administrator Bush\AppData\Roaming\Mozilla\Firefox\Profiles\ywmg8h0l.default\prefs.js ]
"In an age when mass society has rendered obsolete the qualities of individual courage and independent thought, the oceans of the world still remain, vast and uncluttered, beautiful but unforgiving, awaiting those who will not submit. Their voyages are not an escape, but a fulfillment."

~ THE SLOCUM SOCIETY ~

siljaline

The CLSID - best as I could determine is Skype.
http://www.systemlookup.com/CLSID/66064-skypeieplugin_dll_skypeieplugin4_dll.html
(read full citation before deciding if you want to recover the item)

The Firefox script has been falsely flagged forever but it covers regardless if it's removed.

Please note that I'm not an expert in what the tool can and can't do as I've stopped using it.

siljaline
MVPS Hosts . MBAM . Why ESET