seeking info about generic pup.z

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aroidgrower, Mar 12, 2009.

  1. aroidgrower

    aroidgrower Private E-2

    I have read through the removal steps for the generic pup.z trouble and still have some questions.

    Like others I have located the *.cab files in the Temparary Internet Files directory running V13.3 of McAfee virus scan. The system is running Vista and the browser version is 5.?

    I was unaware of the ability for internet explorer to remove these files properly, so I manually deleted them only for them to show up again during future virus scans.

    Can you please explain in detail what steps to take from here.

    I also have one related question about my original attempt to manually delete these *.cab files that McAfee told me contained the generic pup.z.

    This is the first time I attempted to do this type of manual operation on a machine running Vista( in the past I have only used this technique with success On machines running XP. ). In the process of using windows explorer to navigate to the directory containing the *.cab files I did something that resulted in 2 desktop.* files being visible on the desktop( I assume desktop.ini and desktop.* ). How do I make these two files hidden using Vista? It has been 2 years since I worked on a PC and I am very rusty.
    I remember enough not to trash the system but don't remember enough to undo what should be very obvious to me. I was considering just deleting them and allowing them to be re-created during the next re-boot but didn't know for sure if this would make the system unstable.

    Thank you for any advice you wish to offer me.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    We don't have instructions on our site for this since it is really not a problem. PUP = Potentially Unwanted Program and may well be something you are downloading/installing. And if it keeps appearing in the TIF folder it is due to the websites you are accessing and again may not be a problem esepcially if you know what the files are from. Anything can be called a PUP. We could even classify McAfee as a PUP too. ;)

    Not a chance!! There is no way you are running IE version 5. If you have Vista, you have at least IE7.


    Having multiple Desktop.ini files appear is not a problem. It is just due to enabling viewing of hidden files. You have on that is really in the All Users Desktop folder and it is now also showing on your Desktop along with the real one from your Desktop.


    If you wish to properly check your PC for malware then follow the below instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First.
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. aroidgrower

    aroidgrower Private E-2

    Thank you.

    I have uploaded 3 log files.

    If I missed any please let me know.

    I will re-read all of the instructions to make sure I ran everything properly.

    In the process of running everything there was 22 malware programs found and removed and 200 registry entries fixed.

    This computer belongs to a friend, so I will take it back to her and ask her to connect to the internet to see if everything works for her. I will also ask her to make sure the original problems she had experienced are fixed.

    I have included the detailed instructions from MajorGeeks.com on how to avoid malware in the first place and placed all of this information on her desktop as well as all downloaded application files and instructions on a CD for her.

    While she checks out her system for functionality I will await your report on the log files I sent you.

    Thank you so much for your help!

    Aroidgrower
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You forgot to uninstall Ask Toolbar and Viewpoint Media Player in step 1 of the READ & RUN ME. Uninstall them now.

    Also you did not uninstall the 3 old Sun Java versions and install the new version which was also requested in step 1. The below are the old versions to uninstall:
    J2SE Runtime Environment 5.0 Update 3
    Java(TM) 6 Update 11"
    Java(TM) 6 Update 3


    There should be 4 logs. You skipped ComboFix and it needed to be run before MGtools. So you will have to rerun MGtools after following the procedure for ComboFix.
     
  5. aroidgrower

    aroidgrower Private E-2

    Thank you chaslang for your help. I added a brief explanation below of what I did and also a few questions about the risk of leaving the machine as is.


     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they have nothing to do with Vista.

    Yes they are in add/remove programs.

    The old versions are major security risks and frequently are reasons why people get Vundo infections. The update from verion 6 update 11 to version 6 update 12 is not as critical. But the J2SE Runtime Environment 5.0 Update 3 and Java(TM) 6 Update 3 versions need to be removed asap.


    If you ran ComboFix, the log would be C:\combofix.txt; however I can tell from your MGtools log that ComboFix was not run. It was not even downloaded. At least not to the Desktop which is required.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds