MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 11-16-08, 11:19
Deak689 Deak689 is offline
Private E-2
 
Join Date: Nov 2008
Posts: 4
Thanks: 3
Thanked 0 Times in 0 Posts
Default Generic PUP.z removal

First of all, thank you to all of the people associated with creating and maintaining this web resource site... I have truely found it valuable since only registering yesterday!

Started out by seeking how to remove "Generic PUP.z" which my McAfee would attemt to remove, but could only partially remove and continued to show up in every scan while posting a directory path in the results which I could not manually locate.

Have follow all of the steps for "Vista Cleaning Procedure"

Also, DVD writer and cdrom device drivers have become corrupted, which may or may not be due to "Generic PUP.z?"
Attached Files
File Type: txt SASLog - 11-16-2008 - 08-26-20.txt (465 Bytes, 29 views)
File Type: txt mbam-log-2008-11-16 (09-33-53).txt (1.4 KB, 16 views)
File Type: zip MGlogs.zip (153.9 KB, 9 views)
Reply With Quote
Sponsored links
  #2  
Old 11-19-08, 00:05
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,123
Thanks: 61
Thanked 7,566 Times in 4,067 Posts
Default Re: Generic PUP.z removal

Welcome to Major Geeks!

Please attach the requested C:\ComboFix.txt log.

Quote:
Originally Posted by Deak689 View Post
Started out by seeking how to remove "Generic PUP.z" which my McAfee would attemt to remove, but could only partially remove and continued to show up in every scan while posting a directory path in the results which I could not manually locate.
You need to tell us exactly where it is being found. What file and what folder?

Your logs are clean.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
The Following User Says Thank You to chaslang For This Useful Post:
Deak689 (12-19-08)
  #3  
Old 12-05-08, 06:39
Deak689 Deak689 is offline
Private E-2
 
Join Date: Nov 2008
Posts: 4
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Generic PUP.z removal

Here is the filepath that McAfee is detecting the pup in:

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1XHZX0B\upgrade[1].cab


Thank you!
Attached Files
File Type: txt ComboFix.txt (20.1 KB, 10 views)
Reply With Quote
  #4  
Old 12-06-08, 15:16
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,123
Thanks: 61
Thanked 7,566 Times in 4,067 Posts
Default Re: Generic PUP.z removal

Quote:
Originally Posted by Deak689 View Post
Here is the filepath that McAfee is detecting the pup in:

C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1XHZX0B\upgrade[1].cab
It is just a temporary internet file from browsing. You can easily just delete it yourself or you can empty your browser cache.

To flush your Internet Explorer Cache:
  • click Tools
  • Internet Options
  • Now on the General tab and click Delete Files and select Delete all Offline content too
  • Click OK.
  • When it finishes Click OK.

Your logs are basically clean. We just have some minor details to take care of.

Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

After clicking Fix, exit HJT.

Now run Ccleaner!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

Then attach the below log:
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
The Following User Says Thank You to chaslang For This Useful Post:
Deak689 (12-19-08)
  #5  
Old 12-12-08, 18:00
Deak689 Deak689 is offline
Private E-2
 
Join Date: Nov 2008
Posts: 4
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Generic PUP.z removal

System appears to be performing normal except for the continued detection of "generic pup.z" by McAfee scan at the exact same previously posted filepath.
Attached Files
File Type: zip MGlogs.zip (157.7 KB, 15 views)
Reply With Quote
Sponsored links
  #6  
Old 12-15-08, 00:09
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,123
Thanks: 61
Thanked 7,566 Times in 4,067 Posts
Default Re: Generic PUP.z removal

You did not allow the GetLogs.bat program to run thru to completion or you allowed McAfee to get in the way of it running. Disable McAfee and do all of the below.


Now download The Avenger by Swandog46, and save it to your Desktop.
  • Extract avenger.exe from the Zip file and save it to your desktop
  • Run avenger.exe by double-clicking on it.
  • Do not change any check box options!!
  • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
Quote:
Folders to delete:
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U1XHZX0B
  • Now click the Execute button.
  • Click Yes to the prompt to confirm you want to execute.
  • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
  • Your PC should reboot, if not, reboot it yourself.
  • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
Now run Ccleaner!

Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).


Then attach the below logs:
  • C:\avenger.txt
  • C:\MGlogs.zip
Make sure you tell me how things are working now!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
The Following User Says Thank You to chaslang For This Useful Post:
Deak689 (12-19-08)
  #7  
Old 12-19-08, 12:30
Deak689 Deak689 is offline
Private E-2
 
Join Date: Nov 2008
Posts: 4
Thanks: 3
Thanked 0 Times in 0 Posts
Default Re: Generic PUP.z removal

System is running fine.

Running manual scan with McAfee to see if "Generic Pup.z" is still detected.

Will post McAfee scan results.

TY
Attached Files
File Type: txt avenger.txt (1.2 KB, 9 views)
File Type: zip MGlogs.zip (160.0 KB, 20 views)
Reply With Quote
  #8  
Old 12-22-08, 00:13
chaslang's Avatar
chaslang chaslang is offline
MajorGeeks Admin - Master Malware Expert
 
Join Date: Feb 2004
Location: Northern New Jersey USA
Posts: 80,123
Thanks: 61
Thanked 7,566 Times in 4,067 Posts
Default Re: Generic PUP.z removal

Your MGlogs.zip file is still not updated properly. You need to stop McAfee as it is probably getting in the way. The delete the current C:\MGlogs.zip file. Now download the current version of MGtools from here MGtools.exe Then make sure that you have UAC disabled as mentioned in the READ & RUN ME. If it is not disabled, you will have to disable it and then you must reboot. Now right click on the MGtools.exe that you just downloaded and select Run As Administrator. Make sure you let it finish running and do not let McAfee block anything from running. Then attach the new C:\MGlogs.zip file.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't."


Support Majorgeeks on Facebook:

Majorgeeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
generic.dx system 32 start removal process nitma Malware Removal 1 10-11-08 16:25
generic.dx trojan removal help chitra Malware Removal 2 11-19-07 03:34
At a loss. New at this, but did all the basics and generic HSA removal finnman Malware Removal 17 04-07-05 13:36
Media Player not working in IE after Generic HSA removal buzzsaw Malware Removal 3 03-29-05 09:04


All times are GMT -5. The time now is 19:30.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger