Just Got A Frightening Popup From Winpatrol

Discussion in 'Software' started by Jesse Newell, Dec 28, 2017.

  1. Jesse Newell

    Jesse Newell MajorGeek

    Capture.PNG

    Any ideas what this could mean? I'm really frightened by it. I just saw an even more frightening window pop up just behind it.

    Capture2.PNG

    This window MAY have popped up because I MAY have accidentally clicked a button in the first window without realising it while moving the first window out of my way. But I'm really terrified as to what's suddenly happening. Someone please help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should have clicked reject change.
     
  3. Jesse Newell

    Jesse Newell MajorGeek

    I'm still pretty certain I didn't click accept change. I just clicked and held the top of the window a few times to move it out of my way. What should I do now? Both windows are still on screen by the way, in case you think that I clicked accept change accidentally and the second window popped up. No. The second window popped up behind the first one but the first one didn't disappear. Presumably, if I had clicked something, it would have. So I'm inferring from the fact it hasn't that I didn't actually click anything after all.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then click reject!!
     
  5. Jesse Newell

    Jesse Newell MajorGeek

    Sorry for taking so long. I just did click reject but the restart now or later window is still showing. That didn't go away.

    EDIT: And now I just got another WinPatrol alert.

    Capture.PNG
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Can't you close the pop-up window by clicking on the X? Then - click "Reject change" on the WinPatrol pane.
     
  7. Jesse Newell

    Jesse Newell MajorGeek

    The WinPatrol alert or the one that says restore now or later?
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    "Restart now or later".... close that
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you signed up for any streaming service like netflix or amazon?
     
  10. Jesse Newell

    Jesse Newell MajorGeek

    OK, just did. But will that matter? Doesn't that kind of window only pop up when you have made some kind of change that will take effect the next time the computer restarts regardless of whether you click now, later or the x?
     
  11. Jesse Newell

    Jesse Newell MajorGeek

    Well I've had a Netflix account for a year or two now. Sometimes I watch Netflix on my computer but mostly on television. Don't see what could have affected that. And I did get an Amazon Echo for christmas but I haven't plugged it in yet or downloaded the Alexa app.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suspect that is what the warning is about. What happens when you click on Plus info?
     
  13. Jesse Newell

    Jesse Newell MajorGeek

    Just an "oops, this page could not be found." You mean you think this has to do with Alexa? But, like I said, I haven't downloaded Alexa yet, and I haven't even tried to plug in the Echo yet. So how could either of them be affecting my computer when I haven't gone near them yet?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Netflix.
     
  15. Jesse Newell

    Jesse Newell MajorGeek

    Oh, OK. What could have affected it then, or what could it be doing? I wasn't watching Netflix on my computer at the time, or trying to. So what do you think might be happening? And what should I do about this,

    Capture.PNG ?
     
  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    "This partner program needs to be killed...etc"
    Open WinPatrol and look for any new startups that have been detected/added/modified. Research any you don't recognize.
     
  17. Jesse Newell

    Jesse Newell MajorGeek

    The only one that really stands out is something called ASYNCMAC because I see the word asyncmac in that WinPatrol alert window.

    This is the first link that came up when I Googled asyncmac,

    https://www.file.net/process/asyncmac.sys.html
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  19. Jesse Newell

    Jesse Newell MajorGeek

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes.
     
    dr.moriarty likes this.
  21. Jesse Newell

    Jesse Newell MajorGeek

    OK, done, will try not to worry about it from now on unless something else happens. Thought it was a huge malware attack when it first happened.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That's why I don't use WinPatrol.
     
  23. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    https://www.howtogeek.com/212494/how-to-use-winpatrol-to-monitor-your-system-for-any-changes/
    *Emphasis on ANY changes...
     
  24. Jesse Newell

    Jesse Newell MajorGeek

  25. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Thought about applications that auto-update? Programs that look for driver updates?
     
    Last edited: Dec 28, 2017
  26. Jesse Newell

    Jesse Newell MajorGeek

    Thanks. Not too concerned about it anymore, then. As long as it's not a virus or something. That's all that'd really worry me. I'll run Malwarebytes later and if that says I'm clear, I'll just forget about it.
     
  27. AtlBo

    AtlBo Major Geek Extraordinaire

    Found a pretty good bit about this. Here is a link at Wilder's (start with Krusty post #14738):

    https://www.wilderssecurity.com/threads/voodooshield.313706/page-590

    In this thread the same key reference shows up under the Registry (Whitelisted) heading in the Farbar scan results in the original poster's first post. It's whitelisted by Farbar. Additionally, in the Malwarebytes scan that follows it's not listed as anything malicious or sketchy, although five other keys are mentioned. Thread:

    https://forums.malwarebytes.com/topic/158485-malwarebytes-repeatedly-finds-pupoptionalmultiplug/

    Here is another. Post #3 in the Farbar scan result again under Registry (Whitelisted):

    https://www.bleepingcomputer.com/forums/t/590568/persistent-adware-and-malware/

    Seems to show up frequently Farbar whitelist in scans.
     
  28. Jesse Newell

    Jesse Newell MajorGeek

    Thanks! I ran Malwarebytes a half hour ago. Fully updated version and scanned for rootkits. It found absolutely nothing. Then I restarted the computer, and found out why I got that dialog box earlier that said I must restart my computer to apply "these changes".

    Capture.PNG
     
    AtlBo likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds