Clearing Pup.optional.ask

Discussion in 'Malware Help (A Specialist Will Reply)' started by Topspeed, May 5, 2019.

  1. Topspeed

    Topspeed Private E-2

    Malwarebytes is not removing PUP.Ooptional.Ask. The two threats found would come back after they have been quarantined and deleted. All 5 required files are attached. Please help me clear the threats found. Thank you.

    P.S. After AdwCleaner deleted registry keys, Windows Explorer and Word 2013 would hang non-stop. I spent over a day doing repeated rebooting to fix the repeated non-responding hanging Windows Explorer and Word. End Task and Restarting File Explorer through Task Manager and rebooting latptop didn't fix the problem. I couldn't continue with the cleaning/removal procedure until I have working File Explorer and Word. I looked around Windows Security and Maintenance log and researched for a fix. I didn't want to restore system files because 1) AdwCleaner deleted registry keys looked legit. 2) I didn't want to mess with Malwarebytes Premium Trial in progress. 3) The other suspect is "WWA Host Stopped Working", but it happened long before the hanging non-responsive Windows Explorer and symptoms immediately after AdwCleaner removed the 5 threats. Luckily somehow the non-stop cycle of non-responding File Explorer and Word mysteriously stopped this morning on their own without any fix being done. Windows Explorer and Word are working for now, but is "WWA Host Stopped Working" related to any threat removed and found and how should I fix it?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You took no action when you ran MBAM to remove the two Ask items. Please do that now, reboot and rescan with MBAM....
    Run one more scan:
    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.

    Now :
    1. Hit the Windows Start button
    2. In the search box, type "cmd" but DO NOT PRESS "ENTER".
    3. Press and hold "CTRL-Shift" on your keyboard while pressing "ENTER".
    4. You'll be prompted with a permission dialog box.
    5. In the box, click "YES".
    6. You should have a black screen with a blinking cursor.
    7. In that black screen, type "sfc /scannow" and hit "ENTER".
    8. SFC will begin scanning for WWAHost.exe issues and any other system file problems.
    9. Follow any on-screen commands to complete the process.
    Please be aware that this scan might take a while, so please be patient while it is working.

    Please attach the two new logs when it is finished.
     
  3. Topspeed

    Topspeed Private E-2

    Hi Tim,

    Thanks for your instructions early yesterday morning. It took me a whole day just to complete the two simple scans because I got stuck with “not responding” Word and Windows 10 File Explorer again. I couldn’t run the Malwarebytes and Zemana scans because the computer was not able to save documents in Word or Excel. When I hit save, Word or Excel and then File Explorer would freeze and not respond and I lose data. Windows 10 seems unable to multitask (can’t process even just one program either Word or Excel) and its booting and shutting and processing speeds are unusually slow worse now than after I started the cleaning process with Malwarebytes and AdwCleaner when Word and File Explorer would hang. I could not save document files (lost data several times and a lot of time). Restart would hang and Shut Down didn’t even respond properly earlier in the evening and again this morning. Shut Down took a good 3 minute delay to respond and because the delayed processing response didn’t have the usual turning circle to show Windows is processing a command and so Windows was shutting down in the midst of me navigating and commanding the laptop to do other things causing loss data and total chaos and confusion. In short, the tasks of saving data and Restart and Shut Down are totally hit and miss and unreliable. Malwarebytes also seemed to take a lot longer to finish today than yesterday: 1 hr 40 min yesterday vs 20 min 2 days ago.

    This morning starting fresh I tested and attempted to repeat scanning the system, but Shut Down failed for the first time and Restart (and the lock screen) were either not responding or taking longer than usual. The Restart problem obviously worse than yesterday and I had to do a hard shown down from the power button a couple of times.

    Through the forced shut downs this morning, the AMD USB 3.0 eXtensible Host Controller- 1.0 (Microsoft) incurred error. I had to uninstall the USB controller and reboot the laptop to restore its function. The USB port error is also another recurrent problem that started as I started the cleaning and removal process.

    Scandisk found no error both times when I ran it on Saturday through Windows 10 File Explorer to fix the slow and non-responsive system and possibly the “WWAHost Stopped Working” issue after running AdwCleaner and again on Sunday through the command prompt as directed by you. The result of the disk scan from yesterday at the command prompt: “Windows Resource Protection did not find any integrity violations.” I did not run Windows scandisk after the hard shut down this morning. Should I?

    In looking through Task Manager, I found several background processes that were opening and suspending on their own and using memory. I click on End Task to close many of them, but several of them will revert themselves back to run and being suspended, namely Cortana, YahooMail and Windows Shell Experience and there were other different process. These automated suspended processes may be there by design but with the exception of YahooMail, I do not use Cortana (other than Search) or have not even touched Skype and there were other changing program processes in suspension that I don’t use. I don’t know what Windows Shell Experience is. Perhaps you know what to make of this as to restore processing speed and security. Are these processes causing program conflict and causing “WWAHost Stopped Working,” Windows not multi-tasking and Word and File Explorer to hang? I have included a brief note with a print screen of two sample suspended processes: Cortana and Windows Skype.

    With respect to removing PUP, I did quarantine and delete the two Ask files after I exported the Malwarebytes report and so the report didn’t show I quarantined them. I guess I should have exported the text file after I quarantined the two files, so you would see the files were quarantined.

    Zemana Anti-malware found the system to be clean yesterday and this morning after reboot (I may not have opened Google Chrome before I ran Zemana like I did with Malwarebytes).

    These PUP files are repopulating themselves after I opened Google Chrome and rebooted the laptop. I ran Malwarebytes scan (and Zemana) this morning again after I rebooted and opened Google Chrome, and it detected the two Ask files that were quarantined and deleted previously.


    Total of Five Files Uploaded: 2 Print Screens of Automated Suspended Background Processes in Task Manager, Zemana scan log and 2 Malwarebytes scan logs

     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your issues are not malware related. You are having system issues and should pursue them in the software forum.
    To make sure ASK is gone, please reset Chrome to defaults:
    Reset Chrome to Defaults

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     
  5. Topspeed

    Topspeed Private E-2

    Resetting Chrome to default didn’t do it. After I rebooted the laptop, opened (default) Google Chrome and run Malwarebytes, the scan found the two Ask files.

    Questions:

    1) Am I right that no action is needed on the 2 registry keys and the PUP.AutoIt.Gen files found by RogueKiller on 5/5?


    2) Do you have an issue of me running Junkware Removal Tool and trying the steps listed in this link to remove the two Ask files https://forums.majorgeeks.com/threa...low-and-found-some-stuff.283589/#post-1859111
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can run it, thought it is no longer supported.
    Try this:
    Download ZHPCleanerto your desktop.

    Close all applications (including your web browsers and antivirus)
    Double-click on ZHPCleaner to run the tool.
    If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    Please click the "J'accepte/I agree" button.
    First press the "Scanner" button. Be patient, the scan may take some time.
    Do NOT fix/repair anything yet! Please upload that logfile also with your next reply.
     
  7. Topspeed

    Topspeed Private E-2

    DHPCleaner installer is asking for "Try recommended settings or Troubleshoot program" Which option should I choose? See attached print screen.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you right click it and choose to Run as Administrator? The notice you got should not have happened...but if you can't get it to run normally, choose recommended settings.
     
  9. Topspeed

    Topspeed Private E-2

    Good Morning. I ran as Administrator when I got the dialogue box.

    I just tried running it and downloading the .exe file twice this morning after getting your go-ahead and both times it tells me version 2019.3.1.27 is out of date and please to download a new version on https://nicolascoolman.eu/. The free version posted on the site is version: 2018. Should I do it?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. Topspeed

    Topspeed Private E-2

  12. Topspeed

    Topspeed Private E-2

    Actually, if you could make sense of the discussions, perhaps you can target or confirm the steps relevant to my case.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go for it.
     
  14. Topspeed

    Topspeed Private E-2

    Score! Removing the Ask Search engine (and other search engines) from Chrome as described in the steps found in the posted malwarebytes forum link seems to have stopped the detection of the two ASK files. I rebooted the laptop, opened Chrome and ran Malwarebytes and repeated the steps a few times and Malwarebytes is showing zero detection. AdwCleaner, Malwarebytes, Zemana, and Hitmanpro all showed zero threat, but RogueKiller scan is still detecting the same 3 threats, however. Are they false positives to be ignored? Is the system clean and ready for the final steps of removing the cleaning/removal programs? Thanks for your help.
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know...yes, you can ignore the RogueKiller report.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds