Reoccurring PUPs, false positive or Webroot not picking anything up?

  • 14 December 2016
  • 2 replies
  • 102 views

Yesterday I ran a typical scan from Malwarebytes, and 3 PUPs were picked up by it labeled as "PUP.Optional.Gameo".  These consisted of a file, folder, and a registry key associated with something called "GoldenGate", and as far as I know I have no apps or programs associated with it.  Webroot had not detected them or alerted me yet.
 
After deleting them and restarting the computer, Malwarebytes detected the same 3 files again.  Webroot did not detect them again.  I even did a direct scan on the file and folder with Webroot and they came away clean.  Could these be false positives from Malwarebytes or is Webroot not detecting anything on its end?

2 replies

Userlevel 7
Badge +54
Welcome to the Community @
 
Different vendors have slight differences in how they classify PUP's which may go some way to explain why it was not picked up by Webroot.
 
However I would contact Webroot to and have them check your computer to make sure that all is fine.
 
This service is free to all current subscription holders, you can contact them here - Webroot Support.
Hi Dirtydeeds,
 
Welcome to the Webroot Community.
 
In addition to the info Jasper has provided I wanted to add some info regarding PUAs/PUPs.
 
PUAs are very annoying at best in that they cause pop-us, redirect your browser home page, and other behavior that may slow down the computer and direct ads your way, but they are not actually doing anything bad like damaging files or stealing information. Often they are installed intentionally by you the user as browser add-ons for various tasks such as quick search tools.. but they also come with the result of added annoying pop-ups and ads. Other times they 'piggy back' with other software that you installed, or try to 'sneak' onto your system entirely.
 
WSA does detect and remove many PUA's, and more are being added, but WSA does not detect all of them. A simple browser add-on with PUA behavior that is easy to identify and easy to remove is not likely to be detected and removed by WSA. Those that are intentionally difficult to locate and remove are. Please see THIS LINK for more information regarding Webroot's stance on these annoying programs.
 
For those that are not detected by WSA, please see this KB Article. It has some easy to follow directions on locating and removing PUA's. You may also want to submit a Trouble Ticket, especially if you cannot remove it easily from the directions in the KB Article.
 
For those that ARE detected by WSA, but cannot be removed automatically, you can submit a Trouble Ticket.  Webroot Support will help you get these annoying 'crapware' off your computer at no extra charge, and the additional examples may help to better automatic removal of that particular PUA for all users in the future.
 
To make sure that your WSA is checking for PUA's with the best proficiently, it sometimes helps to reset the PUA detection within WSA's settings. For PUA's that had previously been scanned and determined to be OK, but have since been added to detection/removal, you may want to complete the following steps:
 
  • Open Webroot SecureAnywhere
  • Click on ‘Advanced Settings’ from the top right
  • Select ‘Scan Settings’ from the left side
  • Unselect the option “Detect Potentially Unwanted Applications”
  • Click on the Save button (you may have to enter in a CAPTCHA)
  • Reselect the option to “Detect Potentially Unwanted Applications”
  • Click on the Save button
  • Run another scan with Webroot and remove any items that get detected.
To help avoid PUA's in the future, remember to read all of the information when installing or updating software (Adobe downloads often have those "extra special offers"attached... PUA'S!: often the PUA included will be mentioned, and you can opt out of installing it.  Those check boxes you see? Usually only one of them is for the User Agreement of the software you want, the others are for the junk you don't.
 
 
NOTE: As noted above, PUA's that:
 
  • Come in with other downloads
  • Have a clear opt out ability prior to install
 
are often NOT detected and removed.  This is partly for legal reasons: the source of the download can complain about it's extra software being blocked automatically by Webroot.  Many users would like a way to allow WSA to recognize and block a LOT more PUA's than it currently can.  Please see THIS IDEA for more information, and give a KUDO if you agree.  User Idea requests are noted by the Webroot Team, and the more Kudo's on an Idea the more likely we may see dev time devoted to it.
 
 
 
Hope this info helps,

 
BD

Reply