dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
30883
share rss forum feed


lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne

1 edit

Is 'Optimum Installer' Adware or Malware?

I have a Win 7 Home Premium laptop PC that I barely use, and am very careful where I go. Just out of habit, I ran Malwarebytes and SAS. Malwarebytes found nothing, and SAS just found some benign tracking cookies.

Then, I decided to also run Spybot Search and Destroy. It found 1 entry of 'Optimum Installer' which it would not delete.

After doing a little research, it seems that 'Optimum Installer' is probably Adware. Any thoughts? If I need to go to Security Cleanup, I will, but I want to make sure that it is needed before I do so. Thanks.

Edit: I want to manually remove it, but haven't found directions yet that I can follow or rely on. Oh, Avast found nothing.



TonyKlein
Premium
join:2001-07-02
Netherlands

1 recommendation

It's adware, an iBryte variant.

Here's the VT report of a file I uploaded a few days ago

(url: hxxp://install.optimum-installer.com/o/*******/Groove*****.exe)

»www.virustotal.com/file/a2b4625c···5331579/


lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1

Thanks. I also checked with VT. Has anyone manually removed it? If so, can you post a link?



TonyKlein
Premium
join:2001-07-02
Netherlands

It's best to post in "Security Cleanup", as there's no way to tell from here whether it came accompanied by, or dropped other adware



lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne

said by TonyKlein:

It's best to post in "Security Cleanup", as there's no way to tell from here whether it came accompanied by, or dropped other adware

Thanks, I will.


TonyKlein
Premium
join:2001-07-02
Netherlands

np, you're very welcome



lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne
reply to lordpuffer

In case others find this adware with Spybot, I posted the question about it in the Spybot Forum here:

»forums.spybot.info/showthread.php?t=67300

It looks like it may be a False Positive. I'm going to post it to the Spybot False Positive Forum this weekend.



TonyKlein
Premium
join:2001-07-02
Netherlands

Based on the location and file type of the item SpyBot detected it is very likely to be a FP indeed.

Why not open the file with Notepad and have a look? That should already give you an idea of its origins or nature



lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne

said by TonyKlein:

Based on the location and file type of the item SpyBot detected it is very likely to be a FP indeed.

Why not open the file with Notepad and have a look? That should already give you an idea of its origins or nature

I looked at the Spybot log and it looks to me like it may be mistaking the Google Toolbar as 'Optimum Installer'.


TonyKlein
Premium
join:2001-07-02
Netherlands

Certainly looks like it



lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne
reply to lordpuffer

Re: Is 'Optimum Installer' Adware or Malware? (SOLVED)

Solved the issue. I have been using my Macs most of the time, so I forgot this. I ran across this thread in the Spybot Forum:

»forums.spybot.info/showthread.php?t=67295

I ran Spybot as Administrator (by right-clicking the icon and choosing 'Run As Administrator'). It found the adware and removed it. Shut down, restarted, ran Spybot again, and nothing. So I'm clean with Spybot, MBAM, SAS and Avast. I'm going to take that as a clean bill of health.



Lazer

@bellsouth.net
reply to lordpuffer

Re: Is 'Optimum Installer' Adware or Malware?

I ran Spybot Search and Destroy in Safe Mode and was able to delete it



lordpuffer
Comfortably Numb
Premium
join:2004-09-19
Rio Rancho, NM
kudos:1
Reviews:
·CableOne

said by Lazer :

I ran Spybot Search and Destroy in Safe Mode and was able to delete it

It was determined by Spybot S&D that it is a False Positive:

»forums.spybot.info/showthread.php?t=67308

However, deleting it should do no harm. The Google Toolbar for IE may not work properly if you delete it, but you can always uninstall it and then reinstall it again.