Jump to content

Potential Unwated Program - pup.optional.candy


Recommended Posts

Hello

 

I am a little confused by pop, Potentially Unwanted Program.  Anti-Malware found several pup's as you can see from the list below.  The strange part all the files identified are uninstalled downloads.  It did not pick up a problem with the download installed only the actual download.  I will probably delete the first and fourth entry because I do not know what they are, that is 4shared_Desktop_3.3.5.exe and Daemon4091-x86.exe, however, the remaining are for a the old and most recent versions of a plugin for Irfanview RIOT, - the plugin is a save for web option that reduces the size of a photo and gives you the option to save it as jpg, png or gif.

 

Why did RIOT, the Irfanview plugin, come up as a potentially unwanted program?

 

Thank you

David

-----------

partial log from Anti-Malware below:

 

Processes: 0

(No malicious items detected)

 

Modules: 0

(No malicious items detected)

 

Registry Keys: 0

(No malicious items detected)

 

Registry Values: 0

(No malicious items detected)

 

Registry Data: 0

(No malicious items detected)

 

Folders: 0

(No malicious items detected)

 

Files: 26

PUP.Optional.4Shared, D:\MyData_All\My Documents\Downloads\Programs\4shared_Desktop_3.3.5.exe, , [6938e5232a51e74fa5b030ee4bb50bf5], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Dowmloads_Win7_PriorToDataMove\Riot_dll.zip, , [ffa2a36519628aaccd4de646d3315fa1], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Dowmloads_Win7_PriorToDataMove\Riot_dll\Riot-plugin.exe, , [a7fa080093e846f0e13928049e668a76], 

Adware.WhenU, D:\MyFolders_All\Downloads_All\Daemon Tools (virtual CD or DVD player)\daemon4091-x86.exe, , [633e7890bdbe44f2aeccd83618ec3bc5], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20110712_SaveForWeb_RIOT Plugin\Riot-plugin.exe, , [604192766516ac8a2ded9d8fe0240af6], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20110712_SaveForWeb_RIOT Plugin\Riot_dll.zip, , [3c65e721df9c1620be5c4ae28f7545bb], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20120405_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [3f62da2ed5a6bb7b98823cf064a0ef11], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20120405_SaveForWeb-RIOT Plugin\Riot_dll.zip, , [3a67ea1e0e6d52e41efc7bb1ea1ac53b], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20130108_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [0e937296344710260f0bb07c0bf9d32d], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20130108_SaveForWeb-RIOT Plugin\Riot_dll.zip, , [91102cdc710a7abc1208aa821ee61ce4], 

PUP.Optional.OpenCandy, D:\MyFolders_All\Downloads_All\Irfanview\20131130_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [732edf29e299a88e150534f88b7904fc], 

PUP.PSWTool.ProductKey, D:\MyFolders_All\Downloads_All\Nirsoft Utilities\produkey.zip, , [dbc6ff09413a171f40e251fb956ba060], 

PUP.PSWTool.ProductKey, D:\MyFolders_All\Downloads_All\Nirsoft Utilities\produkey\ProduKey.exe, , [7c25c93fa1dae05635edf557a75949b7], 

PUP.Optional.4Shared, G:\Sec Copy\MyData_All\My Documents\Downloads\Programs\4shared_Desktop_3.3.5.exe, , [6d3457b1e49777bfb89df22ca25e24dc], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Dowmloads_Win7_PriorToDataMove\Riot_dll.zip, , [1a87d53314670d29c25843e924e01ee2], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Dowmloads_Win7_PriorToDataMove\Riot_dll\Riot-plugin.exe, , [d1d010f87902f640be5c34f8b94b9a66], 

Adware.WhenU, G:\Sec Copy\MyFolders_All\Downloads_All\Daemon Tools (virtual CD or DVD player)\daemon4091-x86.exe, , [178a8682304bcf672951050941c3b34d], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20110712_SaveForWeb_RIOT Plugin\Riot-plugin.exe, , [158cf21685f602347e9cd25a13f146ba], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20110712_SaveForWeb_RIOT Plugin\Riot_dll.zip, , [237eb751ed8efd392cee111bc63e8b75], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20120405_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [0a972bdd3c3f22140f0be5471be916ea], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20120405_SaveForWeb-RIOT Plugin\Riot_dll.zip, , [b0f19c6c403bba7c3bdf9f8dc04402fe], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20130108_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [841d996f512a37fff921a88455aff20e], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20130108_SaveForWeb-RIOT Plugin\Riot_dll.zip, , [9011f117a4d79d99f6240d1f9d67946c], 

PUP.Optional.OpenCandy, G:\Sec Copy\MyFolders_All\Downloads_All\Irfanview\20131130_SaveForWeb-RIOT Plugin\Riot-plugin.exe, , [326f0503ff7ce5511a00989427dd45bb], 

PUP.PSWTool.ProductKey, G:\Sec Copy\MyFolders_All\Downloads_All\Nirsoft Utilities\produkey.zip, , [3170b454d2a99e9866bcaaa2a85848b8], 

PUP.PSWTool.ProductKey, G:\Sec Copy\MyFolders_All\Downloads_All\Nirsoft Utilities\produkey\ProduKey.exe, , [1d84f414afccd66044deaca067990ef2], 

 

Physical Sectors: 0

(No malicious items detected)

 

Link to post
Share on other sites

Hello

 

I apologize but I forgot to mention what the least two files that the last two files, produkey.zip and produkey.exe are the zipped and unzipped program for Nirsoft that finds and lists the product key for some program such as Windows and MS Office.  What did this come up as a pup.

 

 

Do you agree that pup, potentially unwanted program, should not be removed all the time?

 

Thank you

David 

Link to post
Share on other sites

That's why I don't install software with this adware / spyware / malware (or whatever you want to call it) in... I think DAEMON Tools contains this candy pup. Found this crap before and I started checking what I really downloaded, if it has any adware. (For me it's all malware). So if any software has something like this in, I'm not installing it. Even if you don't choose to install any toolbar or adware that comes with it, it makes changes to your registry ( sometime it makes files in your PC) mainly temp, I checked these files, and log of this adware / spyware / malware. And it was sending some data from my PC to them. That PUP.

 

If you just click on this exe, that adware on it create some registry entries and send some info from your PC to them... (At least the one I checked before).

 

Like Ron said, PUP.. pretty much malware.

 

Wanna advice? Try to download portable software, like ImgBurn portable (so you can be sure there's no crap in it, it has adware on it too).

As for DAEMON Tools Lite, I was about to reinstall my system, so what I did, I installed DAEMON once on it, then moved the files from program files to my USB flash drive (so I don't have to download and install DAEMON with that malware in it every time.)

Link to post
Share on other sites

Whoa.

 

just because a software is portable does not mean there is no pups with it.

 

As for Daemon tools, I just bought the Pro Advanced version several years back.  Now, any additional licenses are 8 Euros apiece.  And no crap ware with the installer either.

Link to post
Share on other sites

Actually if I download ImgBurn portable, there's no crap on it, since there's no installer with that crap on it.

DAEMON Tools, I won't have any crap either. SM Player too.

And other softwares I got like that.

 

It's not like I know every single software in the world, I didn't talk about everything too.

 

But sorry for giving him advice how to dodge this stupid adware on installers. ;-)

Link to post
Share on other sites

As far as RIOT is concerned it has Open Candy embedded and that is what is being flagged. When installing a program that includes Open Candy it will scan your PC and then offer other programs that may interest you based on what you have now. 

 

Jim

Link to post
Share on other sites

Hello

 

I would like to take this opportunity to thank everyone who sent a response.   Of particular interest was the response on RIOT Save for Web Plugins for Irfanview.  I will for a similar plugin for IrfanView with the same functionality as RIOT Save for Web plugin.  I was just surprised that some install programs were marked as pup without being installed - some were just in my downloads direction but  never installed.

 

Again, thank you everyone.

 

David

Link to post
Share on other sites

I use IrfanView and out of curiosity I downloaded the RIOT plugin. I then right clicked and scanned the downloaded file with MB and it was flagged for Open Candy. I have NIS and it did not pickup on this when it was scanned during download. So I will now be using MB to scan all my downloaded files to catch these PUPs that Norton misses. Thanks MB for your upgraded PUP policy.

 

Jim

Link to post
Share on other sites

That's because the installer for said plugins is probably what contained the PUP

 

Wow!   That's news to me.   Thank you for that, because I have used FileHippo.com for good free programs for years, being a pensioner.   But of late I have found many of my downloaded program updates, on opening and viewing the EULA, to include embedded horrors like Open Candy, Ask Toolbar, Conduit, Delta Search etc. Uncheky deals with the pre-ticked ones, but I immediately decline any install containing Pups embedded  in the EULA, and uninstall the old version of the program - and good riddance.   But now, what  I learn from you is that it may be too late. But then, you refer to plugins only.   Your warning does not seem to apply to programs as well. Just a point of interest you may want to elaborate on for us? 

 

MBAM, which has always spotted PUPS I have downloaded accidentally, but has never shown any PUPs being installed from declined downloads - as far as I,m aware.   I cannot be sure about this.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.