Adware - Pup Optional Superfish

Lately i've been getting ads whenever I press on some series or "play" on Netflix, so I use malwarebytes & ccleaner to remove the adware.

That works for about 1-2 days, and then it returns again. This has been going on for about a month now and it doesn't seem to stop, it returns everytime.

How do I fix this?  :unsure:

If you need any translations just ask  :)



Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-05-2014 02
Ran by marco (administrator) on MARCO-HP on 27-05-2014 19:53:11
Running from C:\Users\marco\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Dutch Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link from any site other than Bleeping Computer is unpermitted or outdated.
  • Launch Malwarebytes' Anti-Malware
  • Go to Update tab and select Check for Updates. If an update is found, it will download and install the latest version.
  • Go to Scanner tab and select Threat Scan, then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer,please do so immediately.
Malwarebytes Anti-Malware



Scan Date: 30-5-2014

Scan Time: 13:25:30


Administrator: Yes



Malware Database: 

Rootkit Database: 

License: Free

Malware Protection: Disabled

Malicious Website Protection: Disabled

Self-protection: Disabled


OS: Windows 7 Service Pack 1

CPU: x64

File System: NTFS

User: marco


Scan Type: Threat Scan

Result: Completed

Objects Scanned: 307245

Time Elapsed: 26 min, 3 sec


Memory: Enabled

Startup: Enabled

Filesystem: Enabled

Archives: Enabled

Rootkits: Disabled


PUP: Warn

PUM: Enabled


Processes: 0

(No malicious items detected)


Modules: 0

(No malicious items detected)


Registry Keys: 0

(No malicious items detected)


Registry Values: 0

(No malicious items detected)


Registry Data: 0

(No malicious items detected)


Folders: 0

(No malicious items detected)


Files: 2

PUP.Optional.Superfish.A, C:\Users\marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage, Delete-on-Reboot, [bbd2c097ef8cb383b94eade508faf60a], 

PUP.Optional.Superfish.A, C:\Users\marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.superfish.com_0.localstorage-journal, Delete-on-Reboot, [612c98bf84f7c67030d7eda516ec48b8], 


Physical Sectors: 0

(No malicious items detected)




Hello, I did another scan because the one I send before was from yesterday, this time it found another PUP called Betterdeals.


Malwarebytes Anti-Malware
Scan Date: 31-5-2014
Scan Time: 19:30:59
Administrator: Yes
Malware Database: v2014.05.31.08
Rootkit Database: v2014.05.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: marco
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 311283
Time Elapsed: 59 min, 52 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 2
PUP.Optional.BetterDeals.A, C:\Users\marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage, Quarantined, [e113a6b1f883b08654f97f0fa35f37c9], 
PUP.Optional.BetterDeals.A, C:\Users\marco\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_static.betterdeals00.betterdeals.co_0.localstorage-journal, Quarantined, [8e665304423986b0d17cc3cb689ad52b], 
Physical Sectors: 0
(No malicious items detected)
Step 1

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 2

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan button. Wait until is finished.
  • Click on Clean.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner\AdwCleaner[s0].txt as well.
In your next reply, post the following log files:
  • Junkware Removal Tool log
  • AdwCleaner log
Ran by marco on zo 01-06-2014 at 15:51:34,47






~~~ Services




~~~ Registry Values




~~~ Registry Keys




~~~ Files




~~~ Folders




~~~ Event Viewer Logs were cleared







Scan was completed on zo 01-06-2014 at 15:55:04,79

End of JRT log

# AdwCleaner v3.211 - Rapport aangemaakt 01/06/2014 op 15:56:25

# Laatste Update 26/05/2014 door Xplode

# Besturingssysteem : Windows 7 Home Premium Service Pack 1 (64 bits)

# Gebruikersnaam : marco - MARCO-HP

# Gestart vanuit : C:\Users\marco\Downloads\AdwCleaner.exe

# Optie : Verwijderen


***** [ Services ] *****



***** [ Bestanden / Mappen ] *****



***** [ Snelkoppelingen ] *****



***** [ Register ] *****


Sleutel Verwijderd : HKCU\Software\AppDataLow\Software


***** [ Browsers ] *****


-\\ Internet Explorer v11.0.9600.17041



-\\ Mozilla Firefox v


[ Bestand : C:\Users\marco\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]



-\\ Google Chrome v


[ Bestand : C:\Users\marco\AppData\Local\Google\Chrome\User Data\Default\preferences ]





AdwCleaner[R4].txt - [1433 octets] - [01/06/2014 15:56:07]

AdwCleaner[s4].txt - [1359 octets] - [01/06/2014 15:56:25]


########## EOF - C:\AdwCleaner\AdwCleaner[s4].txt - [1419 octets] ##########
Please scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.

    ESET OnlineScan

  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer.

      Save it to your Desktop.

    • Double click on the esetsmartinstaller_enu.png to download the ESET Smart Installer. icon on your Desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under Scan Settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
Glad I could help! :)

Step 1

  • Download OTL to your desktop and run it.
  • Click on CleanUp button.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Step 2

Please uninstall ESET Online Scanner .

Step 3

Some malware preventions:


Safe surfing! :)

Link to post
