Jump to content
klauwkikker

These items are removed by adwcleaer. What are they

Recommended Posts

What are these? Malwarebytes antimalware didn't flag them. Only adwcleaner did.

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP-NoScope

Share this post


Link to post
Share on other sites

***This is an automated reply***

Hi,

Thanks for posting in the AdwCleaner Help forum.

Someone will reply shortly, but in the meantime here are a few resources which may help resolve your issue:

Thanks in advance for your patience.

-The Malwarebytes Forum Team

Share this post


Link to post
Share on other sites

I have restored this two items from quarantaine and did an new scan and now adwcleaner found nothing.

False postive? Kind if I get a answere

Share this post


Link to post
Share on other sites

got those on 2 computers aswell
5days ago i didnt have them,didnt instal or update anything now i got them on both pc's
what are they? or a false positive?

to restore or not to restore?

Share this post


Link to post
Share on other sites
13 minutes ago, klauwkikker said:

I have restored this two items from quarantaine and did an new scan and now adwcleaner found nothing.

False postive? Kind if I get a answere

I have the same issue. Recently I ran a Adw Scan and the following was detected.

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP-NoScope

Not sure if it's false positive.

Please assist.

Thanks

Share this post


Link to post
Share on other sites

Zani and Fleks,

I did restore the two items from quarantaine and did a clean install of adwcleaner and now adwcleaner found nothing. So i quess they were false positives.

But I like als a answer from the staff.

Share this post


Link to post
Share on other sites

well i just tried a bit
if you restore them then restart the pc and scan after that again then adwcleaner wont find these 2 aswell so  im not sure
(if you just restore them without restarting before the next scan,then adwcleaner will detect them again and report it.)

so i suppose you restarted after restoring them and thats why they are not found (not because you re downloaded adwcleaner) - true?

 

because adwcleaner has not been updated since my last installation(installed 7.6 and last update was 6.6) so i doubt that a new install fixed it and just assume you did a restart in between aswell which results in the two not being detected anymore

 

ill just guess this is a false positive that got "enabled" with the last windows updates - because they were exactly between the time of 6.6 and today
and atleast for me thats the only thing i changed on my system OR downloaded

Edited by fleks717

Share this post


Link to post
Share on other sites

Fleks717,

I did not restarted the pc. i have used the option remove adwcleaner in options and reinstalled it.

Share this post


Link to post
Share on other sites

i see
but wel as i said restoring -> restart -> scan again does not detect them either so as i said above i expect it to be a false positive
i jusst dont know if you should restore them or not IF theyre still in quarantine (my case for example)

Share this post


Link to post
Share on other sites

Fleks717,

In youre case i restore the two items and wait for a answer. I advise you to not delete them from quarantaine. I think it is a false positive.

Hopefully we get a answer soone.

Share this post


Link to post
Share on other sites

i will just let them sit there for now and wait as my pc works fine without restoring them i dont need to take "the risk" to restore them in case it isnt a false positive (but im fairly certain it is.)
now we can only wait

Share this post


Link to post
Share on other sites

Hello,

Sorry for the delay. We're investigating why this is occurring and I'll get back to you very soon.

You can ignore or let this detection in quarantine until then.

Share this post


Link to post
Share on other sites

I have it as well as 13 other issues found by adwcleaner. My computer memory was maxing out at 97% with nothing open so I started scanning. I scan regular and I have corporate Kaspersky on my computer as I work from home through a vpn and nothing was detected there. Came across this. Ill check back soon. 

 

Edited by HopeElease

Share this post


Link to post
Share on other sites
1 hour ago, fr33tux said:

Hello,

Sorry for the delay. We're investigating why this is occurring and I'll get back to you very soon.

You can ignore or let this detection in quarantine until then.

thanks for the answer,ill let it stay in the quarantine until then.
i use 3 pcs in my household and all 3 had it occur so it is indeed kinda weird. (but they all had a windows update between this new adw release and it being detected,so as stated above maybe the new windows updates enabled this false posivite because it didnt get detected before the windows update.)

what is the thing detected if one may ask? 
appreciated.

Edited by fleks717

Share this post


Link to post
Share on other sites
13 hours ago, fr33tux said:

Hello,

Sorry for the delay. We're investigating why this is occurring and I'll get back to you very soon.

You can ignore or let this detection in quarantine until then.

Hi. I don't know if this helps or not, but it seems to flag on W10 v1803, and not on W10 v1709, even though the registry entries are indeed present in v1709.

Share this post


Link to post
Share on other sites

Can you share me the whole AdwCleaner logfile showing this detection? (from C:\AdwCleaner\Logs).

Thanks,

Share this post


Link to post
Share on other sites
19 hours ago, klauwkikker said:

What are these? Malwarebytes antimalware didn't flag them. Only adwcleaner did.

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP-NoScope

hi ;) i update my drivers here
https://www.driverscloud.com/

but the old site

https://www.touslesdrivers.com/index.php?v_page=29

if you insttal this appp to found your drivers
                Mes_Drivers_3.0.4.exe
 

in adwcleaner 

adware.agent

***** [ Registry ] *****

Adware.Agent                    HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP
Adware.Agent                    HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP-NoScope

 

 

I uninstalled malwarebytes (license ran out) but the other years I remembered it, it always detected and warned before applying Mes_Drivers_X.X.X (versions) .exe.

Now I have bitdefender total security and did not warn ... but I think it's not dangerous ... just ports to comunicate for drivers...

Share this post


Link to post
Share on other sites
6 hours ago, fr33tux said:

Can you share me the whole AdwCleaner logfile showing this detection? (from C:\AdwCleaner\Logs).

Thanks,

Adwcleaner show once again these two treads. Are these false positeves or not? Please a answer. Malwarebytes premium finds nothing

Share this post


Link to post
Share on other sites

I am watching this thread for replies because I am also having this issue, but I am on Win 7 Professional.

Share this post


Link to post
Share on other sites

Got the same thing and I've discovered that if you disable cloud database in adwcleaner it doesn't detect anything..

Share this post


Link to post
Share on other sites

Hello,

Thanks all!

Can you confirm me that the issue is gone with `2018.06.15.1`? (it should be used automatically when you start scanning with AdwCleaner).

Thanks, and sorry for the issue. Please keep me posted if you have any question.

Share this post


Link to post
Share on other sites

Hello,

I have exact same thing happen to me all day, and even today.

klauwkikker,  Posted yesterday at 03:24 PM
What are these? Malwarebytes antimalware didn't flag them. Only adwcleaner did.

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP

Adware.Agent HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|WMI-ASYNC-In-TCP-NoScope

I saw the suggestion from Tezzle (thank you!) "Got the same thing and I've discovered that if you disable cloud database in adwcleaner it doesn't detect anything.." and followed that advice, and the detection went away!

Somewhere on the Internet, it says these are attached to some game!?

Would like to know what they are.

Thanks.

 

AdwCleaner[S59].txt

Share this post


Link to post
Share on other sites

Hello,

The database isn't the last one that includes the fix. Can you retry with a working network connection?

Thanks,

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.