PDA

View Full Version : Spybot Found 'OptimumInstaller' - Questions



thelordpuffer
2012-12-14, 16:42
I ran both Malwarebytes and SUPERAntiSpyware and it found nothing on my Win 7 x64 Home Premium laptop. However, when I ran Spybot, it found 1 entry of 'OptimumInstaller'. It would not fix the problem.

Is this Adware or Malware? I cannot tell by doing research. If it is best to get rid of it, how should I do it? One other note: I just ran Avast Pro Antivirus and it found no infections. Could this be a FP, since only Spybot detects it? Thanks.

Edit: To Mods....If this should be in the Malware Removal Forum, please place it there.

Zenobia
2012-12-14, 23:31
Could you let me know if you are using Spybot 1.6.2,or Spybot 2.0? :)

thelordpuffer
2012-12-14, 23:34
I'm using Spybot 1.6.2.

Zenobia
2012-12-14, 23:45
Ok,thanks. :)
Could you please open Spybot,click Mode up top,select Advanced mode,(if a warning window comes up,please select "Yes"),then click Tools,View Reports,then click View Previous Reports.

The Spybot logfiles are dated(Checks.yymmdd-hhmm or Fixes.yymmdd-hhmm).Please select the Spybot Fixes logfile with the date from the scan that found Optimum Installer and doubleclick it.It should open in the Spybot window.Rightclick somewhere in that window,and select "Select All".Then rightclick again,select Copy,then Paste the logfile here in a reply.

thelordpuffer
2012-12-14, 23:56
Thank you:


--- Report generated: 2012-12-14 09:45 ---

OptimumInstaller: [SBI $0B5D7EDA] Data (File, nothing done)
C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML
Properties.size=12722
Properties.md5=E295A82CD8133FD5698DAC49745518B8
Properties.filedate=1339881305
Properties.filedatetext=2012-06-16 14:15:04


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-01-26 TeaTimer.exe (1.6.4.26)
2012-06-23 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2012-11-20 Includes\Adware.sbi (*)
2012-12-11 Includes\AdwareC.sbi (*)
2010-08-13 Includes\Cookies.sbi (*)
2012-11-14 Includes\Dialer.sbi (*)
2012-11-14 Includes\DialerC.sbi (*)
2012-11-14 Includes\HeavyDuty.sbi (*)
2012-11-14 Includes\Hijackers.sbi (*)
2012-11-14 Includes\HijackersC.sbi (*)
2012-11-14 Includes\iPhone.sbi (*)
2012-11-14 Includes\Keyloggers.sbi (*)
2012-11-14 Includes\KeyloggersC.sbi (*)
2012-11-21 Includes\Malware.sbi (*)
2012-12-11 Includes\MalwareC.sbi (*)
2012-11-14 Includes\PUPS.sbi (*)
2012-12-11 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2012-11-14 Includes\Security.sbi (*)
2012-11-14 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2012-11-14 Includes\Spyware.sbi (*)
2012-11-14 Includes\SpywareC.sbi (*)
2012-11-19 Includes\Tracks.uti
2012-12-11 Includes\Trojans.sbi (*)
2012-12-11 Includes\TrojansC-02.sbi (*)
2012-12-11 Includes\TrojansC-03.sbi (*)
2012-12-11 Includes\TrojansC-04.sbi (*)
2012-11-14 Includes\TrojansC-05.sbi (*)
2012-12-03 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Zenobia
2012-12-15, 02:20
Thanks for posting your logfile.
From what I could find,this looks like it may be a false positive,but the info I came up with was scanty,at best.So it's best to ask about it in the false positives forum.

This post shows how to report False Positives:
http://forums.spybot.info/showthread.php?t=19117

False Positives:
http://forums.spybot.info/forumdisplay.php?f=16
A lot of the info needed you've posted here,so it should be okay for you to include a link to this thread,if you like.It may be a few days for a reply,since it's the weekend.You'll probably get a reply around Monday or so. :)

thelordpuffer
2012-12-15, 02:26
I will do that. Thank you for your help. :bigthumb:

Zenobia
2012-12-15, 02:28
You're welcome. :)

thelordpuffer
2012-12-15, 14:28
I've been using my Mac a lot and forgot this, but it seems like it is solved. I found the thread at:

http://forums.spybot.info/showthread.php?t=67295

I then ran Spybot as ADMINISTRATOR, it found the adware and removed it. I shut down, restarted, ran Spybot again and it found nothing. :bigthumb:

Zenobia
2012-12-16, 10:07
Okay,good. :)

Zenobia
2012-12-16, 13:53
I was looking for info on this,and here it is on my own computer. :laugh:
I have Google toolbar on Internet Explorer,which I hardly ever use,and I have the same C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML file.
That file looks like it has something to do with custom buttons on Google toolbar,or something like that.I hardly ever use Internet Explorer,and I'm pretty sure my Google toolbar is just the standard,run-of-the-mill ordinary toolbar which hasn't been added to by anything.
So,unless some part of something to do with optimum installer is included with Google toolbar by default,then I think this might be a false positive.You could still ask about it in the false positives forum if you like. :)

thelordpuffer
2012-12-16, 14:10
This is what I think happened to both of us. I downloaded some mainstream software (not 100% sure I am correct, so I won't mention which one). The software came bundled with the Google Toolbar for IE (I never use IE). I just uninstalled the Google Toolbar for IE.

I believe that Optimum Installer can download with other bundled software, so it came along for the ride.

I may be wrong, and it may be a FP, however, everything seems to be working fine since I deleted the 'Optimum Installer' find with Spybot. If the Google Toolbar for IE was affected by me deleting Optimum Installer, then I will probably never know it.

If you discover any more info on this, please post it. Thanks. :)