[RESOLVED] Malwarebytes detect 2 PUP.Dealio... ?

Hi guys and girls i dont know if im in the right section so please dont jump on me if im not.

I did a scan of Malwarebytes and this come to the result.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} (PUP.Dealio) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) → No action taken.

So is it a false positive ? Can anyone help me ?

Mr.Agent

I used to got BigSeek Toolbar Pro because of my recorder which i dont have anymore. And its was having Search Settings so is it because of that ?

If yes then i did remove the two things so im safe to delete this things or no ?

Malwarebytes

PUP.Dealio Date spotted: First seen on 2010-12-28. Last seen on 2011-01-04.

You find the comment from Miekiemoes at the bottom (Assistant Director of Research)
http://forums.malwarebytes.org/index.php?showtopic=71464

Thank pondus for your so fast respond !!!

But if in the past i did uninstall BigSeek Toolbar Pro or Dealio with Search Settings which might have somewhat related to the source can i remove it without harm ? Also if its remain on my toolbar as left click and i did desactivate it on IE8 its wont cause harm also ?

Have no idea, do not know the program…

Well if the things is uninstalled and Malwarebytes flag the regkey that is left over its shouldnt harm right ?

you can always restore the file from MBAM quarantine if problems :wink:

I should let this left even if i did uninstall that toolbar long time ago ?

BUMP ! I did quarantine them and now i dont see any problems on my browser…

So can i delete them from quarantine or no ? Should i let it 1 day more ?

There is no rush do delete anything from quarantine, it can not harm your computer when in quarantine.
I always wait 30 days before i delete…but thats me

Well 30 days lol.

Humm ok… Well i will maybe give 1 day or 5 just to see how my internet work and if all is fine then i shouldnt worry. Anyway a regkey can recreate its self if its in use or somewhat but i dont got that toolbar so im safe.

PS : Thank you for help me Pondus im very glad that you did. I hope i did not post in a wrong forum because i trust alot the ppl here so if anything come suspicious to me you guys/girls are good 4 it. Also many use Malwarebytes so i dont have to scare.

Mr.Agent

Me I’m in the FP camp (have said as much on the topic above) as that also turned up in my scan, yet there is not a single other trace/piece of evidence of a Dealio associated cr**ware on my system, toolbar, files, registry keys, etc. just this:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio)

I don’t use IE and hate toolbars with a vengeance and always on the lookout for this kind of cr**ware.

Well i bet its as my recorder Hypercam 2 that did put this and i removed it long time ago when he did do this and full updates its was become annoying as hell.

So yeah i hate that toolbar but not my google toolbar its good and nice its aint like any others toolbars.

Now i can say there no such toolbar of dealio on my system omg hell yeah ! David if you got that … then i suggest you remove it if you dont have it because its pretty useless if you stay this on the system.

Mr.Agent

I won’t even have the google toolbar for me one toolbar is one too many ;D

MBAM really has form for detecting things in registry when there are zero associated indications of there ever being any infections on the system. I haven’t had an infection on my system in almost 7 years, but I have had a few FPs in MBAM since I have used it.

This system which is two years old has never been better protected so how this supposedly infected registry key miraculously turns up is beyond me. A registry key like this in isolation is inert and no risk even if it were a PUP.

Maybe you should do a FP post in MBAM forum ?

I added it to the link that you gave to an existing one.