and these icons on their desktop,in their taskbar, and in their start-menu:
icons PUP.Optional.WinThruster
and they may have seen these warnings during install:
Install instructions PUP.Optional.WinThruster
main screen PUP.Optional.WinThruster installer
EULA PUP.Optional.WinThruster
Malwarebytes can detect and remove PUP.Optional.WinThruster without further user interaction.
A Malwarebytes log of removal will look similar to this:
Malwarebytes www.malwarebytes.com-Log Details- Scan Date: 9/18/18 Scan Time: 8:46 AM Log File: 81b53081-bb0e-11e8-aae7-00ffdcc6fdfc.json
-Software Information- Version: 3.5.1.2522 Components Version: 1.0.441 Update Package Version: 1.0.6883 License: Premium
-System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: {computername}\{username}
-Scan Summary- Scan Type: Threat Scan Scan Initiated By: Manual Result: Completed Objects Scanned: 252096 Threats Detected: 57 Threats Quarantined: 57 Time Elapsed: 3 min, 14 sec
-Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Enabled Heuristics: Enabled PUP: Detect PUM: Detect
-Scan Details- Process: 1 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\WinThruster.exe, Quarantined, [1466], [182298],1.0.6883
Module: 2 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\IsLicense50.dll, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\WinThruster.exe, Quarantined, [1466], [182298],1.0.6883
Registry Key: 13 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D7C6C53B-C335-417f-ABB8-F5A157F92EA0}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\IsLicense50.IsLicenseMgr, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\IsLicense50.IsLicenseMgr.1, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D7C6C53B-C335-417F-ABB8-F5A157F92EA0}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\TYPELIB\{8D732308-066E-4E85-9D5C-4410EB6BFDBC}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\INTERFACE\{3C4ABAB8-F6D3-4BC3-922D-43715A228CC2}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3C4ABAB8-F6D3-4BC3-922D-43715A228CC2}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3C4ABAB8-F6D3-4BC3-922D-43715A228CC2}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{8D732308-066E-4E85-9D5C-4410EB6BFDBC}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{8D732308-066E-4E85-9D5C-4410EB6BFDBC}, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{D7C6C53B-C335-417f-ABB8-F5A157F92EA0}\InprocServer32, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D7C6C53B-C335-417f-ABB8-F5A157F92EA0}\InprocServer32, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WinThruster_is1, Quarantined, [1466], [182298],1.0.6883
Registry Value: 0 (No malicious items detected)
Registry Data: 0 (No malicious items detected)
Data Stream: 0 (No malicious items detected)
Folder: 2 PUP.Optional.WinThruster, C:\PROGRAM FILES (X86)\WINTHRUSTER, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\WINTHRUSTER, Quarantined, [1466], [182299],1.0.6883
File: 39 PUP.Optional.WinThruster, C:\USERS\PUBLIC\DESKTOP\WINTHRUSTER.LNK, Quarantined, [1466], [260282],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_pl.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\help.ico, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\IsLicense50.dll, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_ar.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_cs.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_da.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_de.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_el.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_en.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_es.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_fi.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_fr.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_hu.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_it.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_ja.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_ko.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_nl.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_no.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_pt-br.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_pt.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_ro.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\local_ru.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_sv.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_tr.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_zh-cn.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Local_zh-tw.xml, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\PerformanceMonitor.exe, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\Post _Scan_Notification_English.wav, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\unins000.dat, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\unins000.exe, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\unins000.msg, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\WinThruster.exe, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\Program Files (x86)\WinThruster\WinThruster.ini, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\DOCUMENTS AND SETTINGS\PUBLIC\Desktop\WinThruster.lnk, Quarantined, [1466], [182298],1.0.6883 PUP.Optional.WinThruster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinThruster\Uninstall WinThruster.lnk, Quarantined, [1466], [182299],1.0.6883 PUP.Optional.WinThruster, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinThruster\WinThruster.lnk, Quarantined, [1466], [182299],1.0.6883 PUP.Optional.WinThruster, C:\USERS\{username}\DESKTOP\SETUP_WINTHRUSTER_2018.EXE, Quarantined, [1466], [461226],1.0.6883
Physical Sector: 0 (No malicious items detected)
WMI: 0 (No malicious items detected)
(end)
Should users wish to keep this program and exclude it from being detected in future scans, they can add the program to the exclusions list. Here’s how to do it.
You may see these entries in FRST logs:
(Solvusoft) C:\Program Files (x86)\WinThruster\WinThruster.exe C:\Users\Public\Desktop\WinThruster.lnk C:\Users\{username}\AppData\Roaming\WinThruster C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinThruster C:\Program Files (x86)\WinThruster (Solvusoft ) C:\Users\{username}\Desktop\Setup_WinThruster_2018.exeWinThruster (HKLM-x32\...\WinThruster_is1) (Version: 1.3.5.138 - Solvusoft) <==== ATTENTION
Select your language