Start a Conversation

Unsolved

This post is more than 5 years old

3 Apprentice

 • 

15.2K Posts

41032

December 6th, 2016 06:00

MalwareBytes now detecting many Auslogics products as "PUPs"

PUP = Potentially Unwanted Program

Auslogic's Disk Defragmenter is included among the programs being detected... it is NOT a "False Positive" on MBAM's part.

I had "frozen" my Auslogic's Disk Defragger program a few years ago (i.e., I intentionally haven't updated it since then), so it's possible that the newer/modern objections don't apply to mine.   Regardless, since it's a program I want and use, I am instructing MBAM to allow/ignore it.

I *MIGHT* be concerned about the later/newest versions...

The choice is yours... to each, his own.

https://forums.malwarebytes.org/topic/191302-adwcleaner-fp-with-auslogics-disk-defrag/

1 Rookie

 • 

5.8K Posts

December 6th, 2016 09:00

As it happens, I found this morning that MBAM Premium had detected 2 Auslogics files on a scheduled overnight scan on my Win 7, namely:
PUP.Optional.AuslogicsDiskDefrag, C:\Users\joseph\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.html, No Action By User, [eb2f06deb4e644f20cce1b8ab14faa56],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\joseph\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.xml, No Action By User, [eb2f06deb4e644f20cce1b8ab14faa56],

These files (both reports) were created in September/2013, when I was using Auslogics Disk Defrag, which I subsequently decided to uninstall, after Auslogics bundled Search Protect by Conduit with a defrag upgrade (which I allowed to install in an unguarded moment - my bad!). I just couldn't trust any company that would bundle malware like Conduit.  

So I uploaded both files to to VirusTotal, where 0/54 scanners detected anything amiss (including MBAM). I don't know if the scanners at VT scan for PUPs, however. So I downloaded the latest version of AdwCleaner from Malwarebytes, and its scan also flagged some Auslogic folders:
[!] Folder not deleted: C:\Users\joseph\AppData\Roaming\Auslogics
[!] Folder not deleted: C:\ProgramData\Auslogics
[!] Folder not deleted: C:\ProgramData\Application Data\Auslogics
It also detected 4 registry keys related to Auslogics.

I'm not surprised that Malwarebytes detected Auslogics files. What remains a bit of a mystery is why only now does MBAM decide that Auslogic files are potentially unwanted?

3 Apprentice

 • 

15.2K Posts

December 6th, 2016 10:00

On this particular system, I have Auslogics Defragger 4.4.0.0 ;  (c) 2008-13 ; which was detected as a PUP.

Edit:   On another system, I have Defragger 4.4.1.0 ; and the MBAM detections were all during its heuristic analysis phase.

9 Legend

 • 

30.3K Posts

December 6th, 2016 10:00

I just scanned with Malwarebytes(FREE Edition)(NO Trial) version on 12/3

It did NOT detect any issues with Auslogic's Disk Defragger Version 5.4.0.0

(Version has a copyright date of 2008 - 2015)

Rick

3 Apprentice

 • 

15.2K Posts

December 6th, 2016 10:00

1 Rookie

 • 

5.8K Posts

December 6th, 2016 15:00

Thanks for the link, ky. It's about time Malwarebytes got more aggressive.

You guys were wise not to update your versions of Disk Defrag. I liked the program, and all my problems with it began with a version update. Out of interest, I went to Auslogics website, and looked at the version history of Disk Defrag. Of note were:

v. 5.3.0.0 (10/02/2015)
•the program now participates in the Auslogics Green Seal Project, which guarantees it to be free of toolbars, adware or third-party offers in the installer;
•fixed minor bugs.

v. 7.1.0.0 (09/11/2016)
•Users may now choose if they want disk temperature to be displayed in Celsius or Fahrenheit;
•Installer was optimized for better user experience;
•All known bugs have been fixed.

Wow- no 3rd party offers in an optimized installer! Could Auslogics have changed its ways? I had to investigate. So against my better judgement, I downloaded and ran the most recent version of Disk Defrag, using a "Custom Install".

Results:
The installer will set Yahoo as your home page and default search engine, and also install "BoostSpeed" (a registry and disk "cleaner"), unless you use the custom install, and uncheck these default options. Despite unchecking these options, it still tried to change my homepage to Yahoo (caught by WinPatrol), which I rejected. Despite rejecting Yahoo twice, WinPatrol kept throwing up alerts.

MBAM Premium detected a dozen or so Auslogic files during the installation, which I allowed (for now). After installation completed, I was re-directed to giveaway-club dot- com, which promoted Auslogics free "BoostSpeed". When I opened IE 11, my homepage was unchanged, but I got an alert that an unkown program was still  trying to change it to Yahoo, which I yet again rejected. 

I ran Disk Defrag, which ran without problems. But I was informed that over 2,000 problems with my computer had been detected, (most of them registry errors, plus junk files wasting 94 MB of disk space) that - you guessed it - BoostSpeed could fix. Talk about scareware!

In short, this PUPpy hasn't changed one bit. It ignored my explicit instructions, and installed what it dangwell pleased. If not for WinPatrol and MBAM real-time protection, my home page, my search engine would have changed, and I'd probably have a worthless registry cleaner installed.

So I uninstalled Disk Defrag (and its evil twin program - AuslogicsDriverUpdater) via Control Panel. Then I purged the Auslogics remnants (files, folders, and registry keys) found by MBAM (17) and AdwCleaner (6).

Malwarebytes was right to tag Auslogics as a PUP. I just wish I still had the installer for a version of Disk Defrag from before the time Auslogics crossed  to the dark side.

9 Legend

 • 

30.3K Posts

December 6th, 2016 16:00

Joe,

Older versions of Auslogics Disk Defragger can be found HERE.

If I click on System Health, I get...

Registry errors = 7579

Junk Files = 3412

But I NEVER do anything about them. I like the Defragger part.

Rick

1 Rookie

 • 

5.8K Posts

December 6th, 2016 21:00

Hey Rick - thanks!

I downloaded Disk Defrag 4.4.0.0 (Released: 28 Nov 2013), which I believe is the last version that came without unwanted bundled junk, from:
filehippo.com/.../

It installed cleanly, and didn't mess with my browser. Nothing was added to my startup list, or to my services. No ads for wretched registry cleaners. I had to toggle off the setting to notify me of updates. And if I ignore the "System Health" tab, I won't have to see all those registry entries and junk files that are not in need of "cleaning".

3 Apprentice

 • 

15.2K Posts

December 7th, 2016 04:00

Joe,

Glad you were able to download/install a clean(er) version.    But to emphasize, my MBAM scans still had PUP objections to versions 4.4.0.0 and 4.4.1.0 --- probably "guilt-by-association" with analogous files in the newer versions.  

I am happy with my results/performance with 4.4.x, and intend to keep it... settings exclusions for any "objections" found by MBAM.

9 Legend

 • 

30.3K Posts

December 14th, 2016 15:00

I spoke too soon. Just ran Malwarebytes and it detected the pups...

Registry Keys: 1
PUP.Optional.AuslogicsDiskDefrag, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1, Quarantined, [b78f8d5a0397082efc62c4e3d92744bc],


Folders: 2
PUP.Optional.AuslogicsDiskDefrag, C:\Users\Rick\AppData\Roaming\Auslogics\Disk Defrag, Quarantined, [163033b40397270f95d7a7004ab608f8],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\Rick\AppData\Roaming\Auslogics\Disk Defrag\Reports, Quarantined, [163033b40397270f95d7a7004ab608f8],

Files: 2
PUP.Optional.AuslogicsDiskDefrag, C:\Users\Rick\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.html, Quarantined, [163033b40397270f95d7a7004ab608f8],
PUP.Optional.AuslogicsDiskDefrag, C:\Users\Rick\AppData\Roaming\Auslogics\Disk Defrag\Reports\Disk_Defrag_Report.xml, Quarantined, [163033b40397270f95d7a7004ab608f8],

Rick

1 Message

February 7th, 2017 05:00

You're all too extremely paranoid, really. Just set malware bytes to ignore these warnings. 

1 Message

September 26th, 2021 08:00

It still flags Auslogics apps.

3 Apprentice

 • 

15.2K Posts

September 26th, 2021 14:00

It's been over 5 years... and I would not expect anything to be changing at this point.

1 Message

May 25th, 2022 04:00

Hey Rick - thanks!

I downloaded Disk Defrag 4.4.0.0 (Released: 28 Nov 2013), which I believe is the last version that came without unwanted bundled junk 

No Events found!

Top