Ongoing notifications for win32:pup-gen / win32:OpenCandy threats for onedrive.exe

Issue abstract:

Ongoing notifications for win32:pup-gen / win32:OpenCandy threats for onedrive.exe

Detailed description:

New laptop with pre-installed Norton for Gamers.

Every ~20 seconds I get a notification with threat for win32:pup-gen, win32:OpenCandy and variants of these PUP threats.

The origin is always onedrive.exe. I use OneDrive and have it installed myself.
How serious is this threat and how can this be solved?

Product & version number:

Norton for Gamers

OS details:

Win11 24H2

What is the error message you are seeing?

If you have any supporting screenshots, please add them:

1 Like

Any Windows Updates pending?
And you’ve run Norton LiveUpdate + Restart (not Shut down) machine…a few times.
And you’ve run Disk Cleanup/Storage Sense…system temporary files/cache + Restart (not Shut down) machine?

You installed onedrive.exe…yourself…from what source?
Did you install ā€œbundled softwareā€ ā€œother softwareā€ from the source?

Are you signed in to Microsoft account?
Are you synching new machine with other devices?

\AppData\Local\Microsoft\OneDrive.exe = head scratch

Maybe, your new machine has pre-installed trialware/freeware? that Norton detects?

Did you run Norton full scan + Malwarebytes threat scan.
How to install and run a scan with Malwarebytes here

=================================================

AI Overview
Ongoing notifications for Win32:PUP-Gen or Win32:OpenCandy threats related to onedrive.exe likely indicate that your security software has detected bundled software (PUA), not necessarily that the OneDrive application itself is infected. This PUA, like OpenCandy, often comes bundled with other freeware and performs potentially unwanted actions, such as installing toolbars or modifying browser settings. To resolve this, update your antivirus/anti-malware software to the latest version, then perform a full system scan. If the threat is identified, follow the security software’s instructions to remove or quarantine it, then restart your computer and run another scan to confirm.

Understanding Win32:PUP-Gen and Win32:OpenCandy

  • Potentially Unwanted Programs (PUPs):

Win32:PUP-Gen and Win32:OpenCandy are classified as Potentially Unwanted Programs (PUAs) or Potentially Unwanted Programs (PUPs), rather than true malware.

  • Bundling:

These are often bundled with legitimate free software that users download from unofficial sources.

  • Undesirable Behaviors:

They can modify browser settings, install unwanted add-ons, change the homepage, or inject into other processes.

  • False Positives:

They can sometimes be flagged by antivirus software even if they are not directly related to the OneDrive application, especially if the user was trying to install another program.

======================================================

fwiw ~ boiler plate
Did you clear browser cookies n cache? system cache?
Do you run browser/device sync?
Did you recently install any program / browser extension?
Did you recently allow push notifications?
Did you recently change site permissions?
Did you run Norton full scan?
Did you run Malwarebytes threat scan?

==========================================================

https://en.wikipedia.org/wiki/OpenCandy

FreeFileSync_5.18_Windows_Setup.exe - VirusTotal report … Win32:OpenCandy-D [PUP]

Related

Edited: Are you also using SharePoint on this device?

SA

I’m not using sharepoint as far as I know. The program is not installed

Does the file being nailed actually exist in your OneDrive either locally or in the cloud? If so have you tried removal of that file?

SA

https://community.norton.com/t/ongoing-notifications-for-win32-pup-gen-win32-opencandy-threats-for-onedrive-exe/448582/2

Thanks bjm, so many questions :slight_smile: I went through them, didn’t answer publicly though…

But I installed OneDrive myself from Microsoft website.

This one \AppData\Local\Microsoft\OneDrive.exe = head scratch I didn’t understand. But then the comment below from SoulAsylum. So I removed the file from the folder. Did full scan, restart, and didn’t get new threat notifications anymore. But can also not run OneDrive anymore, so that I will need to reinstall I guess.

I’m signed into Microsoft account, and am syncing only this laptop. My previous laptop was also linked to the same folders in OneDrive, in the cloud.

About bundled software, not sure if I downloaded Office365 and that it included OneDrive, or that I downloaded OneDrive separately. But anyway, it came from Microsoft, not a random website offering software.

Let me try the re-install of OneDrive. Seems to be the next step

1 Like

Hello @user9465
Is this your OneDrive from M$ website?
https://www.microsoft.com/en-us/microsoft-365/onedrive/download


File: OneDriveSetup.exe
File size: 87.5 MB (91,778,920 bytes)
MD5 checksum: 72AC202B786447776498CA176D059C5A
Date/Time: 10/6/2025

------------------------------------------------------------------

fwiw ~ as test:
OneDrive.exe with Program Files?

OneDrive.exe with \AppData\ = head scratch

1 Like

Indeed, if the installation location changed for OD and you didn’t perform that malware most likely is at play. Guru Bjm laid that out nicely earlier.

SA

Hi bjm,

Thanks again.

I removed OneDrive.
Indeed, I downloaded from the same location from Microsoft website. And re-installed it:

In AppData it look like this now:

<I can only do 1 snapshot per post as I’m new to this forum, so I’ll post it separately>

Before I removed OneDrive, in AppData it had more files and at least application files OneDrive.App and OneDrive. I guess like it’s now in Program Files.

For now, Norton is silent. OneDrive is syncing. I’ll keep you updated about the status.

Thanks for your help and time. Appreciated!

1 Like

1 Like

fwiw ~ my OneDrive…Apps → Installed apps → Uninstall…left residual files with Program Files and AppData…before & after my machine Restart (not Shut down).

Your Oct 06 with Oct 07 dates (maybe) suggests…you did not scour File Explorer for residual files…did not Restart machine…before your OneDrive re-install.

I’m curious…did you run Norton full scan &or Malwarebytes threat scan…after OneDrive re-install?
I’m curious…what your OneDriveTemp folder looked like when Norton was not silent.


Edit:

Hoping, your Norton remains silent.

--------------------------------------

OneDrive.App = OneDrive.App.exe
OneDrive = OneDrive.exe

---------------------------------------
Caveat: I do not run OneDrive. I’m not familiar with OneDrive app/client and my as test: OneDrive install…did not Sync.

Urghh. The Norton notification is back. Strange enough, the OneDrive.exe file is not in the folder Norton says it’s the location.

again…I’m not familiar with OneDrive.
did you Delete… Norton 360 → Quarantine files?

Is pre-installed Norton 360 for Gamers trialware?
Is pre-installed Norton 360 for Gamers registered with your Norton account?
Meaning, you’ll be able to reinstall…pre-installed Norton 360 for Gamers.

fwiw ~ were my new machine.
I’d uninstall Norton 360.
I’d uninstall OneDrive with scour File Explorer for remnants.
I’d run new machine as it’s out-of-the-box…with Windows Security…for a while.
I’d run Windows Security scans.
No detections.
I’d setup my new machine with OneDrive to my liking and run Windows Security scans.
I’d only introduce Norton 360 once I’m assured my machine is clean.

Norton 360 detection may be erroneous.
Norton 360 detections may be M$ new machine trialware/bloat.

AI Overview
Ongoing notifications for Win32:PUP-Gen or Win32:OpenCandy threats related to onedrive.exe likely indicate that your security software has detected bundled software (PUA), not necessarily that the OneDrive application itself is infected. This PUA, like OpenCandy, often comes bundled with other freeware and performs potentially unwanted actions, such as installing toolbars or modifying browser settings.

Hi bjm,

Thanks again. I’m going to follow your steps. I’m working, so will have to make time for it.

No, didn’t delete the quarantine files yet, but will do. I’m not logged in Norton.

It’s indeed a trial, and not sure I’ll extend it either. Not a gamer.

I’ll keep you updated after or during the steps.

Appreciate your help and efforts!!

I made edits while you were posting.

1 Like

c68cfb…77926.temp Blocked

c68cfb…77926.temp Quarantined

Hi @bjm

I just wanted to give feedback on the steps you gave ā€˜as it were your new machine’. I followed all, except for the last one, introducing Norton. The first scans Windows Security would come up with threats, that I would remove or put in quarantine. Have run several scans in the past weeks, and it all looks good. I think I will keep on using Windows Security.

I really appreciate your help. Thank you

1 Like

Thanks for posting your progress.