Found 87 results

  1. Hello, AdwCleaner detects one PUP.Optional.Legacy. After cleaning and restarting Windows, AdwCleaner still detects this malware. Malwarebytes doesn't find any threats. Please find attached FRST, Additions, and AdwCleaner Threat Scan logs. FRST.txt Addition.txt AdwCleaner[S07].txt I need your help, please.
  2. Just found these with the adware scanner.. are they ok to remove? wasnt sure it being registry HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\nicepage.com PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\nicepage.com
  3. Short version of the problem: Whenever I press the little bell icon in the top right corner Malwarebytes just completely crashes. Rebooting does not help, ran repair with the Malwarebytes suppport tool. But nothing changed and it still crashes as soon as i click the icon. I have to forcibly close malwarebytes and restart it to get it to work again. When did it start / order of events (some of it might be unrelated to the problem): - I was watching a random youtube video. A little add popped up on the video I want to click on the 'x' to close it but missclicked and clicked the banner instead opening up the site it advertised. - Malwarebytes instantly blocks the site due to 'POP', (which im guessing is 'PUP' but since my malwarebytes is in dutch its says 'POP' instead.) - Just in case I update my virus definitions and run a malwarebytes scan, followed by Norton antivirus scan. Both scans found nothing. - While im scanning the 'Bell icon' still works since im using it to check the notification and what site was blocked etc. (the blocked Domain was "free.gamingwonderland.com") - A very short while after the scans I want to use the bell icon again to click the thing that says I saw the notifications and mark it as read or something. - This time as soon as I click it Malwarebytes crashes and freezes up, but I just assume its a one time problem and turn of my computer cause I got to go do some other stuff. - I came back not long after and started up my computer and again want to use the icon in the top right corner. As soon as I Click it Malwarebytes crashes and freezes up again. - I decide to reboot my computer (during which windows seems to do a quick short update). After reboot it still crashes. - I download Malwarebytes support tool to repair malwarebytes, which seems to do a reinstall of malwarebytes. After which the problem presists, it still crashes when pressing the button. --------------------------------------------------------- I am not super knowledgeable about all this. So, I need some advice. How do I fix this, and do I have anything to worry about with the POP thing. Could they be related or is this just a coincidence. Help is appreciated. :)
  4. This is very frustrating! I'm a Malwarebytes fan, and I am certainly an Iobit fan! - Your excuse can longer be that iobit uses pup files. This is a known entity that has a long standing record of producing quality products. These exclusions should already, by courtesy, be "excluded" from Malwarebytes. We all know the reason they're not, and this brings up the question of ethical practices. Sure, they may be a competitor. You may already have a friendly relationship with AVG's new tools, or some other PC Fix tools provider. But in truth, aren't you just as interested in being loyal to your own base? Those who like your product, but also want to use iobit? You're not just just alienating iobit, you're alienating "your own fans(potential clients)"! It's not like their files are constantly changing, or their software hasn't popped up on your radar, or that people like me haven't written before about this problem... It's that you don't want to do anything about it. Which leaves me with a real problem. You want me to "trust you" as a provider of quality products, yet within your own offering you "exclude" others with a selfish intent. It's time to bury a hatchet and place iobit's files in exclusion of your filter search! I'm tired of my clients constantly calling me because you consistently change back to showing these files as threats, when you know they absolutely are NOT threats! Fix this! because it's more damaging to "your" image, than it is to theirs!
  5. Hi Team, Hope this finds you well. I am struggling with a virus: ”PUP.Optional.Legacy”. Initially, this virus was showing up in my malware scan. I ran through a few procedures, and now it doesn't. However, it is still showing up in my adware scan. I keep going through "clean & repair," but it does not remove the PUP. I've attached my scan logs for your review. Can you please assist with the next steps?? Kindest, Maurice AdwCleaner[S02].txt Malware scan report.txt FRST.txt Addition.txt
  6. I have a Big Fish game, Mind Snares-Alice's Journey & AdwCleaner states it contains a pup - adware heuristic, I think this is a false positive. Can you double check it? I have excluded it for now. Thanks,
  7. Malwarebytes Premium keeps detecting "PUP.Optional.365Stream". I let it quarantine and delete each instance, but they come back very quickly (hours). They return before the machine is rebooted. How do I locate the re-installer and remove it?
  8. So i have that annoying hku goes back and back. I tried deleting it manually without mbam scans first,then, (i cant delete it even with regdellnull) it deleted my computer cant open anything, so i force shut down laptop. user got deleted and created another user without admin rights and cant open task manager. my laptop would be doomed if not for mbam but it is still there and always comes back. help in deleting that *****.? i also got those annoying pop-up shortcuts that always comes back image is shown below. Addition.txt FRST.txt hku disable registry and task manager appeared after restart and scan while i was trying to manually delete the hku 1-5-21.txt pop up shortcuts.docx
  9. Hey there, I am unable to remove some infection that causes popups within my mozilla browser. Malewarebytes Premium on my PC blocks these sites however when I run a scan It can't seem to detect the infection. It does detect something in my my chrome browser but won't remove that permanently either. Attached are the required documents. Thanks FRST.txt Addition.txt Threat Scan Log.txt
  10. Hello, I am having trouble with PUP.Optional.Legacy in Chrome. Tried multiple scanners, only AdwCleaner detects it I've been battling this beast for a while now. What I've done so far: I've clean installed windows twice. I have reset chrome settings multiple times. I have reset chrome sync multiple times.I have deleted cookies, preferences and all files from %LOCALAPPDATA% for Chrome. I have installed Chrome from the offline installer. I have cut the internet connection and did all of those steps again. I've narrowed it down to this: At first I thought it comes from my profile/sync. But I have done the steps below, without internet connection and it keeps coming back. It is somehow connected with the search engines/search providers of Chrome and/or Chrome settings. I can clean it with AdwCleaner, or manually remove the search engines from Chrome settings and it seems to disappear. But even if it does, after a few minutes, Chrome starts lagging, freezing a lot, and loading pages very, very slowly. I can tab out of Chrome and go to another browser, enter the web site and it will fully load, while in Chrome it is still loading. I run a scan with AdwCleaner - nothing, but I know it's there, my browser is lagging so bad... Here how it always comes back. Every time I click on "Reset settings" in Chrome, the adware/virus comes back. This additional search engines appear in the settings: And after a scan, these are the results: And here is the Log File from the scan: AdwCleaner[S70].txt I am not smart enough to handle this on my own. I need help.
  11. I have an old HP Desktop, model s5310f running 64 bit Win7 Home Premium with an AMD Athlon X2 250 3.0GHz processor. I hadn't used it in awhile, mostly my kids playing stupid flash games and youtube, etc. when I noticed the HDD drive was filling up without explanation. I ran an MBAM scan out of curiosity and it found a bunch of PUP junk (pricegong, conduit, utorrent bar) and some reg keys from a trojan bho generic. It seemed to clean them, but just want to make sure everything is fully removed. HDD is still pretty full compared to what it should be. I also ran an AdwCleaner scan as well. Logs are attached. Appreciate the assistance with the remaining clean-up. AdwCleaner[C00].txt MBAM log.txt
  12. Guys, I rarely make comments because in truth, the usually NEVER result in a positive outcome. People who WANT to continue doing what they're doing, do so any way... However, my frustration right now is trying to run Malwarebytes, a trusted source of mine, with iobit products, another "trusted" source of mine! I've even added their information in the "exclusions" tab, yet you continue to bring their products to your scan list every single time. Including the "exact" file listed in the exclusions..... The only conclusion one can draw from such acts, is that you "absolutely" have a campaign against iobit products. As an IT professional, I've used their products almost since they first hit the internet around 2006 or so. As someone who is a military veteran, and a strong "anti-China" advocate, it might seem odd that I'm in support of this organization, but to date, there products have proven to be very effective and without incident. So why are so many antivirus, anti-malware companies attempting to thwart this great company? I can imagine this is a very delicate subject. I'm very aware of the ongoing legal battles with some other entities, like AVG for example. But, I think enough is enough. So my question still stands in accordance with the actual topic here... Why are you still showing me these key files during a scan, when they are clearly listed in my exclusions preferences? Thank you in advance for any "true comments" concerning this issue. Those who post irrelevant argument based upon their own personal like or dislike, will simply be ignored. I am looking for some kind of true explanation/justification for including their content in my scans. Again, I am a big fan of Malwarebytes and will continue to be one. But, I am also a fan of Iobit and need to find some kind of common ground here. If you provide adequate information, that proves they are a threat, I'll gladly listen..
  13. After I downloaded pokki start menu and scanned it with adwcleaner several times and deleted it. I went to my start menu and saw start menu no pokki just start menu my laptop labeled it new so I went to downloads it automatically closed I went on chrome typed malwarebytes it closed what do I do!?
  14. A couple of days, a relative used my computer and downloaded something that came with a malicious software, and it keeps coming back with different names despite constant cleaning using MalwareBytes, HitmanPro, ZemanaAntiMalware, AdwCleaner, Avast Browser Cleanup, ZHP Cleaner and so forth. I also restored my browsers to default settings and deleted all the cookies, cache and such with CCleaner. At first this malware used to open random tabs in my browser but after some cleaning, it stopped. Then it changed to a ksecdd.ax file appearing in my users/user/appdata/local/temp folder every time I restarted the computer. MalwareBytes would find the file and quarantine it, but at the next restart, it would come back. Now it's a BitcoinMiner infecting my msiexec64.exe that once again reappers whenever my computer restarts. Not only that but it makes my browsers crash whenever I search for Farbar Recovery Tools, leaving me unable to see if said software can bring me a solution. I can search for anything else with no problem but as soon as I type farbar and press enter, instant crash. What logs could I provide here for the experts to analyze so they can find a way to fix this? Thanks in advance.
  15. Hi there. I just signed up after finding out with a quick and first scan ever of AdwCleaner that I am infected with PUP.Optional.Legacy. There were about 3 other PUP infections that were easily removed upon restart. This one kept coming back up with a new scan right away. Here are the logs of the AdwCleaner scan. MalwareBytes itself didn't pick up any threats. # ------------------------------- # Malwarebytes AdwCleaner # ------------------------------- # Build: 04-27-2018 # Database: 2018-05-02.2 # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 05-05-2018 # Duration: 00:00:09 # OS: Windows 7 Ultimate # Scanned: 40818 # Detected: 1 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries found. ***** [ Chromium URLs ] ***** PUP.Optional.Legacy AOL ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S03].txt ##########
  16. Chat in Messenger.com - I follow legit facebook link. Suddenly my browser(CHROME)/cpu start lagging. Messenger.com go offline , I check it on "site online checker" - it was globally offline. My lag continue - so I restart the pc. After awhile message appear but facebook say that I have to change my password / fishing issue. I did - instant regret - meanwhile or already a virus hack Chrome - and chrome apps pop up appear - Chrome Cleaner Pro have been installed. I log in to Messenger.com to see a virus have send message to all my friends!!! I follow a tread that recomend me to delete all the "apps" in facebook - I have 2 - del them. I than start to search in Google "REMOVE Chrome Cleaner Pro" - however this redirected me to (first search result) Danger!: I've got suspicious. I dont remember what exacly I did there. However I install Malwarebytes after this - now it blocks it as danger!!! I try to follow this - Chrome Secure Preferences detection always comes back It dont work. adwcleaner_7.1.1 - find primary one tread - PUP.Optional.Legacy - Chrome extension - Chrome Cleaner Pro + Ask PUP few times With every pc restart adwcleaner_7.1.1 cleans it - only to appear again when I power the Internet (it is on 4G usb stick?!) The Chrome downloads the PUP from somewhere I suppose!!!??? I dont know how to stop my 300+ friends to click on message that was send through my account. I dont know is my account continue to send this links and how to stop it. I dont know how I got this? Can I even trust you??? - your older soft - adwcleaner_6.047 found few legit PUP(the name of them was suspicious enough - "one_click_process"...something ) that the new one didnt find? I am becoming paranoid already - the virus app is called Chrome Cleaner Pro, - it is legit GOOGLE APP wtf? and the site that describe how to rig off - it is itself a treat!!! HELP?
  17. Hi! I just did a scan with AdwCleaner 7,1,1and it found these two objects, what is it and what should i do? # ------------------------------- # Malwarebytes AdwCleaner # ------------------------------- # Build: 04-27-2018 # Database: 2018-04-30.1 # Support: https://www.malwarebytes.com/support # # ------------------------------- # Mode: Scan # ------------------------------- # Start: 05-01-2018 # Duration: 00:00:07 # OS: Windows 7 Professional # Scanned: 40814 # Detected: 2 ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** PUP.Adware.Heuristic C:\Windows\System32\Tasks\{ECC531EE-A054-4B19-B6A1-1FBC9166C659} ***** [ Registry ] ***** PUP.Adware.Heuristic HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ECC531EE-A054-4B19-B6A1-1FBC9166C659} ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries found. ***** [ Chromium URLs ] ***** No malicious Chromium URLs found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries found. ***** [ Firefox URLs ] ***** No malicious Firefox URLs found. ########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S03].txt ##########
  18. I received an alert from tonights scan that contained the info at the bottom. Each of the mentioned Registry keys is completely empty. An example of one of the triggered files c:\userdata\ntuser.pol is clearly not infected by anything. The other .pol files are very similar, no indication of any malware. Although its uncler what that .exe is (i tried to run it in EC2 instance and it wont execute/install), the fact that empty registry keys and normal .pol files are mentioned give me concern about this detection. Nor am I experiencing any issues. Reg� [ S o f t w a r e \ P o l i c i e s \ M i c r o s o f t \ W i n d o w s \ G r o u p P o l i c y O b j e c t s \ L o c a l G r o u p P o l i c y ; * * C o m m e n t : G P O N a m e : L o c a l G r o u p P o l i c y ; � ; ; ] [ S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ P o l i c i e s \ E x p l o r e r ; ; ; ; ] [ S o f t w a r e \ P o l i c i e s \ M i c r o s o f t \ W i n d o w s \ W i n d o w s S e a r c h ; A l l o w C o r t a n a ; � ; � ; ] [ S o f t w a r e \ P o l i c i e s \ M i c r o s o f t \ W i n d o w s \ W i n d o w s U p d a t e \ A U ; N o A u t o R e b o o t W i t h L o g g e d O n U s e r s ; � ; � ; � ] Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 4/12/18 Scan Time: 2:40 AM Log File: 65135b06-3e1c-11e8-b1d1-f80f4196759f.json Administrator: Yes -Software Information- Version: Components Version: 1.0.342 Update Package Version: 1.0.4706 License: Trial -System Information- OS: Windows 10 (Build 16299.371) CPU: x64 File System: NTFS User: System -Scan Summary- Scan Type: Threat Scan Scan Initiated By: Scheduler Result: Completed Objects Scanned: 375143 Threats Detected: 11 Threats Quarantined: 0 (No malicious items detected) Time Elapsed: 14 min, 1 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Detect PUM: Detect -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 4 PUP.Optional.NovaRambler.ChrPRST, HKLM\SOFTWARE\POLICIES\GOOGLE\CHROME, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\CHROME, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, HKLM\SOFTWARE\POLICIES\CHROMIUM, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, HKLM\SOFTWARE\WOW6432NODE\POLICIES\CHROMIUM, No Action By User, [299], [-1],0.0.0 Registry Value: 0 (No malicious items detected) Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 0 (No malicious items detected) File: 7 PUP.Optional.BundleInstaller, C:\$RECYCLE.BIN\S-1-5-21-3940657776-1240908072-4294066368-1001\$RK9Q0LV.EXE, No Action By User, [396], [496654],1.0.4706 PUP.Optional.NovaRambler.ChrPRST, C:\USERS\ILYA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, No Action By User, [299], [493310],1.0.4706 PUP.Optional.NovaRambler.ChrPRST, C:\USERS\ILYA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, No Action By User, [299], [493310],1.0.4706 PUP.Optional.NovaRambler.ChrPRST, C:\DOCUMENTS AND SETTINGS\ALL USERS\NTUSER.POL, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, C:\PROGRAMDATA\NTUSER.POL, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, No Action By User, [299], [-1],0.0.0 PUP.Optional.NovaRambler.ChrPRST, C:\USERS\ILYA\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, No Action By User, [299], [493310],1.0.4706 Physical Sector: 0 (No malicious items detected) (end)
  19. It started showing up yesterday on Malwarebytes. I noticed on Firefox (I don't have chrome), Bing was coming up as my default homepage even though I never selected that. I've used MWB and Adwcleaner to remove PUP.Optional.Conduuit but it keeps coming back. malarebytes.txt AdwCleaner[S0].txt
  20. Trovi and Spigot returns every time I open Chrome. If I remove and restart and scan without opening Chrome, nothing is detected. If I then run Chrome and do a scan it will detect it. Please help. Log are attached. I appreciate it very much thank you! Addition.txt FRST.txt MBLog.txt
  21. I have the Premium Trial of Malwarebytes and it did not find the PUP.Optional.Legacy infection in my Registry that AdwCleaner found.... I am confused why Malwarebytes did not recognize it? I'm even more perplexed as to what to do about it... I'm not tech savvy and I don't want to remove a registry file that is needed for my computer to run properly... Legacy (I presume) is causing occasional havoc on my computer and would obviously like for Legacy to be removed before any more damage is done. I'm GRATEFUL for any help! # AdwCleaner - Logfile created on Fri Mar 16 19:30:19 2018 # Updated on 2018/08/02 by Malwarebytes # Database: 2018-03-14.3 # Running on Windows 10 Home (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{8BF0126F-A5B7-4720-ABB2-2414A0AF5474} ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** No malicious Chromium entries. ************************* C:/AdwCleaner/AdwCleaner[S0].txt - [1006 B] - [2018/3/15 17:11:51] C:/AdwCleaner/AdwCleaner[S1].txt - [1074 B] - [2018/3/15 18:4:42] C:/AdwCleaner/AdwCleaner[S2].txt - [1141 B] - [2018/3/15 20:29:46] C:/AdwCleaner/AdwCleaner[S3].txt - [1209 B] - [2018/3/16 5:28:52] C:/AdwCleaner/AdwCleaner[S4].txt - [1276 B] - [2018/3/16 19:23:41] ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt ##########
  22. Hello, Couple of days ago this particular PUP has been appearing on daily scans and I can't seem to get rid of it with Malwarebytes. There's not much else to say, it seems to be the only item that appears in the logs and doesn't seem to be doing any harm, nonetheless I'd like advice on how to remove it. I've attached the three recommended files. Thank's in advance! Threat Scan Results.txt FRST.txt Addition.txt
  23. Hi, I am having a bit of an issue removing that ware from Chrome. I've tried everything - reinstalling Chrome, clearing cache, clearing up my entire my profile, reseting synchronisation. AdwCleaner detects it as startup pages (report included) but I also deleted every possible startup pages as well. Thanks for help. Addition.txt AdwCleaner[S8].txt FRST.txt
  24. Well I managed to get my first virus in a decade due to negligence and being tired. Having a hell of a hard time actually getting rid of it though. I've formatted and reinstalled windows twice now each time I've ran Malwarebytes once and it finds ~170 threats that I quarantine, then 2 "Registry Value" PUP's repeatedly keep popping up. I've traced the Registry Key path that Malwarebytes gives me to a corrupted folder that contains what is being generated but even after deleting those in my Registry it continues to generate those 2 small PUP's from somewhere else but I don't have super in-depth knowledge of Registry files so it's hard to find the origin source. As i've said this is my first virus in a decade and i've never had one this deep so at this point i'm at a loss on what my actions are. I've enclosed a couple files including my malwarebytes report of the two PUP's in question, and a screenshot comparing the Registry Key being created & location to the Registry Value path that Malwarebytes leads me on. I'm hoping to maybe get some feedback on what I could be looking for in my registry (or if someone can spot it in my brief screenshot) or if there are any trusted programs that can help the registry? Or is my only option trying to Hardwipe everything with DBAN? If I used DBAN would it absolutely necessary to DBAN even my external HDD? Literally any help or feedback is appreciated, thank you. Addition.txt FRST.txt updatePUP.txt
  25. I recently installed Chrome onto my laptop in order to use a certain website (worldspinner), and Malwarebytes picked up its Web Data and Sync Data as a PUP. Since I have used Chrome in the past this should not be picking up as such, and I have not installed any suspicious/malicious extenstions either. Chrome's PUPs.txt
