Jump to content

PUP.Optional.Legacy keeps coming back


Recommended Posts

Malwarebytes told me about something called Bazz search in my Google Chrome folder, so I just completely got rid of chrome and that got rid of that detection, but now AdwCleaner is telling me about this PUP.Optional.Legacy in my firefox folder. It comes back each time I quarantine/delete it, and I'd like to know how to get rid of it for good.

I've attached my AdwCleaner log, and my FRST.txt and Addition.txt logs.

FRST.txt Addition.txt AdwCleaner[S04].txt

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

I suspect that this is a Sync issue.
Check it out.

If the problem persists in Firefox and you are Syncing with other Devices reset it.
https://support.mozilla.org/en-US/kb/how-do-i-set-sync-my-computer

When all is well you can re-sync your devices.

Let me know if the problem is solved or not.

Link to post
Share on other sites

Hi,

Lets see what we can find in the Registry.

Run the Farbar program .exe as an Administrator.

In the Search text area, copy and paste the following:
suggestqueries
Once done, click on the Search Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====

Link to post
Share on other sites

On 3/8/2019 at 8:56 AM, nasdaq said:

Hi,

Lets see what we can find in the Registry.

Run the Farbar program .exe as an Administrator.

In the Search text area, copy and paste the following:
suggestqueries
Once done, click on the Search Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====

Sorry I took so long to reply, I'm not sure if I did this right. Here's the whole log:

Farbar Recovery Scan Tool (x64) Version: 11.03.2019
Ran by Dinghy (12-03-2019 06:58:53)
Running from C:\Users\Dinghy\Downloads
Boot Mode: Normal

================== Search Registry: "suggestqueries" ===========


====== End of Search ======

Link to post
Share on other sites

Hi,

This is set in the Firefox preferences.

To remove it it completely, remove and reinstall Firefox.

Before proceeding save your Bookmarks. (Export)
https://support.mozilla.org/en-US/kb/export-firefox-bookmarks-to-backup-or-transfer

Firefox Password manager - Import your passwords.
Password Manager - Remember, delete, change and import saved passwords in Firefox
https://support.mozilla.org/en-US/kb/password-manager-remember-delete-change-and-import#w_protecting-your-passwords

(if Needed)
If the problem persists in Firefox and you are Syncing with other Devices reset it.
https://support.mozilla.org/en-US/kb/how-do-i-set-sync-my-computer

When all is well you can re-sync your devices.


Clean the Firefox Cache.
https://kb.iu.edu/d/ahic#firefox

Remove Firefox using the instructions one this page.
https://support.mozilla.org/en-US/kb/uninstall-firefox-from-your-computer

Restart the computer normally.

Install the latest version of the application.
https://www.mozilla.org/en-US/firefox/new/

Import your Bookmarks. Same link as the Export function above.

Restart the computer normally.

Link to post
Share on other sites

  • 2 weeks later...
  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.