Jump to content

Registry Key Adware Keeps Coming Back


Recommended Posts

  • Replies 50
  • Created
  • Last Reply

Top Posters In This Topic

  • Root Admin

Create an Autoruns Log:

  • Please download Sysinternals Autoruns from here.
  • Save Autoruns.exe to your desktop and double-click it to run it.
  • Once it starts, please press the Esc key on your keyboard.
  • Now that scanning is stopped, click on the Options button at the top of the program and select Verify Code Signatures and Check VirusTotal.com and Submit Unknown Images
  • Once that's done press the F5 key on your keyboard, this will start the scan again, this time let it finish.
  • When it's finished, please click on the File button at the top of the program and select Save and save the Autoruns.arn file to your desktop and close Autoruns.
  • Right-click on the Autoruns.arn file on your desktop and hover your mouse over Send To and select Compressed (zipped) Folder
  • Attach the Autoruns.zip folder you just created to your next reply

 

image.png

 

Thanks

 

Link to post
Share on other sites

  • Root Admin

Please review the following and perform a clean up of Google Chrome settings

Once that is done we'll run one more extensive clean up script. This has to be from an extension or setting in Google Chrome that is allowing it to come back I'm reasonably sure.

 

 

Link to post
Share on other sites

  • Root Admin

I'd still like you to run the ESET antivirus scan as well to ensure it too finds nothing.

I'll repost the information below.

 

 

 

Let me have you run a different scanner to double-check. I don't expect it to find anything, but no harm in checking.

I would suggest a free scan with the ESET Online Scanner

Go to https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe

  • It will start a download of "esetonlinescanner.exe"
  • Save the file to your system, such as the Downloads folder, or else to the Desktop.
  • Go to the saved file, and double click it to get it started. 
  • When presented with the initial ESET options, click on "Computer Scan".
  • Next, when prompted by Windows, allow it to start by clicking Yes 
  • When prompted for scan type, Click on Full scan 
  • Look at & tick  ( select )   the radio selection "Enable ESET to detect and quarantine potentially unwanted applications"   and click on Start scan button.
  • Have patience.  The entire process may take an hour or more. There is an initial update download.
  • There is a progress window display.
  • You should ignore all prompts to get the ESET antivirus software program.   ( e.g.  their standard program).   You do not need to buy or get or install anything else.
  • When the scan is completed, if something was found, it will show a screen with the number of detected items.  If so, click the button marked “View detected results”.
  • Click The blue “Save scan log” to save the log.
  • If something was removed and you know it is a false finding, you may click on the blue ”Restore cleaned files”  ( in blue, at bottom).
  • Press Continue when all done.  You should click to off the offer for “periodic scanning”.

 

 

Link to post
Share on other sites

  • Root Admin

Please go ahead and uninstall all versions and plugins for Adobe Flash Player. That has been discontinued

As expected the ESET log did not find anything either. This would appear to almost have to be caused from some type of object in your Chrome Browser.

Please follow these directions and clean up Google Chrome.

Let me know how that goes please.

Also, you can manually delete that Registry key

 

 

Link to post
Share on other sites

I set microsoft edge to my default browser, uninstalled the registry key, and restarted my computer. After the restart I checked the registry and the key was not there. I only used microsoft edge, but eventually the adware opened internet explorer and displayed ads. I then checked the registry and sure enough the key was there again.

Link to post
Share on other sites

  • Root Admin

Okay, do some more testing.

Delete the registry key. Restart the computer.

Then do not run any browser or other app. Start Regedit and see if the key is back on it's own after a reboot.

Assuming it's not back. See if you can use the computer for a couple hours WITHOUT opening any browser. Keep Regedit open and press the F5 key to refresh it and see if that key comes back or not.

If it does not come back, then launch your browser and keep watching the Registry to see if it comes back.

We can run some other programs to try and track it down but it's gets a bit more complex so let's see if we can catch it this way.

Let me know

 

Link to post
Share on other sites

I deleted the reg key and restarted the computer. On the restart the key was not there, so I used only application programs and now browsers for 2 hours. The key did not reappear during the 2 hours. I then briefly opened microsoft edge to check if the key would appear as soon as edge is opened, but it did not appear. After that, I opened chrome to see if they key would immediately appear after opening chrome, and it did not. I then left chrome open and about 5-7 minutes after chrome was open, the adware opened internet explore and displayed ads. Sure enough, the key was back in the registry after I checked it.

 

From what I can gather it is definitely correlated to browsers being opened. Also, the moment the key reappears it displays ads. The adware does not remain dormant, it immediately executes what it is supposed to do if the key and deleted and then reappears. 

 

We know chrome likely causes the key to reappear and I'm fairly certain edge does as well, but I can run another test to verify this if you think it is needed.

Link to post
Share on other sites

  • Root Admin

Well at this point I'd like to try and do a full uninstall and forced removal of Google Chrome.

Please save all bookmarks or other items needed and I'll give you a script to force a removal of Google Chrome.

For the moment please download Firefox and use that as your default browser before we remove Chrome.

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.