logo elektroda
logo elektroda
X
logo elektroda

AdwCleaner & PUP.optional Legacy Virus: Removal & Prevention Tips after PC Reset

Grzechu126 4020 15
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16694142
    Grzechu126
    Level 5  
    Hello, when I scan the pc with the adwcleaner program, he finds me this virus, the problem is that after removing and resetting the computer the virus still appears. I am asking for help in getting rid of this virus.
  • ADVERTISEMENT
  • #2 16694150
    Kolobos
    IT specialist
    It's not a virus.

    Post the log with adwc and the required logs from FRST in the attachment.
  • ADVERTISEMENT
  • ADVERTISEMENT
  • #4 16694187
    Kolobos
    IT specialist
    Still addition.txt.

    You have reset your sync in Chrome as you have given it -> https://support.google.com/chrome/answer/3097271?

    If after doing and using adwc you still don't delete it, delete the entire chrome profile directory. Save bookmarks beforehand.

    Fixlist.txt for FRST:
    HKU \ S-1-5-21-2895471607-1423486506-844269107-1000 \ ... \ MountPoints2: H - H: \ SETUP.EXE
    HKU \ S-1-5-21-2895471607-1423486506-844269107-1000 \ ... \ MountPoints2: {10559e18-c2be-11e6-9be9-d8cb8abed04e} - F: \ HTC_Sync_Manager_PC.exe
    HKU \ S-1-5-21-2895471607-1423486506-844269107-1000 \ ... \ MountPoints2: {12f7f3d6-f8fe-11e6-b389-d8cb8abed04e} - H: \ SETUP.EXE
    HKU \ S-1-5-21-2895471607-1423486506-844269107-1000 \ ... \ MountPoints2: {712600c9-a696-11e6-8c63-806e6f6e6963} - E: \ _ AUTORUN \ AUTORUN.EXE
    HKU \ S-1-5-21-2895471607-1423486506-844269107-1000 \ ... \ MountPoints2: {beb6cba7-ca94-11e6-b162-d8cb8abed04e} - G: \ SETUP.EXE
    CHR StartupUrls: Default -> "", "hxxp: //www.interia.pl/#utm_source=instalki1&utm_medium=installer&utm_campaign=instalki1&iwa_source=installer_installation"
    CHR HKLM-x32 \ ... \ Chrome \ Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps: //clients2.google.com/service/update2/crx
    S3 MSICDSetup; \ ?? \ E: \ CDriver64.sys [X]
    S3 NTIOLib_1_0_C; \ ?? \ E: \ NTIOLib_X64.sys [X]
    S3 VGPU; System32 \ drivers \ rdvgkmd.sys [X]
    2017-09-11 20:59 - 2016-11-11 01:10 - 000000000 ____D C: \ AdwCleaner
    EmptyTemp:
  • #6 16694198
    Kolobos
    IT specialist
    Change Adobe Reader 9 to the latest AR.
  • ADVERTISEMENT
  • #7 16694209
    Grzechu126
    Level 5  
    I have already downloaded but did it help?
  • #9 16694225
    Grzechu126
    Level 5  
    ok, i already did that, something else?
  • #10 16694231
    Kolobos
    IT specialist
    If it's ok, just delete the C: \ FRST directory and that's it.
  • #11 16694237
    Grzechu126
    Level 5  
    but it still shows me so I don't know if it's a virus or not?
  • #13 16694279
    Grzechu126
    Level 5  
    I've already reset the synchronization and what about the folder to remove all its contents?

    Added after 20 [minutes]:

    I deleted this folder, started the chrome, reset everything but still nothing worked.
  • #14 16694396
    krzychupar
    Level 43  
    Post new logs from FRST.
  • #15 16694481
    Grzechu126
    Level 5  
    The problem itself disappeared when I reinstalled chroma and installed windows updates, so it wasn't a virus.
  • #16 16694620
    Kolobos
    IT specialist
    I wrote to you at the beginning that it was not a virus. This is just a changed default search engine.

Topic summary

The discussion revolves around the persistent detection of a PUP.optional Legacy issue by AdwCleaner, even after the user has attempted removal and reset their PC. Initial responses clarify that the detected item is not a virus but rather a changed default search engine or browser setting. Users are advised to reset Chrome synchronization, delete the Chrome profile directory, and ensure all bookmarks are backed up. The problem was ultimately resolved by reinstalling Chrome and applying Windows updates, confirming that it was not a virus but a configuration issue.
Summary generated by the language model.
ADVERTISEMENT