logo elektroda
logo elektroda
X
logo elektroda

PUP Optional Legacy & Softonic Assistant: AdwCleaner & Malwarebytes Solutions (09/28/2017)

Mateocantana 6702 10
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16727935
    Mateocantana
    Level 7  
    Hello yesterday (28/09/2017) I noticed when I scanned adwc computer something like PUP optional legacy, PUP optional softonic assistant like adwc it deleted but when it scans again it is the same again, malwarebytes also didn't help, I decided to use FRST but I completely don't see what I have there to do in other topics I saw that it helped others and I don't know what's going on as if someone could help in advance thanks.
  • ADVERTISEMENT
  • #2 16727956
    Kolobos
    IT specialist
    Manually delete the file and do not download "download assistants" for future use, such programs install malicious add-ons.
  • #3 16727963
    Mateocantana
    Level 7  
    And how do I know which file I can't find it? As I type in the search engine, there is nothing
  • ADVERTISEMENT
  • #4 16727966
    Kolobos
    IT specialist
    What are you looking for? After all, the program that detects it displays the full path to the file. As long as it is a file, not e.g. an entry in the registry.
  • #5 16727977
    Mateocantana
    Level 7  
    Well adwc doesn't show me this and in this frst I don't know what's going on PUP Optional Legacy & Softonic Assistant: AdwCleaner & Malwarebytes Solutions (09/28/2017)
  • ADVERTISEMENT
  • #6 16728005
    Kolobos
    IT specialist
    Post logs from FRST, that scan in the attachment.
  • #7 16728015
    Mateocantana
    Level 7  
    Logs already in the attachment.
  • ADVERTISEMENT
  • #8 16728042
    Kolobos
    IT specialist
    To tylko jeden log, gdzie jest addition.txt?

    Obok frst.exe utworz plik Fixlist.txt z zawartoscia:
    BHO: Brak nazwy -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> Brak pliku
    BHO-x32: Brak nazwy -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> Brak pliku
    CHR Extension: (Lone Tree) - C:\Users\Mateusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip [2017-09-29]
    C:\Users\Mateusz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfmkllfplegemejikoabfpjdaoncphip
    2017-09-29 14:06 - 2017-01-22 21:18 - 000000000 ____D C:\AdwCleaner
    Task: {0A3A87DF-52C3-4295-A41E-CA895908E7CF} - System32\Tasks\{551CAC08-E0BC-4E23-BACE-DCCC83351095} => C:\Windows\system32\pcalua.exe -a "C:\Users\Mateusz\Downloads\Setup (1).exe" -d C:\Users\Mateusz\Downloads
    Task: {3692DD77-04D2-450B-BE31-64520694A98A} - System32\Tasks\{BA65F2DF-EE26-4B39-8534-137C1BD6A40E} => C:\Windows\system32\pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe"
    Task: {62696EBC-BE1F-4593-8E64-B8A5F5274307} - System32\Tasks\{BE1A8493-13D0-495E-B39A-1180111C08C9} => C:\Windows\system32\pcalua.exe -a C:\Users\Mateusz\Downloads\Setup.exe -d C:\Users\Mateusz\Downloads
    Task: {85D1CB88-2322-480E-9595-65EEAA0CBCA6} - System32\Tasks\{57A798E2-41F9-4C97-BF92-227D18E2949A} => C:\Windows\system32\pcalua.exe -a E:\display\DRIVERS\Installation\Setup.exe -d E:\display\DRIVERS\Installation
    Task: {9BF7C1CA-6D99-49EC-8614-F833DF06C352} - System32\Tasks\{3ED3E615-821E-40CE-9985-33700B9394E0} => C:\Program Files (x86)\LG Electronics\OnScreen Control\bin\OnScreen Control.exe [2016-05-18] (LG Electronics Inc.)
    Task: {E9917D53-D856-4729-AFA2-D2D0DB2C9A84} - System32\Tasks\{A557DAA4-DE62-4575-B0A0-B67140D62291} => C:\Windows\system32\pcalua.exe -a "C:\Users\Mateusz\Downloads\Setup (3).exe" -d C:\Users\Mateusz\Downloads

    W FRST wybierz Napraw.
  • #9 16728046
    Mateocantana
    Level 7  
    Okay, that's all now.
  • Helpful post
    #10 16728054
    Kolobos
    IT specialist
    If it still detects these pages in Chrome, make a copy of the bookmarks and delete the browser's profile directory from C: \ Users \ Mateusz \ AppData \ Local \ Google \ Chrome \ User Data \ Default
  • #11 16728114
    Mateocantana
    Level 7  
    Thanks to everything working you had to delete this default file and google account syncs and everything works.

Topic summary

The discussion revolves around persistent detection of PUP (Potentially Unwanted Programs) labeled as "optional legacy" and "Softonic Assistant" by AdwCleaner and Malwarebytes. The user reports that despite attempts to remove these threats, they reappear after rescanning. Suggestions include manually deleting the associated files and avoiding download assistants that may install malicious add-ons. The user is advised to post logs from FRST (Farbar Recovery Scan Tool) for further analysis. A solution is provided to delete the Chrome browser's profile directory to eliminate persistent detections, which ultimately resolves the issue for the user.
Summary generated by the language model.
ADVERTISEMENT