logo elektroda
logo elektroda
X
logo elektroda

Removing Wirus PUP.optional Legacy, Adware.File Tour, SSD/HDD Issues & Malwarebyte Scans

dada41728 3738 6
ADVERTISEMENT
Treść została przetłumaczona polish » english Zobacz oryginalną wersję tematu
  • #1 16904423
    dada41728
    Level 3  
    Hello. Generally, today I was looking for a program and I downloaded it through the download assistant. Suddenly the computer began to cut like never before. I have the system on SSD and data on HDD. Use indicated 100 percent. I downloaded the Malwarebyte program and found out that I have 2,000 viruses. I cleared it however, popup.optional.mailru still appears. I am totally powerless. The computer on startup still does not work as before. Antivirus programs block websites that I visit, although I don't do it ... You can hear that the hard disk is strangely loud - it works. Strange ads appear on pages.
    I'm a little scared because when I had this virus the system did a long update when I turned on the computer again. Could the virus hide itself between these files?
    After scanning Malwarebytes, I kind of remove this virus and it appears again ...

    I have already read many other posts on the subject but the problem after restarting the computer still appears. I am a total like. Thank you in advance for your help and I ask for detailed step-by-step advice on how to perform the given task. Regards
  • ADVERTISEMENT
  • #2 16904475
    dt1
    Admin of Computers group
    Hello.
    If a colleague read many posts about, then at this point a colleague would already have scanned and removed problems found with adwcleaner -> https://toolslib.net/downloads/viewdownload/1-adwcleaner/ - and also, after this operation, would have A colleague downloaded the FRST program, from which logs are needed to help a colleague remove the infection (using the FRST program in posts in this section is really hard to miss).

    FRST can be downloaded here: https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ (you must run, do not change options, do a scan, insert the generated two text files in the attachment).

    After catching up with this arrears, you can move on with the topic.
  • ADVERTISEMENT
  • #3 16904819
    dada41728
    Level 3  
    Thank you so much for the advice. I would like to announce that the programs you proposed have also been used only in a wrong way. Instead of scanning in this FRST, I made a folder and copied something to a notebook and later repaired it, but it probably didn't make sense. ADW also removed something from me, but later the problem appeared again. I add the attachment in the main subject.
  • Helpful post
    #4 16904943
    Kolobos
    IT specialist
    Wykonaj Fixlist.txt dla FRST:
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    Task: {3090344C-6362-45E9-A906-DCFE9CC49161} - System32\Tasks\{B60B51CB-998F-4F2A-A101-27B6CE9A1320} => C:\WINDOWS\system32\pcalua.exe -a "d:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=17
    Task: {587A73E3-ED71-433A-8FCE-3775F14F760B} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku C:\Program Files\Tracker Software\Update\TrackerUpdate.exe [2016-01-18] (Tracker Software Products (Canada) Ltd.)
    Task: C:\WINDOWS\Tasks\TrackerAutoUpdate.job => C:\Program Files\Tracker Software\Update\TrackerUpdate.exe-CheckUpdate(Tracker Software Products (Canada) Ltd.Kee
    GroupPolicy: Ograniczenia "chrome-extension://lfgkmlldjpjacgicdjmmgcboihbghpal/visual-bookmarks.html"
    CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B3CAEDA96-5174-4654-B4DF-3D12B91DB174%7D&gp=811142
    CHR DefaultSearchKeyword: Default -> go.mail.ru
    CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
    C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie
    CHR Extension: (ScriptGate) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2017-12-20]
    C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgkmlldjpjacgicdjmmgcboihbghpal
    CHR Extension: (Пульс) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgkmlldjpjacgicdjmmgcboihbghpal [2017-12-20]
    CHR HKLM-x32\...\Chrome\Extension: [lfgkmlldjpjacgicdjmmgcboihbghpal] - hxxps://clients2.google.com/service/update2/crx
    2017-12-21 01:23 - 2017-12-21 01:25 - 000000000 ____D C:\AdwCleaner
    2017-12-20 14:41 - 2017-12-20 14:41 - 000000000 ____D C:\Users\user\AppData\LocalLow\Unity
    2017-12-20 14:41 - 2017-12-20 14:41 - 000000000 ____D C:\Users\user\AppData\Local\Unity
    2017-12-20 14:40 - 2017-12-20 14:40 - 000000001 _____ C:\Users\user\AppData\Local\WMI.ini
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001237 _____ C:\Users\user\AppData\Local\EJTYEHsqLn
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001157 _____ C:\Users\user\AppData\Local\plOoTpkih
    2017-12-20 14:40 - 2017-03-18 21:58 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\8962582.exe
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001237 _____ () C:\Users\user\AppData\Local\EJTYEHsqLn
    2017-03-18 21:59 - 2017-03-18 21:59 - 000001237 _____ () C:\Users\user\AppData\Local\EJTYEHsqLn.bat
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001157 _____ () C:\Users\user\AppData\Local\plOoTpkih
    2017-03-18 21:59 - 2017-03-18 21:59 - 000001157 _____ () C:\Users\user\AppData\Local\plOoTpkih.bat
    2017-12-20 14:40 - 2017-12-20 14:40 - 000000001 _____ () C:\Users\user\AppData\Local\WMI.ini

    Po wykonaniu usun katalog C:\FRST.
  • ADVERTISEMENT
  • #5 16905059
    dada41728
    Level 3  
    And how should I do it exactly because I don't understand ...
  • ADVERTISEMENT
  • Helpful post
    #6 16905108
    dt1
    Admin of Computers group
    In the directory where you have the frst tool create in the notebook a file called fixlist.txt, the content of this file was given by Kolega Kolobos above. Once you have created this file, run frst again and press repair. Frst will find the fixlist.txt file and based on it will remove the identified irregularities.
  • #7 16910352
    dada41728
    Level 3  
    Thank you so much for helping the topic to close.

Topic summary

The discussion revolves around a user experiencing severe performance issues on their computer after downloading a program, leading to the detection of numerous viruses by Malwarebytes. Despite attempts to remove the infections, including the persistent popup.optional.mailru, the problems continue, with the hard disk making unusual noises and strange ads appearing. Recommendations include using AdwCleaner and the Farbar Recovery Scan Tool (FRST) to generate logs for further analysis and removal of the malware. The user is guided on creating a fixlist.txt file for FRST to address identified irregularities effectively.
Summary generated by the language model.
ADVERTISEMENT