Elektroda.com
Elektroda.com
X

Removing Wirus PUP.optional Legacy, Adware.File Tour, SSD/HDD Issues & Malwarebyte Scans

dada41728 3258 6
This content has been translated flag-pl » flag-en View the original version here.
  • #1
    dada41728
    Level 3  
    Hello. Generally, today I was looking for a program and I downloaded it through the download assistant. Suddenly the computer began to cut like never before. I have the system on SSD and data on HDD. Use indicated 100 percent. I downloaded the Malwarebyte program and found out that I have 2,000 viruses. I cleared it however, popup.optional.mailru still appears. I am totally powerless. The computer on startup still does not work as before. Antivirus programs block websites that I visit, although I don't do it ... You can hear that the hard disk is strangely loud - it works. Strange ads appear on pages.
    I'm a little scared because when I had this virus the system did a long update when I turned on the computer again. Could the virus hide itself between these files?
    After scanning Malwarebytes, I kind of remove this virus and it appears again ...

    I have already read many other posts on the subject but the problem after restarting the computer still appears. I am a total like. Thank you in advance for your help and I ask for detailed step-by-step advice on how to perform the given task. Regards
  • #2
    dt1
    Admin of Computers group
    Hello.
    If a colleague read many posts about, then at this point a colleague would already have scanned and removed problems found with adwcleaner -> https://toolslib.net/downloads/viewdownload/1-adwcleaner/ - and also, after this operation, would have A colleague downloaded the FRST program, from which logs are needed to help a colleague remove the infection (using the FRST program in posts in this section is really hard to miss).

    FRST can be downloaded here: https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/ (you must run, do not change options, do a scan, insert the generated two text files in the attachment).

    After catching up with this arrears, you can move on with the topic.
  • #3
    dada41728
    Level 3  
    Thank you so much for the advice. I would like to announce that the programs you proposed have also been used only in a wrong way. Instead of scanning in this FRST, I made a folder and copied something to a notebook and later repaired it, but it probably didn't make sense. ADW also removed something from me, but later the problem appeared again. I add the attachment in the main subject.
  • Helpful post
    #4
    Kolobos
    IT specialist
    Wykonaj Fixlist.txt dla FRST:
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> Brak pliku
    Task: {3090344C-6362-45E9-A906-DCFE9CC49161} - System32\Tasks\{B60B51CB-998F-4F2A-A101-27B6CE9A1320} => C:\WINDOWS\system32\pcalua.exe -a "d:\Program Files (x86)\Hi-Rez Studios\HiRezGamesDiagAndSupport.exe" -c uninstall=17
    Task: {587A73E3-ED71-433A-8FCE-3775F14F760B} - \Microsoft\Windows\UNP\RunCampaignManager -> Brak pliku C:\Program Files\Tracker Software\Update\TrackerUpdate.exe [2016-01-18] (Tracker Software Products (Canada) Ltd.)
    Task: C:\WINDOWS\Tasks\TrackerAutoUpdate.job => C:\Program Files\Tracker Software\Update\TrackerUpdate.exe-CheckUpdate(Tracker Software Products (Canada) Ltd.Kee
    GroupPolicy: Ograniczenia "chrome-extension://lfgkmlldjpjacgicdjmmgcboihbghpal/visual-bookmarks.html"
    CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B3CAEDA96-5174-4654-B4DF-3D12B91DB174%7D&gp=811142
    CHR DefaultSearchKeyword: Default -> go.mail.ru
    CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/chrome?q={searchTerms}
    C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie
    CHR Extension: (ScriptGate) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeocknbjpmfgaclencnfjfkklmmfmiie [2017-12-20]
    C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgkmlldjpjacgicdjmmgcboihbghpal
    CHR Extension: (Пульс) - C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfgkmlldjpjacgicdjmmgcboihbghpal [2017-12-20]
    CHR HKLM-x32\...\Chrome\Extension: [lfgkmlldjpjacgicdjmmgcboihbghpal] - hxxps://clients2.google.com/service/update2/crx
    2017-12-21 01:23 - 2017-12-21 01:25 - 000000000 ____D C:\AdwCleaner
    2017-12-20 14:41 - 2017-12-20 14:41 - 000000000 ____D C:\Users\user\AppData\LocalLow\Unity
    2017-12-20 14:41 - 2017-12-20 14:41 - 000000000 ____D C:\Users\user\AppData\Local\Unity
    2017-12-20 14:40 - 2017-12-20 14:40 - 000000001 _____ C:\Users\user\AppData\Local\WMI.ini
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001237 _____ C:\Users\user\AppData\Local\EJTYEHsqLn
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001157 _____ C:\Users\user\AppData\Local\plOoTpkih
    2017-12-20 14:40 - 2017-03-18 21:58 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\8962582.exe
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001237 _____ () C:\Users\user\AppData\Local\EJTYEHsqLn
    2017-03-18 21:59 - 2017-03-18 21:59 - 000001237 _____ () C:\Users\user\AppData\Local\EJTYEHsqLn.bat
    2017-12-20 14:40 - 2017-03-18 21:59 - 000001157 _____ () C:\Users\user\AppData\Local\plOoTpkih
    2017-03-18 21:59 - 2017-03-18 21:59 - 000001157 _____ () C:\Users\user\AppData\Local\plOoTpkih.bat
    2017-12-20 14:40 - 2017-12-20 14:40 - 000000001 _____ () C:\Users\user\AppData\Local\WMI.ini

    Po wykonaniu usun katalog C:\FRST.
  • #5
    dada41728
    Level 3  
    And how should I do it exactly because I don't understand ...
  • Helpful post
    #6
    dt1
    Admin of Computers group
    In the directory where you have the frst tool create in the notebook a file called fixlist.txt, the content of this file was given by Kolega Kolobos above. Once you have created this file, run frst again and press repair. Frst will find the fixlist.txt file and based on it will remove the identified irregularities.
  • #7
    dada41728
    Level 3  
    Thank you so much for helping the topic to close.