Hi

I'm running the latest version of ADW cleaner and got this back as my report.

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.CrossRider, C:/Users\Gamefan\AppData\Roaming\app

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\MozillaPlugins\@pandonetworks.com/PandoWebPlugin

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

Are any of these False Positives?

I looked in the folder mentioned and I only see 2 files, Jerakine_lang_vesrion.dat and Jerakine_lang_vesrion.dat not sure what they do though. I analyzed them both on VirusTotal, and both came up clean

https://www.virustotal.com/en/file/e5ccfd8cc41402bb51e2dffe4e1378944e3a6ad12c97a9e7018dbb452be326b3/analysis/1500810478/

https://www.virustotal.com/en/file/57dc4adde8d4ed77f2749d34913fc43110c6a8072039822f78a7ac491e943661/analysis/1500810499/

I think the Legacy key is legit, since i think Pando is a legit program. I believe that key has been on my laptop for severalyeas an it hasn'tcaused any troublefrom what inknow

I ran Kaspersky's TDSS killer, Mcafee Rootkit remover Hitman Pro's free version, and JRT, none of them found anything. I scanned the folder with Mbam and Avast and it came up clean. No suspicious programs or Firefox Add-ons/plugins have been installed recently.

Either way can any of these be safely deleted with no harm to my pc?

Re: Potential false positives?

UPDATE: Just did a search for any Crossrider folders, didn't find anything. I think pando is used by several MMOs.

also Roguekiller and Mbam's threat scan didnt find anything

Re: Potential false positives?

PUP is usually named a Potentially Unwanted Program. It doesn't always have to be malware or malicious software. If MMO's have their anti-cheat in form of "Pando", it might interact with files at the system level, which AdwCleaner could deem treating a very normal reaction. Keep in mind that different malware removal software targets malicious software different ways. While one anti-malware software might not find anything, another can. If multiple scans with different anti-malware solutions came out clean on your end, you shouldn't worry then. It is just warning you of potential threats.

Re: Potential false positives?

PUP is usually named a Potentially Unwanted Program. It doesn't always have to be malware or malicious software. If MMO's have their anti-cheat in form of "Pando", it might interact with files at the system level, which AdwCleaner could deem treating a very normal reaction. Keep in mind that different malware removal software targets malicious software different ways. While one anti-malware software might not find anything, another can. If multiple scans with different anti-malware solutions came out clean on your end, you shouldn't worry then. It is just warning you of potential threats.


JoshRoss, 2017-07-24 10:05:26 (UTC)

Oh cool ran both a full and threat scan on mbam, AND did a boot time scan and rootkit scan in avast, they didn't find anythying either?

 

Safe to say these are all false positives? I don't see any Crossrider folders. I worry about any type of detection mainly because I'd rather not have anything that can sneak on to my usb drives I use to backup various stuff which would cause me to start back to square one since I don't know how to remove viruses from USB drives/external USB Hard Drives

Re: Potential false positives?

If they weren't detected as major threats or some form of issues you should be good to go. AdwCleaner should clean up any actually malicious software, but other than that, you don't need to worry. If you want, you can do a full thorough system scan just in case. Avast full scan. Mbam, AdwCleaner and Hitman Pro, additionally use CCleaner to clean up your registry and cache files and you are set!