Help with this Hijack / reg infection

Hi everybody,

I'am in trouble with an infection from a infected installation (all files, archives, download... from this has been removed).

After cleaning all suspicious programs on my compture (with CCleaner), I have clean up all caches files and repair the registre with it.

In third I do scan and clean up with the lasted version of Malwarebytes ; ADWcleaner ; Rkill and UnHackMe. Juste Male...

Re: Download and 3rd party providers

Not in particular. I was surfing other forums, Norton, Kaspersky and in general tech and cyber security forums, and a lot of people have installation issues. Even when downloading from your website and official sources. I have also read plenty of entries in this forum about people not being able to install the software properly

As for 3rd Party providers FileHippo??? uptodown? Cnet? Toms guide...

Re: Can I remove these folders/keys safely with adware cleaner?

PUP is a potentially unwanted program. Basically, something that comes with bundleware or through other sources. As fr33tux mentioned, you should just remove them and not worry about it much. In general, if you see something with WARE in scans, it is some form of malware.

Re: PUP.Legacy.Optional - 3 Threats Identified

Could be that you are a victim of bundleware. Basically, alongside normal maybe even useful software, some providers bundle malicious or useless software just to increase downloads and such. Have you downloading anything from 3rd party providers and not official sources?. Regardless of the fact, Malwarebytes or ADWCleaner should have picked it up and removed it, it could be much more thorough. ...

Re: After install Torch browser from the official page adwcleaner detects malware 18

Glad you solved the issue. Torch browser, unfortunately, is malware. It is what you would call Bundleware or PUP (Potentially unwanted program), usually bundled with other more used software as part to generate more file downloads and installs. In the future always select advanced or expert options when installing, usually, they are hidden after that one checkmark. Additionally, you can do regu...

Firefox prefs.js line detected as a threat

on AdwCleaner by Jkl

This line appears to be detected as a threat:

user_pref("extensions.Imagus.hz", "{\"deactivate\":1,\"actTrigger\":\"ctrl\",\"delay\":300,\"delayOnIdle\":true,\"zoomresized\":25,\"markOnHover\":\"dashed\",\"preload\":0,\"placement\":0,\"fullspace\":true,\"hiRes\":true,\"hiResOnFZ\":3,\"thumbAsBG\":false,\"thumbAsBGColor\":\"#c3c3c3\",\"thumbAsBGOpacity\":0.3,\"hideIdleCursor\":500,\"history\":t...

Re: Résultat analyse adwcleaner

Bonjour,

Il ne s'agit pas d'un faux-positif. L'élément fait parti d'un programme pré-installé sur votre PC. Il est classé en tant que bloatware/bundleware Vous trouverez la réponse complète en cliquant sur le lien suivant : https://forums.malwarebytes.com/topic/179314-jrt-deleted-two-files-that-i-think-are-false-positive/#comment-1021910

Le fait de retirer cet élément ne pose donc pas de prob...

Service trouvé: esgiguard ?

Bonjour à tous,

après avoir effectué ma dernière analyse avec adwcleaner, ce dernier me trouve un service "esgiguard" présent sur mon pc (sous windows 7 64bit).

Malewarebytes, ne trouve rien du tout !

mon antivirus "eset nod32" ne trouve absolument rien lui non plus.

zhpfix et zhpcleaner m'ont supprimé quelques malwares.

Il semblerait que "esgiguard" serait lié à "spyhunter", qui avait été...

Re: sqlite3 error

# DelFix v1.013 - Logfile created 04/10/2016 at 22:00:41
# Updated 17/04/2016 by Xplode
# Username : Lewlew - BLACKHOLE
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\FRST Deleted : C:\AdwCleaner Deleted : C:\RegBackup Deleted : C:\TDSSKiller.3.0.0.44_27.07.2015_01.54.57_log.txt Deleted : HKCU\conso...

Re: vrexjvx le chrome pirate310516

Bonjour,

Ce qui me reste est dans les logs de Malewarebytes :

Le premier ==   mbam-log-2016-05-25 (14-55-16)

-----------

<?xml version="1.0" encoding="UTF-16"?>

<mbam-log>

<header><date>2016/05/25 14:55:21 +0200</date><logfile>mbam-log-2016-05-25 (14-55-16).xml</logfile><isadmin>yes</isadmin></header>

<engine><version>2.2.1.1043</version><malware-database>v2016.05.25.04</malware-database...