PUP.Legacy.Optional

Hello,

Windows10 Chrome -- month ago got a malware popup when on tunein radio. Along with the following popup, a voice came on and said "your pc is infected with Malware, do not ignore this, etc:

** Zeus Virus Detected  - Your Computer Has Been Blocked **

Error: Trojan Backdoor Hijack #365838d7f8a4fa5

---------------------------------------------------------------------

After running adwcl...

False Positive v7?

Today I stumbled upon this detection whilst using Adwcleaner 7.0.1.0:

***** [ Registry ] *****

PUP.Optional.YahooChrome, [Key] - HKLM\SOFTWARE\Yahoo\SS

Afterwards I scanned with other virusscanners (Malwarebytes, MBAR, and Roguekiller) and none of them detected aforementioned registery key. Thus, it seems like a false positive generated by adwcleaner. 

Can someone confirm this?

Kind regard...

Re: False Positives V7

Herewith registry log:

***** [ Registry ] *****

PUP.Optional.SavepathDeals, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F66C7EC4-63CC-4452-A8C9-5A2E898F8EFF} PUP.Optional.SavepathDeals, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F8698E62-9284-432A-9C62-C1293A2B1DD3} Adware.BrowseFox, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\A...

My First Post: Are These Internet Explorer\ActiveX Compatibility Entries False Positives

# AdwCleaner 7.0.1.0 - Logfile created on Thu Aug 24 18:42:33 2017

# Updated on 2017/05/08 by Malwarebytes # Database: 08-22-2017.4 # Running on Windows 7 Professional (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

...

Re: False positives?

Still that same single result...

***** [ Registry ] *****

PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | ImageStoreRandomFolder [mv9xu40]

Re: More false positives

You know that, i know that, but a schoolstudent does not. As a servicedeskmanager i have been promoting adwcleaner for years on our schools but now it's causing confusion among collegues and other cliënts when adwcleaner is stating that there might be a problem or maybe something is a PUP while there isnt anything wrong. I understand there's a behavior pattern wich puts it in a categorie for ma...

Re: More false positives

Hello,

These detections are not FPs - please refer to this page to ask for changes.

Best regards,

Re: More false positives

Yesterday the Windows 10 machine from my wife was scanned by 7.0.1.0 and referred Zylom games and TryMedia as suspicious. Removal of it all led to no gaming anymore because these files (and dirs) are apearently necessary to run and check validation of the Zylom Games. Such a shame because a noob does not understand that.  

# AdwCleaner 7.0.1.0 - Logfile created on Mon Aug 21 19:08:44 2017 # Up...

Re: More false positives

Hello,

The beta version tells me: PUP.Optional.DriverBooster


snabbeltax, 2017-08-07 10:15:05 (UTC)

Can you share a logfile showing this?


fr33tux, 2017-08-23 00:30:14 (UTC)

# AdwCleaner 7.0.2.0 - Logfile created on Mon Aug 07 10:03:39 2017 # Updated on 2017/29/08 by Malwarebytes  # Database: 08-06-2017.2 # Running on Windows 10 Pro (X64) # Mode: scan # Support: https://www.malwarebytes....

Re: More false positives

Hello. Sure.

# AdwCleaner 7.0.2.0 - Logfile created on Wed Aug 23 17:39:18 2017 # Updated on 2017/29/08 by Malwarebytes # Database: 08-22-2017.2 # Running on Windows 7 Ultimate (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files...