Re: PUP.Legacy.Optional

Hi,

Don't panic, this is a classic "aggressive (scam) advertising" and a (real) false 'Zeus' alert! None zeus virus is present on your computer!

https://www.bleepingcomputer.com/virus-removal/remove-zeus-virus-detected-popups

https://blog.malwarebytes.com/threat-analysis/2017/06/the-numeric-tech-support-scam-campaign/

I've not seen yet MalwareBytes, ADWCleaner, HitmanPro, uBlock, adblock, a...

PUP.Legacy.Optional

Hello,

Windows10 Chrome -- month ago got a malware popup when on tunein radio. Along with the following popup, a voice came on and said "your pc is infected with Malware, do not ignore this, etc:

** Zeus Virus Detected  - Your Computer Has Been Blocked **

Error: Trojan Backdoor Hijack #365838d7f8a4fa5

---------------------------------------------------------------------

After running adwcl...

False Positive v7?

Today I stumbled upon this detection whilst using Adwcleaner 7.0.1.0:

***** [ Registry ] *****

PUP.Optional.YahooChrome, [Key] - HKLM\SOFTWARE\Yahoo\SS

Afterwards I scanned with other virusscanners (Malwarebytes, MBAR, and Roguekiller) and none of them detected aforementioned registery key. Thus, it seems like a false positive generated by adwcleaner. 

Can someone confirm this?

Kind regard...

Re: vers 7.0

vers 7.0.2 beta 5

now the tabs quarantine shwos the elements deleted..but there is only one option..to re have them in the pc..no way to delete them from there but only manually..

also for events logs..it shows but no way to delete them..only manually..:

 

i'd like to upload here the debug file but how to do it..??

Re: False Positives V7

ActiveX detection started after the new update. I am getting the same pop-ups. I can assure you it is not malware. ActiveX detections are usually guidelines for processes and services to follow. While they can be exploited, I doubt this is the case.

Re: My First Post: Are These Internet Explorer\ActiveX Compatibility Entries False Positives

ActiveX detections are usual FP's. Try doing an additional scan with Malwarebytes to confirm that. But I am fairly certain that these should not be detected. According to the internet and research that I did, ActiveX sets guidelines for processes, it can be exploited to some degree, but Adwcleaner would have removed them if found.

Re: False Positives V7

Herewith registry log:

***** [ Registry ] *****

PUP.Optional.SavepathDeals, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F66C7EC4-63CC-4452-A8C9-5A2E898F8EFF} PUP.Optional.SavepathDeals, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F8698E62-9284-432A-9C62-C1293A2B1DD3} Adware.BrowseFox, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\A...

My First Post: Are These Internet Explorer\ActiveX Compatibility Entries False Positives

# AdwCleaner 7.0.1.0 - Logfile created on Thu Aug 24 18:42:33 2017

# Updated on 2017/05/08 by Malwarebytes # Database: 08-22-2017.4 # Running on Windows 7 Professional (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

...

Re: False positives?

Still that same single result...

***** [ Registry ] *****

PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | ImageStoreRandomFolder [mv9xu40]

Re: More false positives

You know that, i know that, but a schoolstudent does not. As a servicedeskmanager i have been promoting adwcleaner for years on our schools but now it's causing confusion among collegues and other cliënts when adwcleaner is stating that there might be a problem or maybe something is a PUP while there isnt anything wrong. I understand there's a behavior pattern wich puts it in a categorie for ma...