Re: New user - puzzling behaviour

Greetings terrypin,

first of all, sorry for the delay of my answer.

1. Deleted folder

I don't understand how I should interpret these entries: ***** [ Folders ] *****

[-] Folder Deleted : C:\Docs\radio
[!] Folder Not Deleted : C:\Docs\radio
[!] Folder Not Deleted : C:\Docs\radio

terrypin, 2015-09-14 07:46:49 (UTC)

Folder is deleted one time but AdwCleaner just made some duplicates by mi...

Some other false positive entries ("New Tab Redirect" Chrome add-on) ?

Hello all,

AdwCleaner (last version: 5.007) found 3 following entries:

***** [ Dossiers ] *****

Dossier Trouvé : C:\Users\###\AppData\Local\Google\Chrome\User Data\Default\Extensions\icpgjfneehieebagbmdbhnlpiopdcmna

***** [ Fichiers ] *****

Fichier Trouvé : C:\Users\###\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\icpgjfneehieebagbmdbhnlpiopdcmna

***** [ Navigat...

Re: submit samples

on AdwCleaner by ****

in particular i wanted to raise awareness about some firefox adware/malware which is showing up rather frequently as an addon with a randomized id and name which hides itself from the addons manager which is going undetected at the moment.

you can find some samples of the amlicious addon's .xpi file attached at https://bugzilla.mozilla.org/show_bug.cgi?id=1161259

Re: submit samples

Hello,

hi & thank you for your tool. is there any documented way to submit malicious samples to be included in future detection?


madperson, 2015-09-08 19:05:31 (UTC)

Nevertheless, don't hesitate to use this forum for submitting feedbacks.

Regards,

Probably FP

on AdwCleaner by ****

Hi / Salut,

2 détections :

***** [ Fichiers ] *****

Fichier Trouvé : C:\WINDOWS\Sysnative\drivers\mcaudrv_x64.sys Fichier
Trouvé : C:\WINDOWS\Sysnative\drivers\mcvidrv.sys

Virustotal :

https://www.virustotal.com/fr/file/609f805a80e535b7b1bc01a6e63377a78d7c72ea8de8d44730a29e5d9f516c22/analysis/1441911053/

https://www.virustotal.com/fr/file/b4b06b17f687be591275d80d63e3f648cac9d34dd83c80af5...

Re: HP Client Security Manager détecté par AdwCleaner. Faux positif ?

Bonjour Xplode,

Est-ce que tu as eu l'occasion de regarder les détails du mail que je t'ai envoyé ?

J'espère qu'il ne s'est pas perdu parmi les nombreux autres mails que tu reçois ou parmi les spams.

submit samples

on AdwCleaner by ****

hi & thank you for your tool. is there any documented way to submit malicious samples to be included in future detection?

Re: HP Client Security Manager détecté par AdwCleaner. Faux positif ?

Bonjour Xplode,

Merci pour ta réactivité.

Je t'ai par email le contenu du dossier "C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncffjdbbodifgldkcbhmiiljfcnbgjab" ainsi qu'une autre petite question.

Re: HP Client Security Manager détecté par AdwCleaner. Faux positif ?

Bonjour,

Il s'agit d'un faux positif. La détection a été retirée de la base de données.

Cordialement,

Re: ADWCleaner deleted a folder it shouldn't

Hello,

Can you please provide us with AdwCleaner's logfile so that we will be able to remove it from the database or update our detections ?

You can write a script to restore many files at once. Just put one line per file to restore ( you can extract the lines from Quarantine.log file ) and use "Script" option in Quarantine manager. Put only the original location of each file in your script.

...