Re: False Positive v7?

Interesting development. Thanks for the logs, as expected they are clean. Successful removal could indicate that Adwcleaner stopped the threat further or was a false positive. Honestly, everything related to Yahoo is a massive security hole for me, and I would avoid it as much as possible. 

Upon further investigation, this looks like malware's registry file that wasn't removed correctly, but t...

Re: version 5.016 ..... FP with Spyware blaster active x registry entries

ActiveX is used for Microsoft services. I am fairly certain that this is a false positive. There have been a number of threads about the ActiveX issue, still waiting for confirmation from representatives.

Re: PUP.Legacy.Optional

Thanks Bernard. Good point on adding to firewall if happens again. Was thinking same thing -- that it's not a real hijack or spyware. Glad to hear it from somebody with more IT proficiency. It only happens on one specific station on tunein, and I listen to a bunch so seems site specific. 

Re: PUP.Legacy.Optional

Hi,

Don't panic, this is a classic "aggressive (scam) advertising" and a (real) false 'Zeus' alert! None zeus virus is present on your computer!

https://www.bleepingcomputer.com/virus-removal/remove-zeus-virus-detected-popups

https://blog.malwarebytes.com/threat-analysis/2017/06/the-numeric-tech-support-scam-campaign/

I've not seen yet MalwareBytes, ADWCleaner, HitmanPro, uBlock, adblock, a...

Re: version 5.016 ..... FP with Spyware blaster active x registry entries

I'm running adwcleaner version 7.0.1.0 and this is an issue even now and has been in the last few versions of adwcleaner.

It started with the version where you changed the programs interface.

Most of the time Adwcleaner finds five internet explorer active x registry entries but sometimes it can be over a hundred and the next time it's back to five again even though I have not done anything th...

Re: False Positives V7

Since V7 I've been getting false positives on all my machines - often ones reported by others.  I suspect they are down to using SypwareBlaster.  This is an old but quite safe program which puts kill bits in the registry to prevent undesireable stuff running.  I think it would be worth installing SpywareBlaster then "enabling all protection", then see what ADWCleaner makes of it.  Thanks.


SWB...

False Positives V7

Since V7 I've been getting false positives on all my machines - often ones reported by others.  I suspect they are down to using SypwareBlaster.  This is an old but quite safe program which puts kill bits in the registry to prevent undesireable stuff running.  I think it would be worth installing SpywareBlaster then "enabling all protection", then see what ADWCleaner makes of it.  Thanks.

Re: extansion .no_more_ransom

Future here! Hopefully, you will be able to understand this in English. Decided, to surf some older posts and add some information to what we now know. 2 Vendors currently have a decryptor for it as part of the "No More Ransom" project (Not related to this extension, this extension is just mocking). You can find Kaspersky's and McAfee's versions respectively. Additionally, you can read more abo...

Re: More false positives

You know that, i know that, but a schoolstudent does not. As a servicedeskmanager i have been promoting adwcleaner for years on our schools but now it's causing confusion among collegues and other cliënts when adwcleaner is stating that there might be a problem or maybe something is a PUP while there isnt anything wrong. I understand there's a behavior pattern wich puts it in a categorie for ma...

Re: More false positives

Yesterday the Windows 10 machine from my wife was scanned by 7.0.1.0 and referred Zylom games and TryMedia as suspicious. Removal of it all led to no gaming anymore because these files (and dirs) are apearently necessary to run and check validation of the Zylom Games. Such a shame because a noob does not understand that.  

# AdwCleaner 7.0.1.0 - Logfile created on Mon Aug 21 19:08:44 2017 # Up...