Re: PUP \SysNative\drivers\mrxsmb22.sys

Using OSForensics again,

I found it here:

C>Windows>System32>drivers

Name                     Size

mrxsmb.22.sys       57 KB

And

C\AdwCleaner\Quarantine\

I then tracked it thru Manic Time to the exact time in seconds and found what happened at that time as confirmed adw, installer wnd.

What this was is a fake Cedrick Collomb Portable. Unlocker is only an Install.

Would not delete manua...

Re: Can anyone help me identify if any of these deleted registry keys are essential

Greetings,

First of all, sorry for the late answer.

Can you share the scan logfile as well? Thanks.

Regards.


cocochepeau, 2017-09-19 06:55:31 (UTC)

# AdwCleaner 7.0.2.1 - Logfile created on Sun Sep 10 01:05:26 2017 # Updated on 2017/29/08 by Malwarebytes  # Database: 09-08-2017.1 # Running on Windows 7 Home Basic (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [...

Computer Infected, AdwCleaner won't download

Hi, I have Windows 8 and I recently had my computer infected with the ShopAtHome toolbar and possibly other Malware. AdwCleaner won't even start to download, it just says failed. Can anyone help me? Is there an alternative download site?

Can anyone help me identify if any of these deleted registry keys are essential for windows?

# AdwCleaner 7.0.2.1 - Logfile created on Sun Sep 10 01:06:01 2017 # Updated on 2017/29/08 by Malwarebytes  # Running on Windows 7 Home Basic (X64) # Mode: clean # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\Users\lenovo\AppData\Local\Bundled software uninstaller Deleted: C:\Users\lenovo\AppData\Ro...

False positives?

Are these keys FPs? Could someone verify this? Thank you.

# AdwCleaner 7.0.0.0 - Logfile created on Sun Jul 23 10:21:28 2017 # Updated on 2017/17/07 by Malwarebytes # Database: 07-16-2017.1 # Running on Windows 7 Home Premium (X86) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders...

Re: Version 7 FPs (262 elements)

I have no proxies on either machine.

Just updated and ran scan - still same result as yesterday as below - 280 entires found!

The Chrome entries found are simply my personalisations for the Chrome start up page! Should definately not be selected or cleaned!

# AdwCleaner 7.0.0.0 - Logfile created on Fri Jul 21 08:26:44 2017 # Updated on 2017/17/07 by Malwarebytes # Database: 07-16-2017.1 # Ru...

Re: Version 7 FPs (262 elements)

sure, these are immunization entries detected from SpywareBlaster by AdwCleaner.

# AdwCleaner 7.0.0.0 - Logfile created on Fri Jul 21 15:18:41 2017 # Updated on 2017/17/07 by Malwarebytes # Database: 07-16-2017.1 # Running on Windows 7 Ultimate (X64) # Mode: scan # Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No...

Re: Version 7 FPs (262 elements)

Thanks. 10 reg keys are still detected.

***** [ Registry ] *****

PUP.Optional.GameVance, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{02F0243C-2E71-4A1A-A790-6C30888119D0} PUP.Optional.GameVance, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{AEB04B5E-C981-47A9-B847-33EE4C92F6B9} PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windo...

Re: Version 7 FPs (262 elements)

Thanks. AdwCleaner still detects 12 reg keys. One is the value I deliberately changed :

PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext | DisableAddonLoadTimePerformanceNotifications

 

***** [ Registry ] *****

PUP.Optional.GameVance, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{02F0243C-2E71-4A1A-A790-6C30888119D0} PUP.O...

Version 7 FPs (262 elements)

Version 6.047 finds nothing while version 7 finds 262 elements, mostly IE registry keys + one Firefox add-on.

Cookie Manager Button

https://addons.mozilla.org/en-US/firefox/addon/cookie-manager-button/?src=ss

Only new thing I installed recently is Adguard and it is set to work only with IE11. It is not running right now.

***** [ Registry ] *****

PUP.Optional.GameVance, [Key] - HKLM\SOFTWA...