Re: PUP.Legacy.Optional

Hi,

Don't panic, this is a classic "aggressive (scam) advertising" and a (real) false 'Zeus' alert! None zeus virus is present on your computer!

https://www.bleepingcomputer.com/virus-removal/remove-zeus-virus-detected-popups

https://blog.malwarebytes.com/threat-analysis/2017/06/the-numeric-tech-support-scam-campaign/

I've not seen yet MalwareBytes, ADWCleaner, HitmanPro, uBlock, adblock, a...

PUP.Legacy.Optional

Hello,

Windows10 Chrome -- month ago got a malware popup when on tunein radio. Along with the following popup, a voice came on and said "your pc is infected with Malware, do not ignore this, etc:

** Zeus Virus Detected  - Your Computer Has Been Blocked **

Error: Trojan Backdoor Hijack #365838d7f8a4fa5

---------------------------------------------------------------------

After running adwcl...

False Positive v7?

Today I stumbled upon this detection whilst using Adwcleaner 7.0.1.0:

***** [ Registry ] *****

PUP.Optional.YahooChrome, [Key] - HKLM\SOFTWARE\Yahoo\SS

Afterwards I scanned with other virusscanners (Malwarebytes, MBAR, and Roguekiller) and none of them detected aforementioned registery key. Thus, it seems like a false positive generated by adwcleaner. 

Can someone confirm this?

Kind regard...

Re: extansion .no_more_ransom

Future here! Hopefully, you will be able to understand this in English. Decided, to surf some older posts and add some information to what we now know. 2 Vendors currently have a decryptor for it as part of the "No More Ransom" project (Not related to this extension, this extension is just mocking). You can find Kaspersky's and McAfee's versions respectively. Additionally, you can read more abo...

Re: More false positives

You know that, i know that, but a schoolstudent does not. As a servicedeskmanager i have been promoting adwcleaner for years on our schools but now it's causing confusion among collegues and other cliënts when adwcleaner is stating that there might be a problem or maybe something is a PUP while there isnt anything wrong. I understand there's a behavior pattern wich puts it in a categorie for ma...

Re: More false positives

Yesterday the Windows 10 machine from my wife was scanned by 7.0.1.0 and referred Zylom games and TryMedia as suspicious. Removal of it all led to no gaming anymore because these files (and dirs) are apearently necessary to run and check validation of the Zylom Games. Such a shame because a noob does not understand that.  

# AdwCleaner 7.0.1.0 - Logfile created on Mon Aug 21 19:08:44 2017 # Up...

Re: More false positives

Try using the beta, see if that elevate the false positives. However, if your software is obtained in illegitimate ways (I know music software can get quite expensive), it might have some form of virus or malware attached to it. You can never discount the possibility.

Re: Launchpage infection

Hopefully, you can understand English or google translate this. I know this is an old forum, but since it doesn't have a definitive answer, I'd like to share my experience and a solution. My friend had a similar couple of weeks ago. You are dealing with a redirect virus or some form of adware. Quite annoying really. I have used Malwarebytes and Adwcleaner to elevate the issue alongside these in...

Re: Jaff virus?

Utilisez Data Recovery Pro ou Rakhni decryptor pour restaurer les fichiers cryptés par le rançongiciel Jaff. Data Recovery Pro est unun outil automatique qui peut effectuer ce travail à votre place. Vous pouvez il ou Rahini décrypteur conçu par Kaspersky Lab en cliquant ici: http://www.2-spyware.com/remove-jaff-ransomware-virus.html

N'oubliez d'exécuter une analyse supplémentaire de votre syst...

Re: Start\Windows icon

Have you noticed anything else weird/out of the ordinary on your PC? Can you try booting into Windows "Safe mode with networking" and see if you can do any of the actions through that. Otherwise, I would recommend doing a thorough malware check just in case.

Full and thorough malware check:

1. Restart your PC in “Safe mode with networking.” 2. Install and run RKill to kill malicious processes...