I must be infected by a virus! PUP.Optional.StartPage

Solved
zentone -  
bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   -

Hello.

malwarebytes report:

Malwarebytes
www.malwarebytes.com

-Log details-
Scan date: 04/18/2024
Scan duration: 07:06
Log file: 73a4e0be-fd41-11ee-96b0-74563c67983e.json

-Software information-
Version: 4.6.12.323
Component version: 1.0.2309
Update pack version: 1.0.83573
License: Free

-System information-
Operating system: Windows 10 (Build 19045.4291)
Processor: x64
File system: NTFS
User: DESKTOP-BUUFLJM\terri

-Scan summary-
Scan type: Threat scan
Scan initiated by: Manual
Result: Completed
Objects scanned: 281333
Threats detected: 4
Threats quarantined: 4
Time elapsed: 1 min, 34 s

-Scan options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristic: Enabled
PUP: Detection
PUM: Detection

-Scan details-
Processes: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry key: 0
(No malicious items detected)

Registry value: 2
PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTOFFERTHROUGHWUAU, Quarantined, 7622, 676880, 1.0.83573, , ame, , ,
PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTOFFERTHROUGHWUAU, Quarantined, 7622, 676880, 1.0.83573, , ame, , ,

Registry data: 0
(No malicious items detected)

Data stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 2
PUP.Optional.StartPage, C:\USERS\TERRI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AQH0CQ9F.DEFAULT-RELEASE\PREFS.JS, Replaced, 257, 1172032, 1.0.83573, , ame, , 4D1A205F879B4482944B3A1BAE195C89, 3C6326E0C6A81F5C4F0CEBB17F003F7FD6BFE931CC7B9643F6AE33C959F8D943
PUP.Optional.StartPage, C:\USERS\TERRI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AQH0CQ9F.DEFAULT-RELEASE\PREFS.JS, Replaced, 257, 1172033, 1.0.83573, , ame, , 4D1A205F879B4482944B3A1BAE195C89, 3C6326E0C6A81F5C4F0CEBB17F003F7FD6BFE931CC7B9643F6AE33C959F8D943

Physical sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

my config:

windows 10
i5 13400f
b760 gaming x ddr4
16 gb ram
m2 500gb
kingston ssd 120gb
seagate barracuda 1tb
nvidia geforce gtx 1060 6gb
lepa mx f1 550w power supply
27 inch 1440p 144hz monitor

Thank you in advance for your help.


13 answers

  1. zentone
     

    Hello.

    Thank you for your help!

    Malwarebytes doesn't find anything anymore, however since this problem, I have significant FPS drops in my games, I don't know if there's a connection.

    0
  2. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
     

    No, it has nothing to do with a simple pup in Firefox.

    In the MBAM report, we see that apart from a few pups, there was nothing infectious on your PC.

    Following the repair of Firefox and MBAM no longer detecting anything, I am marking the post as resolved.

    0
  3. zentone
     

    I ran a malwarebytes test and it found this:

    Malwarebytes
    www.malwarebytes.com

    -Log Details-
    Scan Date: 04/18/2024
    Scan Duration: 17:22
    Log File: 73c98436-fd97-11ee-8941-74563c67983e.json

    -Software Information-
    Version: 4.6.12.323
    Component Version: 1.0.2309
    Update Package Version: 1.0.83591
    License: Free

    -System Information-
    Operating System: Windows 10 (Build 19045.4291)
    Processor: x64
    File System: NTFS
    User: DESKTOP-BUUFLJM\terri

    -Scan Summary-
    Scan Type: Threat Scan
    Scan Launched By: Manual
    Result: Completed
    Objects Scanned: 284228
    Threats Detected: 4
    Threats Quarantined: 0
    Time Elapsed: 0 min, 56 s

    -Scan Options-
    Memory: Enabled
    Startup: Enabled
    File System: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Detection
    PUM: Detection

    -Scan Details-
    Processes: 0
    (No malicious items detected)

    Module: 0
    (No malicious items detected)

    Registry Key: 0
    (No malicious items detected)

    Registry Value: 2
    PUM.Optional.DisableMRT, HKLM\SOFTWARE\WOW6432NODE\POLICIES\MICROSOFT\MRT|DONTOFFERTHROUGHWUAU, No user action, 7622, 676880, 1.0.83591, , ame, , ,
    PUM.Optional.DisableMRT, HKLM\SOFTWARE\POLICIES\MICROSOFT\MRT|DONTOFFERTHROUGHWUAU, No user action, 7622, 676880, 1.0.83591, , ame, , ,

    Registry Data: 0
    (No malicious items detected)

    Data Streams: 0
    (No malicious items detected)

    Folder: 0
    (No malicious items detected)

    File: 2
    Malware.AI.3548691727, C:\USERS\TERRI\APPDATA\LOCAL\TEMP\F775CBC4-B758-4344-A608-2287CF54956D_WITCHFIRE V0.2.2 EARLY ACCESS(1).ZIP.56D\WITCHFIRE V0.2.2 EARLY ACCESS - INSTALLER.EXE, No user action, 1000000, -746275569, 1.0.83591, D869C6E0B71FB838D384BD0F, dds, 02785744, 31EC00B6FF1B93380C224760C5B04290, 64A007CD1A89669A1849519255C99073A05DDC6FBCCBD341F345B93A743DD977
    Malware.AI.3548691727, C:\USERS\TERRI\APPDATA\LOCAL\TEMP\RAR$EXA14216.14478\LORDS OF THE FALLEN DELUXE EDITION V1.1.664-P2P - INSTALLER.EXE, No user action, 1000000, -746275569, 1.0.83591, D869C6E0B71FB838D384BD0F, dds, 02785744, 31EC00B6FF1B93380C224760C5B04290, 64A007CD1A89669A1849519255C99073A05DDC6FBCCBD341F345B93A743DD977

    Physical Sector: 0
    (No malicious items detected)

    WMI: 0
    (No malicious items detected)


    (end)

    0
  4. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
     

    These are among other things files downloaded via P2P software, apparently pirated games, to check your PC:

    Download FRST.

    Once downloaded save it on the desktop then right-click on FRST and select Run as administrator you will see this:

    Wait for the message the tool is ready to run to appear and then click on Analyze


    Warning, wait for the message indicating that the scan is complete to appear.

    At the end of the scan you will have two text files on the desktop FRST and Addition.

    Then send the FRST and ADDITION reports to https://www.cjoint.com/ and provide the two links generated by https://www.cjoint.com/ in your reply.


    bazfile
    Moderator/Security Contributor.
    A hello, a response, a thank you is always appreciated.

    0
  5. zentone
     

    Hello. I can't install frst64!

    This application cannot run on your PC.

    0
  6. zentone
     

    hello.

    attached are the links:

    https://www.cjoint.com/c/NDtmFZZ2Yzt

    https://www.cjoint.com/c/NDtmHhRmeVt

    0
  7. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
     

    No infection on your PC, what Malwarebytes detects are just games you downloaded, not active processes, the found files are in the Windows temporary folder.

    There are just a few obsolete processes, if you want to delete them, follow the instructions below.

    Procedure to follow in the order indicated:

    1- Open FRST as an administrator to do this, right-click on FRST and choose run as administrator
    2 - Copy the entire script in the box below:

      Start:: CreateRestorePoint: CloseProcesses: HKLM-x32\...\Run: [] => [X] HKU\S-1-5-21-3094595401-900069884-2822542233-1001\...\Run: [BitTorrent] => "C:\Users\terri\AppData\Roaming\BitTorrent\BitTorrent.exe" /MINIMIZED (No file) HKU\S-1-5-21-3094595401-900069884-2822542233-1001\...\Run: [Pinaview] => C:\Users\terri\AppData\Local\Programs\Pinaview\Pinaview.exe (No file) HKU\S-1-5-21-3094595401-900069884-2822542233-1001\...\Run: [EstimateSpeedUp] => "C:\Users\terri\AppData\Local\EstimateSpeedUp\EstimateSpeedUp.exe" -startup (No file) Task: {5838E8C9-C29B-4E21-9891-3E7028B6FFD9} - System32\Tasks\Opera scheduled Autoupdate 1685181508 => C:\Users\terri\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (No file) R2 GigabyteUpdateService; %SystemRoot%\system32\GigabyteUpdateService.exe 2\c:\windows\system32\ [X] S1 ibbhtpao; \??\C:\Windows\system32\drivers\ibbhtpao.sys [X] S3 rsDwf; \SystemRoot\system32\DRIVERS\rsDwf.sys [X] S3 VBAudioVMAUXVAIOMME; \SystemRoot\System32\drivers\vbaudio_vmauxvaio64_win10.sys [X] S3 VBAudioVMVAIOMME; \SystemRoot\System32\drivers\vbaudio_vmvaio64_win10.sys [X] Shortcut: C:\Users\terri\Desktop\launchmod_eldenring - Shortcut.lnk -> D:\SteamLibrary\steamapps\common\ELDEN RING\Game\mods\ModEngine-2.0.0-preview3-win64\launchmod_eldenring.bat (No file) Shortcut: C:\Users\terri\AppData\Roaming\Microsoft\Windows\Start Menu\launchmod_eldenring - Shortcut.lnk -> D:\SteamLibrary\steamapps\common\ELDEN RING\Game\mods\ModEngine-2.0.0-preview3-win64\launchmod_eldenring.bat (No file) cmd: netsh advfirewall reset EmptyTemp: End::

    3- Once the script is copied, click on Fix, FRST automatically takes the script in the clipboard.


    Allow the correction to take place, once it is done, you will be asked to restart your PC, do so as soon as prompted, see below.

    Then once your computer is restarted:
    4- You will have a Fixlog file on your desktop, then send this fixlog report to https://www.cjoint.com/ then provide the generated link from https://www.cjoint.com/ in your reply.


    bazfile
    Moderator/Security Contributor.
    A hello, a response, a thank you are always appreciated.

    0
  8. zentone
     

    ok.

    here it is:

    https://www.cjoint.com/c/NDtpXHJTN7t

    0
  9. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
     

    The fixlog is OK, it allowed you to recover 28.9 GB of space on your C drive, which was really necessary, as there were a lot of useless temporary files filling up your C drive, which is an SSD.

    Uninstall FRST, rename the FRST file that you downloaded to uninstall, then once the file is renamed, open it; the uninstallation will occur automatically via a restart of the PC.


    bazfile
    Moderator/Security Contributor.
    a greeting, a response, a thank you are always appreciated.

    0
  10. zentone
     

    Okay, it's done.

    0
    1. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
       

      As for the security forum, that will be all.

      0
  11. zentone
     

    Hello.

    Everything is fine, thank you again for your help.

    0
    1. bazfile Posted messages 58496 Registration date   Status Moderator Last intervention   20 273
       

      You're welcome.

      See you on CCM.

      0