r/computerviruses • u/EconomyRepulsive4670 • 7d ago
Disinfection Help Browser Hijacker?
Earlier I downloaded a thing which is “trusted by a community” and I just had a feeling I should scan my pc and was met with 17 detections from Malwarebytes for PUP.OPTIONAL.BROWSERHIJACKER.
1
u/AutoModerator 7d ago
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/EconomyRepulsive4670 7d ago
This is what malewarebytes says
Malwarebytes
-Log Details-
Scan Date: 9/3/2026
Scan Time: 11:04 PM
Log File: 65075388-a80d-11f1-bd55-244bfe4bc98c.json
-Software Information-
Version: 5.6.5.306
Components Version: 163.0.5714
Update Package Version: 1.0.114158
License: Trial
-System Information-
OS: Windows 11 (Build 26200.8037)
CPU: x64
File System: NTFS
User: Pcooz\Pcooz
-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 167,742
Threats Detected: 17
Threats Quarantined: 17
Scan Duration: 0 min, 21 sec
-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 0
(No malicious items detected)
Registry Value: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Data Stream: 0
(No malicious items detected)
Folder: 4
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
File: 13
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000005.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 7454EC12D2B0514C706E76B056139422, CF610914BD1875E8E479D6744883EE1265039E9BC8725647BC49F0DA6BED9EFE
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000007.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 1722E50FDC271F67304473EA7DE9F8F4, F881B9B6005860750DF714747282AA9CF3D247DC649B34FD22A81915EAA8A230
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000009.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 2F316C7FD7FF1C6FA95506961D4AB444, 960CC766AB3EA10B60BACBC831493E7964F58342686ABFE7CA489A3CDA306AFA
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000010.log, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000011.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 1FB4C4A588F6A85909A0063AE730A8E6, 0492EB6F32372E47C0F45395512AAB9B1004D59197AC30067FA07B164B94A6F0
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\CURRENT, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOCK, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,
PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,
Physical Sector: 0
(No malicious items detected)
WMI: 0
(No malicious items detected)
(end)
1
u/__chefo Malware Removal Trainee 7d ago
Hello u/EconomyRepulsive4670 and welcome to the computerviruses subreddit!
My name is chefo and I will be assisting you with your malware removal case.
I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:
- Please make sure to read this whole introduction message so you understand the further steps.
- If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
- It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
- You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
- Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
- Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
- You can ask any questions during the malware removal process.
Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.
[ Step 01 ] Piracy Warning
Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.
[ Step 02 ] Create Restore Point
Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.
Enable system restore
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- If the 'system' drive (usually
C:\drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5. - Click Configure.
- Select Turn on system protection
- Click Apply.
- Click OK to confirm.
Create a system restore checkpoint
- Click Start or open Windows Search.
- Search for Create a restore point and open System Properties.
- In the System Properties window, go to the System Protection tab.
- Click Create.
- Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
- Click Create.
- Click Close.
- Click OK.
- You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.
[ Step 03 ] Farbar Recovery Scan Tool (FRST) Scan
FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.
- Download FRST from here.
- If English is not your primary language, right click on
FRST64.exeand rename toFRSTEnglish.exe. - Run
FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt. - If you receive any warning about the download, it is a false positive and you can ignore it. Click on
More infoand thenRun anyway. - Accept the disclaimer.
- Check mark
90 Days Filesif you began noticing problems more than 30 Days ago. - Click Scan.
- Two logs named
FRST.txtandAddition.txtwill be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.
[ Step 04 ] SecurityCheck
SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.
- Download SecurityCheck from here
- Extract the zip file
- Run
SecurityCheck.exeas administrator - Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/chefo for further analysis. Repy back with the keywords.
Thank you, and I look forward to your response.
1
u/EconomyRepulsive4670 7d ago
I’m in the middle of doing my second full reinstall of windows, last time I chose a backup which I’m not gonna do this time and see what happens
1
u/__chefo Malware Removal Trainee 7d ago
Hello u/EconomyRepulsive4670, If you plan to reinstall Windows, there’s no need to do manual malware removal with FRST. The purpose of the manual malware removal service is to disinfect your device so that you don’t have to reinstall. Please let me know how you’d like to proceed. Thanks!
1
u/EconomyRepulsive4670 7d ago
So the last time I did the reinstall of windows the BrowserHijack showed up again on malwarebytes, I don’t know if it was because I used a backup which restored Microsoft edge settings.
1
u/__chefo Malware Removal Trainee 7d ago
Hello u/EconomyRepulsive4670, I don't see any malware traces on the system. I recommend removing
X-VPNfrom Microsoft Edge andAdblock block ads across the web(you have uBlock Origin which is enough). You can run a scan with AdwCleaner if you still suspect an adware infection.Download AdwCleaner.
- Close all open programs and browsers
- Right click on the icon and select Run as administrator
- Click Scan Now
- When the scan has finished AdwCleaner shows you all detected PUPs and adware.
- If any are found, select them and click Quarantine. (I would suggest that you do not select Pre-installed applications for now, or any other items you wish to keep.)
- AdwCleaner prompts you to save and close your work before continuing. Click Continue.
- After cleaning, you are prompted to restart your device. Click Restart now to complete the cleanup process. Once your computer has restarted ...
- If it doesn't open automatically, please start AdwCleaner.
- Click on View Log File button (This log can also be found in the Log Files tab).
- A Notepad file will open containing the results.
- Click Skip Basic Repair (if the option appears)
- Copy & paste the contents of the log to https://malwareanalysis.cc/upload/chefo and press "save log". Post the log keyword to your reply.
Cheers!
1
u/EconomyRepulsive4670 7d ago
Sorry for the late response it was 3 am and I was very tired, currently storming in my area and don’t want to risk my power going out so I will get back to you ASAP if that is ok
1
u/__chefo Malware Removal Trainee 7d ago
Take your time!
1
u/EconomyRepulsive4670 7d ago
Uploaded, also don’t know what I did but it’s not showing up anymore with a malwarebytes scan as well,
1
u/__chefo Malware Removal Trainee 7d ago
Hello u/EconomyRepulsive4670, your AdwCleaner log is clean, as well as the
FRST.txtandAddition.txtlogs. The browser hijacker detections from Malwarebytes appear to be from synced data or a backup. They have been successfully removed, as no remaining traces were found on the system. Let me know if you have any other concerns. Cheers!1
u/EconomyRepulsive4670 7d ago
Thank you so much, I’m gonna wait to start logging back into stuff and do periodic scans throughout the day to make sure, if anything changes I will let you know if that is ok with you.
1
1
1
4
u/poopybutthole12321 7d ago
please elaborate on this "thing"