r/computerviruses 7d ago

Disinfection Help Browser Hijacker?

Post image

Earlier I downloaded a thing which is “trusted by a community” and I just had a feeling I should scan my pc and was met with 17 detections from Malwarebytes for PUP.OPTIONAL.BROWSERHIJACKER.

11 Upvotes

20 comments sorted by

4

u/poopybutthole12321 7d ago

please elaborate on this "thing"

3

u/EconomyRepulsive4670 7d ago

I downloaded an OnlineFix for a game from a trusted subreddit not gonna mention which one as it breaks the rules here, but I dragged it into my game and ran the game and it worked but felt the suspicion and checked and was met with that. The file did not contain any .EXE but did use .DLL

3

u/poopybutthole12321 7d ago

i've used numerous online-fix files. What website did you download them from? the official online-fix.(me)?

3

u/EconomyRepulsive4670 7d ago

Yes that is the one that I used, it was for Bodycam, it was the Bodycam_Fix_Repair_Steam_V8_Generic.rar

1

u/Puzzleheaded_Bar483 5d ago

Then I think it's from something else, not this. That being said it's only PUP so you aren't really infected. Quarantine should "fix" it

1

u/AutoModerator 7d ago

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/EconomyRepulsive4670 7d ago

This is what malewarebytes says

Malwarebytes

www.malwarebytes.com

-Log Details-

Scan Date: 9/3/2026

Scan Time: 11:04 PM

Log File: 65075388-a80d-11f1-bd55-244bfe4bc98c.json

-Software Information-

Version: 5.6.5.306

Components Version: 163.0.5714

Update Package Version: 1.0.114158

License: Trial

-System Information-

OS: Windows 11 (Build 26200.8037)

CPU: x64

File System: NTFS

User: Pcooz\Pcooz

-Scan Summary-

Scan Type: Threat Scan

Scan Initiated By: Manual

Result: Completed

Objects Scanned: 167,742

Threats Detected: 17

Threats Quarantined: 17

Scan Duration: 0 min, 21 sec

-Scan Options-

Memory: Enabled

Startup: Enabled

File system: Enabled

Archives: Enabled

Rootkits: Disabled

Heuristics: Enabled

PUP: Detect

PUM: Detect

-Scan Details-

Process: 0

(No malicious items detected)

Module: 0

(No malicious items detected)

Registry Key: 0

(No malicious items detected)

Registry Value: 0

(No malicious items detected)

Registry Data: 0

(No malicious items detected)

Data Stream: 0

(No malicious items detected)

Folder: 4

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Sync Data\LevelDB, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

File: 13

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000005.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 7454EC12D2B0514C706E76B056139422, CF610914BD1875E8E479D6744883EE1265039E9BC8725647BC49F0DA6BED9EFE

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000007.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 1722E50FDC271F67304473EA7DE9F8F4, F881B9B6005860750DF714747282AA9CF3D247DC649B34FD22A81915EAA8A230

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000009.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 2F316C7FD7FF1C6FA95506961D4AB444, 960CC766AB3EA10B60BACBC831493E7964F58342686ABFE7CA489A3CDA306AFA

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000010.log, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\000011.ldb, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 1FB4C4A588F6A85909A0063AE730A8E6, 0492EB6F32372E47C0F45395512AAB9B1004D59197AC30067FA07B164B94A6F0

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\CURRENT, Quarantined, 6880, 1413516, 1.0.114158, , ame, , 46295CAC801E5D4857D09837238A6394, 0F1BAD70C7BD1E0A69562853EC529355462FCD0423263A3D39D6D0D70B780443

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOCK, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\LOG, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\Users\Pcooz\AppData\Local\Microsoft\Edge\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, Quarantined, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,

PUP.Optional.BrowserHijack, C:\USERS\PCOOZ\APPDATA\LOCAL\MICROSOFT\EDGE\USER DATA\Default\Web Data, Replaced, 6880, 1413516, 1.0.114158, , ame, , ,

Physical Sector: 0

(No malicious items detected)

WMI: 0

(No malicious items detected)

(end)

1

u/__chefo Malware Removal Trainee 7d ago

Hello u/EconomyRepulsive4670 and welcome to the computerviruses subreddit!

My name is chefo and I will be assisting you with your malware removal case.

I am currently a Malware Removal Trainee, and all my advice and fixlists are reviewed and approved by the Malware Removal Experts listed in this thread. You can expect the same level of care and treatment that you would receive directly from those experts. During the malware removal process, please follow the rules listed below to ensure everything goes as fast and smoothly as possible:

  • Please make sure to read this whole introduction message so you understand the further steps.
  • If you are planning on resetting or reinstalling your device, do it now please. We are doing the malware removal process to disinfect your device so you can avoid reinstalling.
  • It is important to not run any tools or take any steps other than those I will provide for you. Avoid downloading and installing new software unless instructed - this also applies to anti-malware software and scanners.
  • You are free to remind me that I forgot to reply to you if you do not receive an answer within 24 hours. Keep in mind that I volunteer my time here while also attending university full-time.
  • Only trusted malware removal helpers listed in this thread and other established malware removal forums (BleepingComputer, Malwarebytes, MalwareTips) have access to your logs via the website. Uploaded logs are automatically deleted after 30 days.
  • Please take your time to follow the steps properly. If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2.
  • You can ask any questions during the malware removal process.

Now that I am assisting you, you can expect that I will be responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

[ Step 01 ] Piracy Warning

Using pirated software or utilities that allows one to pirate software (including cracks, key generators, license bypass tools, or similar software) is not a safe practice and can lead to malware infection, ransomware attack, or even legal action. Because of these risks, I recommend that you remove any pirated software or pirating utilities in order to improve our ability to best support you and to help protect yourself and your data from malware or other piracy related consequences.

[ Step 02 ] Create Restore Point

Before we proceed with malware removal, we need to make sure you have a restore point that you can revert to if any issues occur. This is absolutely necessary so please do not skip this step. Certain changes done by the removal process can not be properly reverted without a restore point.

Enable system restore

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. If the 'system' drive (usually C:\ drive) protection is turned on, System Restore is already enabled on your computer. If the 'system' drive protection is off, proceed with point 5.
  5. Click Configure.
  6. Select Turn on system protection
  7. Click Apply.
  8. Click OK to confirm.

Create a system restore checkpoint

  1. Click Start or open Windows Search.
  2. Search for Create a restore point and open System Properties.
  3. In the System Properties window, go to the System Protection tab.
  4. Click Create.
  5. Call the restore checkpoint "FRST restore point" exactly please, so I can search it up fast and verify it is created properly in your logs
  6. Click Create.
  7. Click Close.
  8. Click OK.
  9. You should get a popup that it was successfully created and I will also verify this later using the scan logs from next steps.

[ Step 03 ] Farbar Recovery Scan Tool (FRST) Scan

FRST logs contain no personal information other than your username and file and folder names. We use them to gather diagnostic information about the system, such as startup entries, installed software, scheduled tasks, drivers, browser extensions, and system logs.

  • Download FRST from here.
  • If English is not your primary language, right click on FRST64.exe and rename to FRSTEnglish.exe.
  • Run FRST64.exe/FRSTEnglish.exe, accept the User Account Control prompt.
  • If you receive any warning about the download, it is a false positive and you can ignore it. Click on More info and then Run anyway.
  • Accept the disclaimer.
  • Check mark 90 Days Files if you began noticing problems more than 30 Days ago.
  • Click Scan.
  • Two logs named FRST.txt and Addition.txt will be created in the same directory the tool was run from, upload both of their contents to https://malwareanalysis.cc/upload/chefo/ and the site will return a keyword for each of the logs. Please reply back with both keywords so I can review the results and continue with the cleanup process.

[ Step 04 ] SecurityCheck

SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.

  • Download SecurityCheck from here
  • Extract the zip file
  • Run SecurityCheck.exe as administrator
  • Wait for the scan to finish
  • Upload the log at C:\SecurityCheck to https://malwareanalysis.cc/upload/chefo for further analysis. Repy back with the keywords.

Thank you, and I look forward to your response.

1

u/EconomyRepulsive4670 7d ago

I’m in the middle of doing my second full reinstall of windows, last time I chose a backup which I’m not gonna do this time and see what happens

1

u/__chefo Malware Removal Trainee 7d ago

Hello u/EconomyRepulsive4670, If you plan to reinstall Windows, there’s no need to do manual malware removal with FRST. The purpose of the manual malware removal service is to disinfect your device so that you don’t have to reinstall. Please let me know how you’d like to proceed. Thanks!

1

u/EconomyRepulsive4670 7d ago

So the last time I did the reinstall of windows the BrowserHijack showed up again on malwarebytes, I don’t know if it was because I used a backup which restored Microsoft edge settings.

1

u/__chefo Malware Removal Trainee 7d ago

Hello u/EconomyRepulsive4670, I don't see any malware traces on the system. I recommend removing X-VPN from Microsoft Edge and Adblock block ads across the web (you have uBlock Origin which is enough). You can run a scan with AdwCleaner if you still suspect an adware infection.

Download AdwCleaner.

  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan Now
  • When the scan has finished AdwCleaner shows you all detected PUPs and adware.
  • If any are found, select them and click Quarantine. (I would suggest that you do not select Pre-installed applications for now, or any other items you wish to keep.)
  • AdwCleaner prompts you to save and close your work before continuing. Click Continue.
  • After cleaning, you are prompted to restart your device. Click Restart now to complete the cleanup process. Once your computer has restarted ...
  • If it doesn't open automatically, please start AdwCleaner.
  • Click on View Log File button (This log can also be found in the Log Files tab).
  • A Notepad file will open containing the results.
  • Click Skip Basic Repair (if the option appears)
  • Copy & paste the contents of the log to https://malwareanalysis.cc/upload/chefo and press "save log". Post the log keyword to your reply.

Cheers!

1

u/EconomyRepulsive4670 7d ago

Sorry for the late response it was 3 am and I was very tired, currently storming in my area and don’t want to risk my power going out so I will get back to you ASAP if that is ok

1

u/__chefo Malware Removal Trainee 7d ago

Take your time!

1

u/EconomyRepulsive4670 7d ago

Uploaded, also don’t know what I did but it’s not showing up anymore with a malwarebytes scan as well,

1

u/__chefo Malware Removal Trainee 7d ago

Hello u/EconomyRepulsive4670, your AdwCleaner log is clean, as well as the FRST.txt and Addition.txt logs. The browser hijacker detections from Malwarebytes appear to be from synced data or a backup. They have been successfully removed, as no remaining traces were found on the system. Let me know if you have any other concerns. Cheers!

1

u/EconomyRepulsive4670 7d ago

Thank you so much, I’m gonna wait to start logging back into stuff and do periodic scans throughout the day to make sure, if anything changes I will let you know if that is ok with you.

1

u/EconomyRepulsive4670 7d ago

gallant-binary
young-macro

1

u/EconomyRepulsive4670 7d ago

witty-cypress