Help with PUP trovi AND Conduit

Status
Not open for further replies.

damaza90

New Member
Thread author
Oct 5, 2020
7
As the title hints, I have tried getting rid of these two PUPs, I tried ADW and Malwarebytes even on safe boots mode, these buggers keep coming back.

Would love some help
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

[/b][/b]Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Wait for further instructions
 

damaza90

New Member
Thread author
Oct 5, 2020
7
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

[/b][/b]Download the Farbar Recovery Scan Tool (FRST).
Choose the 32 or 64 bit version for your system.
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file:
In the Reply section in the bottom of the topic Select Click the Attach Files.
Navigate to the location of the File.
Click the file. It will appear in the reply section.
Click the Post Reply button.

Please post the logs for my review.

Wait for further instructions
 

Attachments

  • Addition.txt
    14.1 KB · Views: 6
  • FRST.txt
    77.2 KB · Views: 7

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

Your logs are clean.

Try this.

If the problem persists and Chrome is Synced with other Devices reset it.



Execute the suggested fix.

Restart the computer normally.
===========

Is the problem solved?
 

damaza90

New Member
Thread author
Oct 5, 2020
7
Hi,

Your logs are clean.

Try this.

If the problem persists and Chrome is Synced with other Devices reset it.



Execute the suggested fix.

Restart the computer normally.
===========

Is the problem solved?
No It did not, both still come back after ADW, Malwarebytes and SYNC clean up
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
HI,

Your copy of Chrome may have been compromised

Remove and re-install Chrome. Follow these instructions.


[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step1.gif[/URL]] Remove Chrome from your Computer and reinstall a fresh copy later.

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step2.gif[/URL]] If you remove the syncing of your account you must remove it before you save your bookmarks etc...
Delete Your Google Chrome Browser Sync Data if you sync with other devices. <- Important ...

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step3.gif[/URL]] Before you remove Chrome Export your Bookmarks
Chrome will export your bookmarks as a HTML file, which you can then import into another browser.
How To: How To Back Up Your Google Chrome Bookmarks

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step4.gif[/URL]] Before you remove Chrome Export your Passwords
How to export your saved passwords from Chrome

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step5.gif[/URL]] Clear your Chrome cache and cookies

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step6.gif[/URL]] Remove Chrome using the the instructions on this page.

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step7.gif[/URL]] Re-install Chrome and the Bookmarks and passwords.
<<<>>

Is the problem solved?
 

damaza90

New Member
Thread author
Oct 5, 2020
7
HI,

Your copy of Chrome may have been compromised

Remove and re-install Chrome. Follow these instructions.


[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step1.gif[/URL]] Remove Chrome from your Computer and reinstall a fresh copy later.

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step2.gif[/URL]] If you remove the syncing of your account you must remove it before you save your bookmarks etc...
Delete Your Google Chrome Browser Sync Data if you sync with other devices. <- Important ...

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step3.gif[/URL]] Before you remove Chrome Export your Bookmarks
Chrome will export your bookmarks as a HTML file, which you can then import into another browser.
How To: How To Back Up Your Google Chrome Bookmarks

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step4.gif[/URL]] Before you remove Chrome Export your Passwords
How to export your saved passwords from Chrome

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step5.gif[/URL]] Clear your Chrome cache and cookies

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step6.gif[/URL]] Remove Chrome using the the instructions on this page.

[img=[URL]https://www.bleepingcomputer.com/forums/public/style_emoticons/default/step7.gif[/URL]] Re-install Chrome and the Bookmarks and passwords.
<<<>>

Is the problem solved?
No, Both still come back, I noticed however that If I clean up and re-install. After using certain pages e.g youtube I start getting pop ups blocked by the blockers I have and then the PUPs come back. Might there be a link about it?
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Do you consider these as popups or some type of notifications?


Please post the Fixlog.txt and let me know what problem persists.

p.s.
You should disable alll you Chrome extension.
Enable the one at a time you may be able to identify is one of them is the culprit.
 

Attachments

  • fixlist.txt
    227 bytes · Views: 1

damaza90

New Member
Thread author
Oct 5, 2020
7
Hi,

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

Do you consider these as popups or some type of notifications?


Please post the Fixlog.txt and let me know what problem persists.

p.s.
You should disable alll you Chrome extension.
Enable the one at a time you may be able to identify is one of them is the culprit.
So both still return, I Disabled all the extensions. Still went on youtube ran ADW cleaner and still found both PUPs. I resorted to uninstalling Chrome, and tested doing the same thing on Edge browser. After using youtube and running ADW again. nothing shows up. Seems the problem is with chrome?
 

Attachments

  • Fixlog.txt
    1,019 bytes · Views: 2

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

The extension may be managed by your organization

Disable "Your browser is managed by your organization: message

Read this article.
You should find the "Managed by your organization" at the bottom of the Menu.

Follow the recommendations on this page.


===

Let me know if the problem is solved.

If not solved can you give me some information on these popups?
 

damaza90

New Member
Thread author
Oct 5, 2020
7
Hi,

The extension may be managed by your organization

Disable "Your browser is managed by your organization: message

Read this article.
You should find the "Managed by your organization" at the bottom of the Menu.

Follow the recommendations on this page.


===

Let me know if the problem is solved.

If not solved can you give me some information on these popups?
I got it sorted out. Thank you very much for the help.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top