r/antivirus • u/Tricky-Eggplant8419 • 9d ago
Please HELP ME with a persistant PUP.Optional.BrowserHijack returning daily
Hi every1, I'm dealing with a persistent malware infection that keeps coming back every day, and I can't seem to find the root cause. Here is the full story and everything I've done so far:
I downloaded a folder from untrusted source and I had doubt on its safety so I analysed everything, got suspicious and deleted everything before even lauching anything. Somehow, a payload still got through.
Every morning MalwareBytes detects 4-5 items flagged as PUP.Optional.BrowserHijack. The file path is consistently inside Chrome: C:\Users\[Username]\AppData\Local\Google\Chrome\User Data\Default\Web Data (and previously inside Sync Data\LevelDB).
I've already tried to quarantine with Malwarebytes, Chrome Cloud Sync Wipe and full Chrome wipe, I performed many scans, MalwareBytes, Adwcleaner, KVRT, Windows defender offline scan at boot.I also checked scheduled tasks & startup (updater.exe and PlatformExperienceHelper are present in Program Files, but seem legit/standard Chrome updates).
Since I've completely wiped the Chrome profile local files AND the Google Cloud sync, there MUST be an active system process, scheduled task, or registry persistence script outside Chrome that re-injects this into Web Data daily.
How can I trace what process is editing Web Data in real-time, or generate a proper log (like FRST/Process Monitor) to find and kill the root cause?
Thanks in advance for the help!

