1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved cdn.montiera

Discussion in 'Malware and Virus Removal Archive' started by Jill, 2014/05/14.

  1. 2014/06/08
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Uninstall McAfee Security Scan, typical foistware.

    [​IMG] Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following
    Code:
    :OTL
    DRV:64bit: - [2013/10/09 02:31:54 | 000,489,568 | ---- | M] (Kaspersky Lab ZAO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\klif.sys -- (KLIF)
    DRV:64bit: - [2013/07/17 03:02:04 | 007,717,984 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\kl1.sys -- (KL1)
    CHR - plugin: Error reading preferences file
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - HKU\S-1-5-21-419062791-1861278453-2196266538-1002..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
    O15 - HKU\S-1-5-21-419062791-1861278453-2196266538-1000\..Trusted Domains: blank ([]about in Trusted sites)
    O15 - HKU\S-1-5-21-419062791-1861278453-2196266538-1000\..Trusted Domains: security_WinAutomation.Console.exe ([]about in Trusted sites)
    
    
    :Services
    
    :Reg
    
    :Files
    C:\FRST
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
    
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Click on "Run ESET Online Scanner" button.
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  2. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Ok, MacAfee is deleted, and here is the OTL report:


    All processes killed
    Error: Unable to interpret <Code: > in the current context!
    ========== OTL ==========
    Error: Unable to stop service KLIF!
    Unable to delete service\driver key KLIF.
    File move failed. C:\Windows\SysNative\drivers\klif.sys scheduled to be moved on reboot.
    Error: Unable to stop service KL1!
    Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\KL1 deleted successfully.
    File move failed. C:\Windows\SysNative\drivers\kl1.sys scheduled to be moved on reboot.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    Registry value HKEY_USERS\S-1-5-21-419062791-1861278453-2196266538-1002\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-419062791-1861278453-2196266538-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blank\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-419062791-1861278453-2196266538-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\security_WinAutomation.Console.exe\ deleted successfully.
    ========== SERVICES/DRIVERS ==========
    ========== REGISTRY ==========
    ========== FILES ==========
    File\Folder C:\FRST not found.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Twitsky
    ->Temp folder emptied: 5914431 bytes
    ->Temporary Internet Files folder emptied: 894910923 bytes
    ->Google Chrome cache emptied: 376229285 bytes
    ->Flash cache emptied: 64484 bytes

    User: UpdatusUser
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 2718776 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36073507 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 1,255.00 mb


    [EMPTYJAVA]

    User: All Users

    User: Default

    User: Default User

    User: Public

    User: Twitsky

    User: UpdatusUser

    Total Java Files Cleaned = 0.00 mb


    [EMPTYFLASH]

    User: All Users

    User: Default

    User: Default User

    User: Public

    User: Twitsky
    ->Flash cache emptied: 0 bytes

    User: UpdatusUser

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 06102014_000751

    Files\Folders moved on Reboot...
    File move failed. C:\Windows\SysNative\drivers\klif.sys scheduled to be moved on reboot.
    File move failed. C:\Windows\SysNative\drivers\kl1.sys scheduled to be moved on reboot.
    C:\Users\Twitsky\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DF856AA81EF1EE4F1E.TMP not found!
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DF8E8950C76ABA268D.TMP not found!
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DFB0485AD8481BFB3F.TMP not found!
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DFB764679CA55C4073.TMP not found!
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DFDEDAB5B841406780.TMP not found!
    C:\Users\Twitsky\AppData\Local\Temp\~DFE26BF8F9DCD71E28.TMP moved successfully.
    File\Folder C:\Users\Twitsky\AppData\Local\Temp\~DFEA5BE58F96FC1EF8.TMP not found!
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R3AGFQYZ\postmessageRelay[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PQVDH0TM\mnu[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PQVDH0TM\V80PAcvrynR[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCL5YV6U\btn[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCL5YV6U\ebay[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCL5YV6U\frame[3].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MCL5YV6U\rd[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M2F56GRD\index[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M2F56GRD\V80PAcvrynR[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L45RTQEJ\like[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\fbTlbrBtn[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\scannerBtn_Gough[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\sitecheck2[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\tlbr[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\twitterBtn[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KUHB2TEM\YKZLKDO4.htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2KN93B9\1402376795433[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2KN93B9\audmeasure[1].gif moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2KN93B9\fastbutton[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B2KN93B9\set[1].gif moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\97Y2W0UE\107592-active-cdn-montiera-2[1].htm moved successfully.
    C:\Users\Twitsky\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    C:\windows\temp\ZLT0039c.TMP moved successfully.

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...





    Now on to the rest....
     

  3. to hide this advert.

  4. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Security check:

    Results of screen317's Security Check version 0.99.84
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Disabled!
    ZoneAlarm Antivirus
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Adobe Reader 9 Adobe Reader out of Date!
    Google Chrome 34.0.1847.137
    Google Chrome 35.0.1916.114
    ````````Process Check: objlist.exe by Laurent````````
    Malwarebytes Anti-Malware mbam.exe
    Malwarebytes Anti-Malware mbamscheduler.exe
    CheckPoint ZoneAlarm vsmon.exe
    CheckPoint ZoneAlarm ZAPrivacyService.exe
    CheckPoint ZoneAlarm zatray.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0%
    ````````````````````End of Log``````````````````````
     
  5. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Farbar report:


    Farbar Service Scanner Version: 09-06-2014
    Ran by Twitsky (administrator) on 10-06-2014 at 00:41:39
    Running from "C:\Users\Twitsky\Desktop "
    Microsoft Windows 7 Professional Service Pack 1 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Attempt to access Local Host IP returned error: Localhost is blocked: Destination is unreachable
    LAN connected.
    Attempt to access Google IP returned error. Google IP is unreachable
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall "=DWORD:0


    System Restore:
    ============

    System Restore Disabled Policy:
    ========================


    Action Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => MD5 is legit
    C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\System32\dhcpcore.dll => MD5 is legit
    C:\Windows\System32\drivers\afd.sys => MD5 is legit
    C:\Windows\System32\drivers\tdx.sys => MD5 is legit
    C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\System32\dnsrslvr.dll => MD5 is legit
    C:\Windows\System32\mpssvc.dll => MD5 is legit
    C:\Windows\System32\bfe.dll => MD5 is legit
    C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\System32\SDRSVC.dll => MD5 is legit
    C:\Windows\System32\vssvc.exe => MD5 is legit
    C:\Windows\System32\wscsvc.dll => MD5 is legit
    C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\System32\wuaueng.dll => MD5 is legit
    C:\Windows\System32\qmgr.dll => MD5 is legit
    C:\Windows\System32\es.dll => MD5 is legit
    C:\Windows\System32\cryptsvc.dll => MD5 is legit
    C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
    C:\Windows\System32\ipnathlp.dll => MD5 is legit
    C:\Windows\System32\iphlpsvc.dll => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\System32\rpcss.dll => MD5 is legit


    **** End of log ****
     
  6. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    TFC cleaned 9mg. Did not lose desktop or restart. Left the "libraries" folder open. On to eset...

    Eset: I accept the terms, press start, and the popup goes blank. Tried twice. At first there is what looks like either a floppy icon or a broken image icon, but then that goes away and leaves a blank page (light blue) with the url in the address bar of http://www.eset.com/us/online-scanner-popup

    ??
     
    Last edited: 2014/06/10
  7. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Try Eset with different browser.
     
  8. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Should I check "scan archives" only?

    "remove found threats" and "enable custom stealth technology" are already checked. Leave them checked or uncheck them?
     
  9. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes and yes.
     
  10. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Lol! Doesn't make sense. Should I check scan archives only? - yes.
    Should I leave them checked or unchecked? - yes
     
  11. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    My instructions are rather clear.
    It says:

    - Check Scan archives

    It doesn't comment on anything else, means leave everything else as it is.
     
  12. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    Eset:

    C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\escortShld.dll Win32/Toolbar.Montiera.J potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\zonealarmApp.dll a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\zonealarmEng.dll probably a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\zonealarmsrv.exe a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\zonealarmTlbr.dll a variant of Win32/Toolbar.Montiera.F potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.5.23.8\bh\zonealarm.dll a variant of Win32/Toolbar.Escort.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\escortShld.dll Win32/Toolbar.Montiera.J potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\uninstall.exe Win32/Toolbar.Montiera.B potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\zonealarmApp.dll a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\zonealarmEng.dll probably a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\zonealarmsrv.exe a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\zonealarmTlbr.dll a variant of Win32/Toolbar.Montiera.F potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.11.6\bh\zonealarm.dll a variant of Win32/Toolbar.Escort.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\uninstall.exe Win32/Toolbar.Montiera.B potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmApp.dll a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmEng.dll probably a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmsrv.exe a variant of Win32/Toolbar.Montiera.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\zonealarmTlbr.dll a variant of Win32/Toolbar.Montiera.F potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\Check Point Software Technologies LTD\zonealarm\1.8.22.0\bh\zonealarm.dll a variant of Win32/Toolbar.Escort.A potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\CheckPoint\Install\CUninstallerZA.exe Win32/Toolbar.Conduit potentially unwanted application deleted - quarantined
    C:\Program Files (x86)\CheckPoint\Install\zatb.exe Win32/Toolbar.Montiera.I potentially unwanted application deleted - quarantined
    C:\Users\Twitsky\Desktop\BotPackage\Bonuses\Pinterest Amazon Product Submitter\Pinterest Amazon Product Submitter.exe a variant of Win32/Packed.Themida potentially unwanted application deleted - quarantined
    C:\Users\Twitsky\Desktop\BotPackage\Bonuses\Pinterest Scheduler\Pinterest Scheduler.exe a variant of Win32/Packed.Themida potentially unwanted application deleted - quarantined
    C:\Users\Twitsky\Desktop\BotPackage\PinPal Bot V3\PinPal Bot.exe a variant of Win32/Packed.Themida potentially unwanted application deleted - quarantined
    C:\Users\Twitsky\Downloads\zaSetupWeb_101_079_000.exe Win32/Toolbar.Conduit potentially unwanted application deleted - quarantined
     
  13. 2014/06/10
    Jill

    Jill Inactive Thread Starter

    Joined:
    2014/05/14
    Messages:
    20
    Likes Received:
    0
    I'm having a problem - malwarebytes keeps alerting me that the database is out of date. I close it and it comes back up immediately. Over and over and over. I went into the task manager to try to end it, but it won't let me! It doesn't matter that the database is out of date, my free trial has expired. Should I uninstall malwarebytes?
     
  14. 2014/06/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No. When trial version expires it becomes free version.
    It doesn't work in real time but it's still good for on demand scanning.

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions (if present).
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    ====================================

    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

    12. Please, let me know, how your computer is doing.
     
  15. 2014/06/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    The issue seems to be resolved.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.