Vosteran search popup when starting chrome browser… can not find it in add/remove programs.
13 min read
Vosteran search popup when starting chrome browser… can not find it in add/remove programs.
start
CloseProcesses:
HKLM-x32\…\Winlogon: [Shell] explorer.exe, C:\Users\William\AppData\Roaming\Microsoft\Windows\Templates\diagx.exe [13848576 ] () <=== ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1328426514-2669664763-694145802-1001 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = http://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3330390&octid=EB_ORIGINAL_CTID&ISID=MDAE3EEB0-4A1E-4A3B-9753-6F5260EA3613&SearchSource=55&CUI=&UM=6&UP=SP904D0DAA-292A-43F8-AA60-2FEC3E1140F3&SSPV=
CHR StartupUrls: Default -> "hxxp://www.msn.com/", "hxxp://Vosteran.com/?f=7&a=vst_frmr_15_02_ch&cd=2XzuyEtN2Y1L1Qzu0EtDyCzyzyyDtAtD0ByC0EyBzytAyE0BtN0D0Tzu0StCtCtDtAtN1L2XzutAtFyCtFtCyCtFyCtN1L1CzutCyEtBzytDyD1V1QtN1L1G1B1V1N2Y1L1Qzu2SyEzyyBtByBtCzytDtGtCyE0A0EtG0B0C0A0EtG0D0C0DyDtGtCtAtB0DtBzzzzyByDtBtDyC2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szyzy0CyByEtAzzyDtGyByDzzyEtGyE0B0CtDtGzztBzytBtG0FtAzyzztAyCzyyDyC0E0FyE2Q&cr=1861526441&ir="
S2 cyycfhtzro64; C:\Program Files\005\cyycfhtzro64.exe run options=01110010050000000000000000000000 sourceguid=B021CBBD-E38E-4F8C-8E93-6624B0597A23 [X]
C:\Program Files\005\cyycfhtzro64.exe
C:\Users\William\AppData\Local\Temp\bitool.dll
C:\Users\William\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4a4gve.dll
C:\Users\William\AppData\Local\Temp\DTLite4491-0356.exe
C:\Users\William\AppData\Local\Temp\Gtuner.exe
C:\Users\William\AppData\Local\Temp\HPPSdr.exe
C:\Users\William\AppData\Local\Temp\ICReinstall_CR_Downloader_for_mega-man-4.exe
C:\Users\William\AppData\Local\Temp\ICReinstall_samsung-usb-driver-for-mobile-phones.exe
C:\Users\William\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\William\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
C:\Users\William\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\William\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
C:\Users\William\AppData\Local\Temp\nsiD758.tmp.exe
C:\Users\William\AppData\Local\Temp\nsk2297.exe
C:\Users\William\AppData\Local\Temp\nso2092.exe
C:\Users\William\AppData\Local\Temp\nsu3BEE.exe
C:\Users\William\AppData\Local\Temp\nsv3E60.exe
C:\Users\William\AppData\Local\Temp\nszCF8B.exe
C:\Users\William\AppData\Local\Temp\proxy_vole6791855571275520233.dll
C:\Users\William\AppData\Local\Temp\Quarantine.exe
C:\Users\William\AppData\Local\Temp\raptrpatch.exe
C:\Users\William\AppData\Local\Temp\raptr_stub.exe
C:\Users\William\AppData\Local\Temp\SAMSUNG_USB_Driver_for_Mobile_Phones.exe
C:\Users\William\AppData\Local\Temp\siinst.exe
C:\Users\William\AppData\Local\Temp\sqlite3.dll
C:\Users\William\AppData\Local\Temp\strings.dll
C:\Users\William\AppData\Local\Temp\Wildstar.exe
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:B1FBBD09
EmptyTemp:
End
Its the same. When i start Chrome two Vosteran tabs open instead of one
Download Malwarebytes Anti-Malware http://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.
please post
- Windows XP : Double click on the icon to run it.
- Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
- On the Dashboard click on Update Now
- Go to the Setting Tab
- Under Setting go to Detection and Protection
- Under PUP and PUM make sure both are set to show Treat Dections as Malware
- Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
- Then on the Dashboard click on Scan
- Make sure to select THREAT SCAN
- Then click on Scan
- When the scan is finished and the log pops up…select Copy to Clipboard
- Please paste the log back into this thread for review
- Exit Malwarebytes
- ***************************************
What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
Most reliable and thorough.
The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
This scanner can take quite a bit of time to run, depending of course how full your computer is.
Go here to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
- Note:
For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.- Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how.
- Click the blue Run ESET Online Scanner button
- Tick the box next to YES, I accept the Terms of Use.
- Click Start
- When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
- Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
- Click on Advanced Settings
- Make sure that the option Remove found threats is unticked.
- Ensure these options are ticked
- Scan archives
- Scan for potentially unsafe applications
- Enable Anti-Stealth technology
- Click Start
- Wait for the scan to finish
- When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
- Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
- Close the ESET online scan.
Malwarebytes log
Eset log
its running now
Anytime we're notified an infection had backdoor capabilities I need to make sure you see this warning.Backdoor.Agent.PGen, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER\RUN|Policies,
start
CloseProcesses:
C:\Program Files (x86)\Milestone\MUD\rld.dll
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie2.1.37.zip
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\DaemonProcess.exe
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\Mobogenie.exe
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\MUServer.apk
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\nengine.dll
C:\Users\William\AppData\Local\Mobogenie\Version\OldVersion\Mobogenie\New_UpdateMoboGenie.exe
C:\Users\William\AppData\Roaming\Apple Computer\MobileSync\Backup\dbcbea720481c994ea55a1788150e91d5d01811f\6692793025aa6d397c87371b912530d71bfccec1
C:\Users\William\AppData\Roaming\Microsoft\Windows\Templates\diagx.exe
C:\Users\William\Downloads\FLVPlayer-Chrome.exe
G:\downloads\Shingeki.MSWC.iso
G:\downloads\DTLite4481-0348\DTLite4481-0348.exe
EmptyTemp:
End
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI