Author Topic: [Resolved] Bogus Anti-virus  (Read 3364 times)

0 Members and 1 Guest are viewing this topic.

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #15 on: June 02, 2012, 12:25:22 PM »
OK. Will do so and let you know.
« Last Edit: June 02, 2012, 12:29:36 PM by johnmac150 »

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #16 on: June 07, 2012, 03:53:10 PM »
type in del ppmate-2-3-1-74-inglesi.exe
Then Enter

Removed file

Download and scan with CCleaner

Scanned and it removed 5Gb worth of files etc. Wipe of MFT free space still running.

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #17 on: June 08, 2012, 06:42:26 AM »
Removed file

Scanned and it removed 5Gb worth of files etc. Wipe of MFT free space still running.
How is your PC running now?

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #18 on: June 09, 2012, 09:05:28 AM »
Hi

Something strange has happened. Somehow I've downloaded and installed what appears to be a free version of AVG Ant-virus 2012. It was late at night and I was tired but I think it was when I clicked on your link to CCleaner. I only realised it was the wrong software when I looked at your instructions and they didn't match what I was seeing. File I downloaded was "avg_avct_stb_all_2012_2178_ppc2.exe". Did something on my computer re-direct your link to a bogus site and I've now installed a malicious application?
If it is bogus, it tells me that the original exe file I downloaded which started this conversation is infected with a Trojan Horse: Generic28.BGTD.

PC appears to be running OK but I am paranoid that I've installed something (rootkit?) that might be monitoring my sessions, keystrokes, passwords etc.

John

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #19 on: June 11, 2012, 07:06:03 AM »
The file avg_avct_stb_all_2012_2178_ppc2.exe is the installer file  for the free version of AVG.

It is quite possible tha there are other free software adds on the location from which you downloaded CCLeaner. It doesn't mean you have to install them.

If you are looking for a replacement AntiVirus program I can recommend some.

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #20 on: June 11, 2012, 01:32:25 PM »
The file avg_avct_stb_all_2012_2178_ppc2.exe is the installer file  for the free version of AVG.
It is quite possible tha there are other free software adds on the location from which you downloaded CCLeaner. It doesn't mean you have to install them.
There is no link to AVG on that site. That is why I am worried I was redirected and therefore I still have a virus and/or rootkit. Also, although name is correct for AVG installer, it could easily be a malicious executable, could it not.

I would like to do another scan and post results here. Would you tell me which tool to use and be willing to analyse it for me?


Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #21 on: June 11, 2012, 01:57:03 PM »

Let's do this another way

Let's scan the file in question. go HERE

Select Choose file. Then using windows explorer locate the file avg_avct_stb_all_2012_2178_ppc2.exe

Then select Scan it. This will scan the file with some 40 sources.

Once the file is scanned, then reply witht the results.

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #22 on: June 13, 2012, 01:44:52 PM »
Results of Virustotal scans are attached because formatting was difficult to read when pasted as text. I have also attached the results for the original problem setup.exe file, which I am still concerned infected PC in background when "Save" was clicked.

Thanks, John

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #23 on: June 14, 2012, 07:34:49 AM »
The results from the Virustotal scan indicate that the installer file avg_avct_stb_all_2012_2178_ppc2.exe is a legit file.

The setup.exe file you scanned needs to be deleted.

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #24 on: June 14, 2012, 03:22:00 PM »
Deleted setup.exe

Sorry but I'm paranoid - How do I verify that it didn't infect PC either first or second time it was downloaded while Microsoft protection was turned off?

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #25 on: June 24, 2012, 05:39:16 PM »
johnmac150

Rerun MalwareBytes antimalware, adn post the results in your reply.

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #26 on: June 25, 2012, 03:37:42 PM »
johnmac150

Rerun MalwareBytes antimalware, adn post the results in your reply.

Don't think I ran that before. Do you want me to run MalwareBytes or one of the others you had me run, e.g. Kaspersky? If Malwarebytes, would you advise best place to obtain most recent version?

Thanks again.

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #27 on: June 25, 2012, 11:21:02 PM »
Don't think I ran that before. Do you want me to run MalwareBytes or one of the others you had me run, e.g. Kaspersky? If Malwarebytes, would you advise best place to obtain most recent version?

Thanks again.
I haven't requested a MalwareBytes scan before, but according to your DDS log you have it installed, do you not have an Icon on your desktop?

Open MBAM ->> Select the Update tab, Once updated ->> Select Scan (Quick scan should be selected) When it's complete a log will open, copy and paste the results of that log in you reply.

2008-2010
With everything comes a price

Offline johnmac150

  • Bronze Member
  • Posts: 29
Re: [In Progress] Bogus Anti-virus
« Reply #28 on: June 26, 2012, 01:28:23 PM »
Had deleted it. Have downloaded again from shop.malwarebytes.org and running full scan just now.
Does it check for rootkit malware?

Offline bamajim

  • Administrator
  • Gold Member
  • Posts: 2745
Re: [In Progress] Bogus Anti-virus
« Reply #29 on: June 27, 2012, 10:49:53 AM »
Had deleted it. Have downloaded again from shop.malwarebytes.org and running full scan just now.
Does it check for rootkit malware?
Yes. And the log will give us some indications as well. Post the log when you are ready.

2008-2010
With everything comes a price