Other > Viruses and worms

Do I have malware?

(1/7) > >>

JoniB:
I've saved the newest version of Avast that I found at filehippo.com to my laptop 32 bit.  I then tried to download it on the computer, but I just get a message saying that it's not compatible with Win32.  Am I missing something, or is this malware that is blocking help?

Pondus:
what AV did you use before installing avast?
have you removed it?


run these and try again   http://forum.avast.com/index.php?topic=53253.0
AdwCleaner....click delete.....post log here
Malwarebyts......after quick scan, click remove selected if anything is found....post log


JoniB:
Searched, and this is the log.........

# AdwCleaner v2.113 - Logfile created 02/28/2013 at 02:24:30
# Updated 23/02/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : User - USER-260401AF3B
# Boot Mode : Normal
# Running from : C:\Documents and Settings\User\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ihwg2pze.default\searchplugins\delta.xml
File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
Folder Found : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Found : C:\Documents and Settings\All Users\Application Data\Toolbar4
Folder Found : C:\Documents and Settings\User\Application Data\Babylon

***** [Registry] *****

Key Found : HKCU\Software\5f6dbdae53eed15
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\DataMngr
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CFACCB6-2F3F-4177-94EA-0D2B72D384C1}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Found : HKLM\Software\Babylon
Key Found : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Key Found : HKLM\SOFTWARE\Classes\Prod.cap
Key Found : HKLM\Software\Conduit
Key Found : HKLM\Software\DataMngr
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v20.0 (en-US)

File : C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\ihwg2pze.default\prefs.js

Found : user_pref("extensions.delta.admin", false);
Found : user_pref("extensions.delta.aflt", "babsst");
Found : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Found : user_pref("extensions.delta.autoRvrt", "false");
Found : user_pref("extensions.delta.dfltLng", "en");
Found : user_pref("extensions.delta.excTlbr", false);
Found : user_pref("extensions.delta.id", "4053a21d0000000000000016cf4ea251");
Found : user_pref("extensions.delta.instlDay", "15740");
Found : user_pref("extensions.delta.instlRef", "sst");
Found : user_pref("extensions.delta.newTab", false);
Found : user_pref("extensions.delta.prdct", "delta");
Found : user_pref("extensions.delta.prtnrId", "delta");
Found : user_pref("extensions.delta.rvrt", "false");
Found : user_pref("extensions.delta.smplGrp", "none");
Found : user_pref("extensions.delta.tlbrId", "base");
Found : user_pref("extensions.delta.tlbrSrchUrl", "");
Found : user_pref("extensions.delta.vrsn", "1.8.10.0");
Found : user_pref("extensions.delta.vrsnTs", "1.8.10.09:33:31");
Found : user_pref("extensions.delta.vrsni", "1.8.10.0");
Found : user_pref("extensions.toolbar@ask.com.install-event-fired", true);

-\\ Google Chrome v17.0.963.79

File : C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [4154 octets] - [28/02/2013 02:24:30]

########## EOF - C:\AdwCleaner[R1].txt - [4214 octets] ##########

Pondus:
you must click delete in AdwCleaner to remove all those crap files.....the log you post is just serch

JoniB:
I've got Essentials, but wasn't finding whatever was bothering my system, so I thought I'd download Avast.  It claims to help with the spyware I think may have my system infected.  I didn't remove Essentials prior to saving Avast.  I was expecting an objection by the software as a reaffirmation that I SHOULD remove it first.  Perhaps that is why the notice, but it seems a strange notice to send as an objection for duplicating AV's.  I also didn't want to remove Essentials prior to knowing that I wouldn't be making matters worse.

Navigation

[0] Message Index

[#] Next page

Go to full version