Avast WEBforum

Other => Viruses and worms => Topic started by: jprieto on December 14, 2013, 12:46:12 AM

Title: Win32:Somoto-J [PUP]
Post by: jprieto on December 14, 2013, 12:46:12 AM
Hi,

After a BSoD I decided to perform an AV scan on my computer, and it found that a file called bitool.dll (C:\Users\(...)\AppData\Local\Temp) was infected. I put it on quarantine and performed analysis with MBAM, OTL and  aswMBR. (You can find the logs attached in this post).

Is it safe to erase the infected file?

Thanks for your help.

P.S. I cannot attach the OTL log because it has a size of 575 kb. Should I split in two parts?
Title: Re: Win32:Somoto-J [PUP]
Post by: Secondmineboy on December 14, 2013, 12:48:15 AM
You can split the OTL Log.

Please wait for an malware expert, he will help you to remove this PUP. ;)
Title: Re: Win32:Somoto-J [PUP]
Post by: Pondus on December 14, 2013, 12:51:07 AM
Since it was located in a temp folder ... yes

And it was not infected
Quote
Win32:Somoto-J [PUP]   
PUP = not virus / Possible Unwanted Program
Google somoto and you find out what it is     ;)
Title: Re: Win32:Somoto-J [PUP]
Post by: jprieto on December 14, 2013, 01:01:02 AM
First part of the OTL log attached.

I googled it, but one of the first results was very scary!  :-\ From one of the first results:

Quote
the Win32: Somoto-J (PUP) virus can take advantage of system bugs and open a backdoor for remote hackers. No doubts that your computer and privacy will be under high-risk due to the presence of Win32: Somoto-J (PUP) virus.
Title: Re: Win32:Somoto-J [PUP]
Post by: jprieto on December 14, 2013, 01:01:56 AM
And here is the second part of the log.
Title: Re: Win32:Somoto-J [PUP]
Post by: Pondus on December 14, 2013, 01:09:54 AM
http://www.sophos.com/en-us/threat-center/threat-analyses/adware-and-puas/Somoto%20BetterInstaller/detailed-analysis.aspx

Quote
PUP.Optional.Somoto is a generic detection given by a security company Malwarebytes Anti-Malware to identify adware or unwanted program that adds various security risks on the computer. PUP.Optional.Somoto was made to control the home page and settings of affected browser. PUP.Optional.Somoto detection normally applies to threat that alters home page settings, loads toolbar, installs FLV Player, and set unknown search engine. The purpose is simply to promote the program, which in return will gain profit for adware authors.

Harmful hijacker that was tagged as PUP.Optional.Somoto is capable of changing the home page without giving you any way to reverse whatever has done. Even removing and reinstalling the affected browser may not help resolve the issue because PUP.Optional.Somoto is somehow using a locking mechanism to prevent further changes. It may require thorough virus scanning of the Windows system.

To avoid the harm cause by PUP.Optional.Somoto, it is important that you know where it originates. Free program or shareware is the number one source of this potentially unwanted program. PUP.Optional.Somoto is bundled with free programs that were configured to install adware once you execute it. Links from social media sites and spam emails may likewise drop PUP.Optional.Somoto into the system.

Title: Re: Win32:Somoto-J [PUP]
Post by: essexboy on December 14, 2013, 12:22:09 PM
Nothing else really ..

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
[2013/12/03 11:51:50 | 000,000,000 | ---D | M] -- C:\Users\Juan\AppData\Roaming\3909

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Win32:Somoto-J [PUP]
Post by: jprieto on December 14, 2013, 06:33:23 PM
Done. Here's the report.
Title: Re: Win32:Somoto-J [PUP]
Post by: essexboy on December 14, 2013, 07:41:08 PM
Looks clean any further problems ?
Title: Re: Win32:Somoto-J [PUP]
Post by: jprieto on December 14, 2013, 08:19:27 PM
No, thank you for helping me :)