Author Topic: So avast let  (Read 3958 times)

0 Members and 1 Guest are viewing this topic.

violation009

  • Guest
So avast let
« on: November 29, 2012, 07:08:36 AM »
iminent.com completely attached to a shit load of other viruses through, manage to get off 6 with mbam and sas just found a trojan...

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: So avast let
« Reply #1 on: November 29, 2012, 01:48:09 PM »
This is a browser hijacker and can be qualified as adware. You may find it undesirable.
Link to removal instructions from link article author, Sean Doyle, a Cyber Security Expert and School Teacher ->
http://botcrawl.com/how-to-remove-the-search-iminent-search-the-web-hijacker-virus/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37553
  • Not a avast user
Re: So avast let
« Reply #2 on: November 29, 2012, 02:07:21 PM »
or run AdwCleaner, a special tool for removing browser/toolbar crap

you find it here  http://forum.avast.com/index.php?topic=53253.0

you may post the log here


violation009

  • Guest
Re: So avast let
« Reply #3 on: November 29, 2012, 11:25:11 PM »
heres the log

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37553
  • Not a avast user
Re: So avast let
« Reply #4 on: November 29, 2012, 11:33:51 PM »
as you see in the log it deleted lots of iminent files  ;)

did that solve your problem?


i also recomend Malwarebytes from the same guide......
if you already have it, make sure it is updated and run a quick scan...then click the remove selected button if anything is found

you may post that log here also

« Last Edit: November 29, 2012, 11:42:06 PM by Pondus »

violation009

  • Guest
Re: So avast let
« Reply #5 on: November 30, 2012, 05:17:24 AM »
yeah it cleared it up, my google chrome is toast though, so i have to reinstall it, thanks for the tip...

true indian

  • Guest
Re: So avast let
« Reply #6 on: November 30, 2012, 06:26:44 AM »
MY WOT: http://www.mywot.com/en/scorecard/iminent.com?utm_source=addon&utm_content=warn-viewsc

probably a lot of Adware stuff on that site..I dont see any trojans there.. ;D

violation009

  • Guest
Re: So avast let
« Reply #7 on: November 30, 2012, 12:18:39 PM »
so i reinstalled google chrome and bam littlefish toolbar installed itself, im sure its connected to conduit files, should i run the anti adware again or what?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37553
  • Not a avast user
Re: So avast let
« Reply #8 on: November 30, 2012, 01:02:17 PM »
you may do that yes

if you want a full check, follow the guide here  http://forum.avast.com/index.php?topic=53253.0

and attach the following logs
AdwCleaner
Malwarebytes
OTL
aswMBR

when done a malware specialist will have a look inside.  ;)




Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: So avast let
« Reply #9 on: December 03, 2012, 11:28:15 PM »
I have transferred the OTL log from the sticky topic to this thread, as the post there will be deleted 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: So avast let
« Reply #10 on: December 03, 2012, 11:32:15 PM »
They are being sneaky now and setting it as a service.  You will need to manually change Chrome

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
SRV - [2012/11/22 09:49:44 | 002,612,336 | ---- | M] (Iminent) [Auto | Running] -- C:\Program Files (x86)\Common Files\Umbrella\Umbrella.exe -- (SProtection)
IE - HKU\S-1-5-21-2164288071-1898435139-315501782-1000\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No CLSID value found
IE - HKU\S-1-5-21-2164288071-1898435139-315501782-1000\..\URLSearchHook: {c28f5072-1bfa-42f0-ba55-5a802d3490cb} - No CLSID value found
IE - HKU\S-1-5-21-2164288071-1898435139-315501782-1001\..\URLSearchHook: {7473b6bd-4691-4744-a82b-7854eb3d70b6} - No CLSID value found
IE - HKU\S-1-5-21-2164288071-1898435139-315501782-1001\..\URLSearchHook: {c28f5072-1bfa-42f0-ba55-5a802d3490cb} - No CLSID value found

:Files
C:\Program Files (x86)\Common Files\Umbrella

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48603
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: So avast let
« Reply #11 on: December 03, 2012, 11:48:35 PM »
I'll clean up the other thread when violation009 replies here. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v24H2 64bit, 32 Gig Ram, 1TB SSD, Avast Free 24.4.6112, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet