Author Topic: Win32:Somoto-J [PUP]  (Read 17557 times)

0 Members and 1 Guest are viewing this topic.

jprieto

  • Guest
Win32:Somoto-J [PUP]
« on: December 14, 2013, 12:46:12 AM »
Hi,

After a BSoD I decided to perform an AV scan on my computer, and it found that a file called bitool.dll (C:\Users\(...)\AppData\Local\Temp) was infected. I put it on quarantine and performed analysis with MBAM, OTL and  aswMBR. (You can find the logs attached in this post).

Is it safe to erase the infected file?

Thanks for your help.

P.S. I cannot attach the OTL log because it has a size of 575 kb. Should I split in two parts?

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: Win32:Somoto-J [PUP]
« Reply #1 on: December 14, 2013, 12:48:15 AM »
You can split the OTL Log.

Please wait for an malware expert, he will help you to remove this PUP. ;)
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37594
  • Not a avast user
Re: Win32:Somoto-J [PUP]
« Reply #2 on: December 14, 2013, 12:51:07 AM »
Since it was located in a temp folder ... yes

And it was not infected
Quote
Win32:Somoto-J [PUP]   
PUP = not virus / Possible Unwanted Program
Google somoto and you find out what it is     ;)

jprieto

  • Guest
Re: Win32:Somoto-J [PUP]
« Reply #3 on: December 14, 2013, 01:01:02 AM »
First part of the OTL log attached.

I googled it, but one of the first results was very scary!  :-\ From one of the first results:

Quote
the Win32: Somoto-J (PUP) virus can take advantage of system bugs and open a backdoor for remote hackers. No doubts that your computer and privacy will be under high-risk due to the presence of Win32: Somoto-J (PUP) virus.

jprieto

  • Guest
Re: Win32:Somoto-J [PUP]
« Reply #4 on: December 14, 2013, 01:01:56 AM »
And here is the second part of the log.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37594
  • Not a avast user
Re: Win32:Somoto-J [PUP]
« Reply #5 on: December 14, 2013, 01:09:54 AM »
http://www.sophos.com/en-us/threat-center/threat-analyses/adware-and-puas/Somoto%20BetterInstaller/detailed-analysis.aspx

Quote
PUP.Optional.Somoto is a generic detection given by a security company Malwarebytes Anti-Malware to identify adware or unwanted program that adds various security risks on the computer. PUP.Optional.Somoto was made to control the home page and settings of affected browser. PUP.Optional.Somoto detection normally applies to threat that alters home page settings, loads toolbar, installs FLV Player, and set unknown search engine. The purpose is simply to promote the program, which in return will gain profit for adware authors.

Harmful hijacker that was tagged as PUP.Optional.Somoto is capable of changing the home page without giving you any way to reverse whatever has done. Even removing and reinstalling the affected browser may not help resolve the issue because PUP.Optional.Somoto is somehow using a locking mechanism to prevent further changes. It may require thorough virus scanning of the Windows system.

To avoid the harm cause by PUP.Optional.Somoto, it is important that you know where it originates. Free program or shareware is the number one source of this potentially unwanted program. PUP.Optional.Somoto is bundled with free programs that were configured to install adware once you execute it. Links from social media sites and spam emails may likewise drop PUP.Optional.Somoto into the system.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Somoto-J [PUP]
« Reply #6 on: December 14, 2013, 12:22:09 PM »
Nothing else really ..

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
[2013/12/03 11:51:50 | 000,000,000 | ---D | M] -- C:\Users\Juan\AppData\Roaming\3909

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

jprieto

  • Guest
Re: Win32:Somoto-J [PUP]
« Reply #7 on: December 14, 2013, 06:33:23 PM »
Done. Here's the report.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:Somoto-J [PUP]
« Reply #8 on: December 14, 2013, 07:41:08 PM »
Looks clean any further problems ?

jprieto

  • Guest
Re: Win32:Somoto-J [PUP]
« Reply #9 on: December 14, 2013, 08:19:27 PM »
No, thank you for helping me :)