Author Topic: Why wasn't I protected?  (Read 3680 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Why wasn't I protected?
« on: September 28, 2015, 11:05:34 AM »
In my weekly full scan on my paid version of Avast Internet Security, it reported that I had something called win32:searchprotect-BE and it was extremely dangerous. It recommended deletion, which I tried to do, but it couldn't do that so it placed it in quarantine. How do I know this thing is actually gone? It came from some webpage called i-dressup that my daughter was on a few days ago. Apparently, it buries itself and infects and steals stuff from my computer, according to what info I've been able to find. it apparently can propagate and give totally false readings about all my computer status, etc. I also tried to find ways to get rid of it, which are all many pages long and sound like you have to be a computer guru to get through it. I am paying for this software because I wanted to extra protection to avoid this very kind of thing. Avast has alerted me many times about different things and stopped my going to a web page, etc., but this time, nothing happened ... and this is the worst infection I've ever had.

NEW
I attached all the files as instructed, but the only one I see is the aswMBR.txt why aren't the others attached?
« Last Edit: September 28, 2015, 12:55:59 PM by spavilkey »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why wasn't I protected?
« Reply #1 on: September 28, 2015, 11:07:29 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37550
  • Not a avast user
Re: Why wasn't I protected?
« Reply #2 on: September 28, 2015, 11:28:35 AM »
Quote
win32:searchprotect-BE and it was extremely dangerous.
it is not, it is a PUP = Possible Unwanted Program

Quote
The Win32:SearchProtect-B [PUP] infection is used to boost advertising revenue, as in the use of blackhat SEO, to inflate a site’s page ranking in search results.

Quote
Win32:SearchProtect-B [PUP] got on your computer after you have installed a freeware software (video recording/streaming, download-managers or PDF creators) that had bundled into their installation this browser hijacker. This Potentially Unwanted Propgram is also bundled within the custom installer on many download sites (examples: CNET, Brothersoft or Softonic), so if you have downloaded a software from these websites, chances are that Win32:SearchProtect-B [PUP] was installed during the software setup process.




Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Why wasn't I protected?
« Reply #3 on: September 28, 2015, 11:43:27 AM »
Monitoring...
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37550
  • Not a avast user
Re: Why wasn't I protected?
« Reply #4 on: September 28, 2015, 02:06:22 PM »
Quote
NEW
I attached all the files as instructed, but the only one I see is the aswMBR.txt why aren't the others attached?
did you click on more attachments ?

the normal way to do this is to click on reply button and attach logs in your next reply (not edit your first post) because that is what the malware expert is waiting (monitoring)  to see


Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why wasn't I protected?
« Reply #5 on: September 28, 2015, 02:18:43 PM »
Quote
NEW
I attached all the files as instructed, but the only one I see is the aswMBR.txt why aren't the others attached?
did you click on more attachments ?
Adding to Pondus' question, reread the instructions in the link I posted, you'll find it (Attaching logs) there.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Why wasn't I protected?
« Reply #6 on: September 28, 2015, 03:43:05 PM »
Can you tell this is my first time posting on this forum?  :)

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Why wasn't I protected?
« Reply #7 on: September 28, 2015, 03:46:24 PM »
OK, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Why wasn't I protected?
« Reply #8 on: September 28, 2015, 05:25:40 PM »
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyclsid;
emptyalltemp;
ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)
Post its content into your next reply.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Why wasn't I protected?
« Reply #9 on: September 28, 2015, 10:59:36 PM »
Here is the Zoesk scan. A couple of notes, as this was scanning, I had turned off my Avast for an hour, but the scan took longer than that and the Avast came back on. I shut it down again, but wanted to let you know in case that might have a false effect on the scan results. Also, I noticed my email client is listed as Thunderbird and my browser is listed as Firefox. I signed up for this forum a while back, and that info was accurate at that time. I am using an email client called Foxmail v. 7.2 (build 7.201) and my browser is Ice Dragon v. 38.0.5 (a product of Comodo Security Solutions). I saw that there wasn't anything in the Zoesk scan that applied to these programs, and I just wanted to also let you know that. I assume my current email client and browser were not checked as a result. If I need to scan again, please let me know. Thanks.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Why wasn't I protected?
« Reply #10 on: September 29, 2015, 09:46:42 AM »
Yes, you actually didn't scan at all, so please do it.
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Why wasn't I protected?
« Reply #11 on: September 29, 2015, 03:56:50 PM »
The dated file is the scan I ran yesterday. The other is an update of that scan that I ran this morning.

Offline TwinHeadedEagle

  • Malware Removal Expert
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 2987
    • Zemana
Re: Why wasn't I protected?
« Reply #12 on: September 29, 2015, 05:38:45 PM »
Excellent. How is your PC behaving now?
My help is free, however if you'd like to show your appreciation by leaving a donation, it will be much appreciated ------> DONATE

REDACTED

  • Guest
Re: Why wasn't I protected?
« Reply #13 on: September 30, 2015, 11:48:51 PM »
Great! Thanks to everyone who contributed to helping me with this problem.  :)