Post by nursedodie on Feb 28, 2015 14:56:39 GMT -8
I have tried for a week to remove this crap on my computer. I am usually not on this computer so I am unaware of when it got downloaded. I have researched my files and seem to have new stuff downloaded on Jan 17 (I think thats the date) andy way - it was like Cleaner Pro and several others...3D Flashplayer...and so on. Well I uninstalled what I could - although Cleaner Pro never uninstalled. I have ran multiple scans - Malwarebytes, Spybot, AVG, Malicious Software Removal from MS as well as CCLeaner to see everything that is running (which I disabled what I could find but it just returns). Everything just keeps coming back. Extensions keep being added to my google chrome like - nitrodeeal and some type of coupon and free stuff. I have deleted and deleted but they keep showing back up. When I did a the windows update - I clicked on the malicious software tool which of course led me to the internet but it gave me a very strange website - it said Microsoft and had the download of the tool but it had 1000's of ads on the page popping up everywhere. So I closed and just went straight to microsoft myself and no, that page didn't have any mass amount of ads. Either way, everything I run will find nothing one time and then tons the next. I have run in safemode, I have run in every mode I can think of ...its just not working.
This is a windows 7 64b service pack one, gateway computer. Any any any help would be greatly appreciated.
Also when I look at my processes, it seems I have at least 10 instances of chrome running?
Also this: Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/28/2015
Scan Time: 3:41:49 PM
Logfile:
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.28.06
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 334487
Time Elapsed: 30 min, 27 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 2
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\MEDIAPLAYER\SHIMINCLUSIONLIST\vosteran.exe, , [fcad180a6f1ba393fe4f049a1ce7a858],
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, , [dbce0a183c4ec07615e30a210bfab947],
Registry Values: 1
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, C156BBA8-8D99-4BC6-A83D-0AC7AE1A04B1, , [dbce0a183c4ec07615e30a210bfab947]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
PUP.Optional.Vosteran.A, C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\n4gd5o4q.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "http://vosteran.com/?f=1&a=vst_cmi_15_03_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyB0ByD0BzytB0DzyyDtN0D0Tzu0StCtCtCtBtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyD0AyB0FyBzz0EzytGtAyEyDyEtGyDyB0CtDtG0DtA0E0AtGtCtAyE0DyCzz0DtDtB0AtByE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0FyDtCyEyByCtCtG0FtC0CtCtGyEtCyCyDtGzy0BzytAtG0DyC0DzyyB0FyCzyzz0DtDtC2Q&cr=427983926&ir="), ,[35741f03d6b49b9b77b4c350d135e719]
Physical Sectors: 0
(No malicious items detected)
(end)
This is a windows 7 64b service pack one, gateway computer. Any any any help would be greatly appreciated.
Also when I look at my processes, it seems I have at least 10 instances of chrome running?
Also this: Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 2/28/2015
Scan Time: 3:41:49 PM
Logfile:
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.28.06
Rootkit Database: v2015.02.25.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Mom
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 334487
Time Elapsed: 30 min, 27 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 2
PUP.Optional.Vosteran.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\MEDIAPLAYER\SHIMINCLUSIONLIST\vosteran.exe, , [fcad180a6f1ba393fe4f049a1ce7a858],
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, , [dbce0a183c4ec07615e30a210bfab947],
Registry Values: 1
PUP.Optional.Tuto4Pc.A, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, C156BBA8-8D99-4BC6-A83D-0AC7AE1A04B1, , [dbce0a183c4ec07615e30a210bfab947]
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 1
PUP.Optional.Vosteran.A, C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\n4gd5o4q.default\prefs.js, Good: (), Bad: (user_pref("browser.startup.homepage", "http://vosteran.com/?f=1&a=vst_cmi_15_03_ff&cd=2XzuyEtN2Y1L1QzuyE0CyBtB0Bzy0AyB0ByD0BzytB0DzyyDtN0D0Tzu0StCtCtCtBtN1L2XzutAtFyBtFtBtFtCtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyD0AyB0FyBzz0EzytGtAyEyDyEtGyDyB0CtDtG0DtA0E0AtGtCtAyE0DyCzz0DtDtB0AtByE2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0B0FyDtCyEyByCtCtG0FtC0CtCtGyEtCyCyDtGzy0BzytAtG0DyC0DzyyB0FyCzyzz0DtDtC2Q&cr=427983926&ir="), ,[35741f03d6b49b9b77b4c350d135e719]
Physical Sectors: 0
(No malicious items detected)
(end)