Author Topic: My family's computers are dying (blogland post #1)  (Read 1590 times)

So lately, my father's, my grandmother's (dear lord), and mine are all dying.

Let's discuss them name by name.
First off, my dad's PC has been acting very unusual lately. iTunes has been messing around with the iPhone, causing it to skip songs and do other things. His PC has also been crashing, lagging, and doing other things. After a scan with Malwarebytes, he found a couple of trojans he found on there. I have no idea if it was on the external drive we had or not, so I don't know if it was my fault.

Second, there's my Grandma's. This isn't viruses or anything, even though the subject is dying computers, but she's giving away her credit card info. A lot. This makes me regret letting her on the internet, because she just gives her info to some random site asking for good deals, and she has to cancel and get her credit card back over...and over...and over. She also got crap like Zwinky, shopping addons, and other crapware she doesn't need.

And then there's me. For some reason, most of the viruses I had were PUPs, but I had very few trojans, and a MSIL file, named Solimba (not the file name, but the virus name.)

The scan from Malwarebytes is as followed:
Code: [Select]
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2014.01.27.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Alex311360 :: ALEX311360-HP [administrator]

1/27/2014 6:35:45 AM
mbam-log-2014-01-27 (06-35-45).txt

Scan type: Full scan (C:\|D:\|Q:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 1243442
Time elapsed: 4 hour(s), 21 minute(s), 55 second(s)

Memory Processes Detected: 1
C:\Users\Alex311360\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> 3416 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCU\SOFTWARE\SOMOTO\SDP (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\SWEETIM (PUP.Optional.SweetIM.A) -> Quarantined and deleted successfully.

Registry Values Detected: 6
HKCU\Software\Somoto\SDP|affid (PUP.Optional.Somoto.A) -> Data: ipadianskog -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{14DD0E04-D4F6-45d2-A958-F361FBD4F64F} (PUP.Optional.WBCEngine) -> Data:  -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions\{FEFE89E5-A43F-4f4b-8211-B11D91D02135} (PUP.Optional.CoolPic) -> Data:  -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{14DD0E04-D4F6-45d2-A958-F361FBD4F64F} (PUP.Optional.WBCEngine) -> Data: C:\Program Files\WBC Engine\Firefox -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Mozilla\Firefox\Extensions|{FEFE89E5-A43F-4f4b-8211-B11D91D02135} (PUP.Optional.CoolPic) -> Data: C:\Program Files\CoolPic - Fun Social Pictures\Firefox -> Quarantined and deleted successfully.
HKLM\Software\SweetIM|simapp_id (PUP.Optional.SweetIM.A) -> Data: {24BC9CD1-D9E4-11E2-963B-B4FC963B8200} -> Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 9
C:\Program Files\CoolPic - Fun Social Pictures (PUP.Optional.CoolPic) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Delete on reboot.
C:\Users\Alex311360\AppData\Local\Temp\ct2612669 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3268494 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804 (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\xpi\defaults (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\xpi\defaults\preferences (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker (PUP.Optional.FilesFrog.A) -> Quarantined and deleted successfully.

Files Detected: 116
C:\Program Files (x86)\Adobe\Adobe Fireworks CS6\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\Program Files (x86)\Adobe\Adobe Photoshop CS6\amtlib.dll (PUP.RiskwareTool.CK) -> No action taken.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir (PUP.Optional.Conduit) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Program Files (x86)\somoto_v.1\Somoto_V.1ToolbarHelper.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Conduit\CT3282812\Somoto_V.1AutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Conduit\CT3287804\VisualBee_V.5AutoUpdateHelper.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\FilesFrog Update Checker\uninstall.exe.vir (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\FilesFrog Update Checker\update_checker.exe.vir (PUP.Optional.FilesFrog.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\SwvUpdater\Updater.exe.vir (PUP.Optional.Amonetize) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\chLogic.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\ctbe.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\ffLogic.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\ieLogic.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\spch.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\spff.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\statisticsStub.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\AdwCleaner\Quarantine\C\Users\Alex311360\AppData\Local\Temp\CT3282812\stub.exe.vir (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Program Files (x86)\SaveShare\sprotector.dll (PUP.Optional.SProtect.A) -> Quarantined and deleted successfully.
C:\Program Files\Adobe\Adobe After Effects CS6\Support Files\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Program Files\Adobe\Adobe Photoshop CS6 (64 Bit)\amtlib.dll (PUP.RiskwareTool.CK) -> Quarantined and deleted successfully.
C:\Program Files\CoolPic - Fun Social Pictures\source.crx (PUP.Optional.CoolPic) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{58895442-C8FC-4A38-A8D3-80DE836A76B4}\Custom.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\FilesFrog Update Checker\uninstall.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\FilesFrog Update Checker\update_checker.exe (PUP.Optional.FilesFrog.A) -> Delete on reboot.
C:\Users\Alex311360\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5J1A0JEZ\SPSetup[1].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5J1A0JEZ\ism[2].exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\AJFG3CHC\bi_downloader[1].exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K3EWA210\BiTool[1].dll (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K3EWA210\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate[2].exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\1371758533_32204799_249_4.tmp (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\1371758569_32241116_976_6.tmp (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\9E34D54F-BAB0-7891-8C52-E1E6F7698C3E\Latest\BExternal.dll (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\BI_RunOnce (1).exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\BI_RunOnce (2).exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\BI_RunOnce (3).exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\BI_RunOnce.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\DeltaTB.exe (PUP.Optional.Babylon.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\FLVPlayerSetup.exe (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\FLVPlayerUpdate_downloader_by_FLVPlayerUpdate.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\FastFreeConverter_Somoto2.exe (PUP.Optional.FastFreeConverter.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\FreeMouseAutoClickerSetup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\GetCC.dll (MSIL.Solimba) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ICReinstall_FreeYouTubeDownloaderInstallerIC.exe (PUP.Optional.Wajam.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\InstallMonetizer.exe (PUP.Optional.InstallMonetizer.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\OfferBrokerage_14200.exe (PUP.Optional.InstallIQ) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\OptimizerPro.exe (PUP.Optional.OptimizerPro.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\QuickShare1.exe (PUP.Optional.QuickShare.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\Shortcut_bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ToolbarHelper.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\UpdateCheckerSetup.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\VisualBeeWebext.exe (PUP.Optional.CrossRider) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\bitool.dll (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\bundlesweetimsetup.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct2612669\ism.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3268494\ism.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\CT3287804.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\CT3287804.xpi (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\chLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\chromeid.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\conduit.xml (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\ctbe.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\ffLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\ieLogic.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\initData.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\manifest.json (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\setup.ini.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\spch.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\spff.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\statisticsStub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\stub.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\version.txt (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\xpi\defaults\preferences\defaults.js (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\ct3287804\xpi\install.rdf (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\dlmD062.tmp\FreeMouseAutoClicker_downloader_by_FreeMouseAutoClicker.exe (PUP.Optional.Somoto) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\hsbing_717_active.exe (PUP.Optional.SweetPacks.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\instloffer.exe (PUP.Optional.VIT.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\mconduitinstaller.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\mgsqlite3.7z (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\mgsqlite3.dll (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\mism.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsa95FA.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsg17D6.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsg69D9.tmp (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsgB68.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsk4E77.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nslF6CC.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsmD0B2.tmp\distro-smartsy-portforward-rs.exe (PUP.Optional.Searchprotect) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nso367A.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsp23A6.tmp (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsp23D2.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsp703E.tmp (PUP.Optional.Somoto.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsr5127.tmp\distro-smartsy-portforward-rs.exe (PUP.Optional.Searchprotect) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nstFCB2.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsu4662.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsu79ED.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nsv5D7A.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.
C:\Users\Alex311360\AppData\Local\Temp\nswFD61.exe (PUP.Optional.Conduit.A) -> Quarantined and deleted successfully.

This was mildly cut off due to a character limit. Also, my dad downloads crap I don't need, so if you see illegal crap that's not mine. Blame my dad.

I didn't know our computers had this crap, when we already had good antiviruses to begin with (we ALL use avast! antivirus).

Sooner or later our computers are going to get wrecked, and then all we'll have are phones and game consoles.

Anyways, that's all I had to say Blogland Forums. See ya.

Dang, that sucks.
My computer is currently in the shop because the damned thing stopped charging

Hope that gets fixed soon

I run a virus scan on a very rare basis and I never get more than a few bad cookies, I think you're kind of bad at using the internet

I run a virus scan on a very rare basis and I never get more than a few bad cookies, I think you're kind of bad at using the internet

I admit, I am a bit bad at using it, but most of that crap is Conduit, aka installers that do stuff behind my back like installing things I don't want.

Why do you download so much stuff?

Why does your grandmother even have a computer?

Why do you download so much stuff?

I play lots of games I have to download, then I forget about them, then I don't delete them. I'm terrible. >_>

Why does your grandmother even have a computer?

I don't know. She posts terrible god crap on Facebook, always asks for money for jpay for my uncle in jail, and always loses her money in seconds.

I play lots of games I have to download, then I forget about them, then I don't delete them. I'm terrible. >_>
Have you ever heard of Steam?

I guess I'll post it here, even though it isn't a computer, but I don't feel like making a thread.

My mom's Android is having an issue.  Every now and again (last happened Saturday night), the phone will just start letting off its battery charge freely.  It went from 18% to 3% in about 60 seconds.  It also did it a few days ago.  It also won't accept any charge from any device (takes a USB charger, so easy to find).  After a few minutes though, it will 'heal' itself and accept/hold charges again.

Have you ever heard of Steam?

have you ever heard that not all games use steam?

Gee, way to show your computer username

Misread the title as my family is dying


this is bad how?
yes i am hacking you right now and i know where you live. look out your window.