Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Hunt for malware c.betrad.com

08 Sep 2013   #1

Windows 7 Professional 64 bit
 
 
Hunt for malware c.betrad.com

Hello

I have tracked an annoying program called c.betrad.com on my computer to Internet Explorer. The program loads onto my machine daily on startup of google. It loads a script into local-storage which I assume it runs on load-up and sends all my private stuff back to its warehouse. Thing is, I do not use IE. I deleted it from my programs list and as far as I am aware, I do not have a copy or does windows sneak IE in through the back-door.

Where is the startup for c.betrad.com lurking? I have disabled my preload folder and kept a copy of the script in local-storage (attached). I always delete my local-storage and other temp folders daily but I assume its too late for this problem. My data has been sent. I attach a snip of the storage directory. I did not use youtube or the daily telegraph either so I assume they load too.

Is there any way I can catch the data being sent. I could turn off the internet and send the stuff to a file, say.

I have turned off the run javascript in google settings.



Attached Images
 
Attached Files
File Type: txt localstorage.txt (74.0 KB, 5 views)
My System SpecsSystem Spec
.

08 Sep 2013   #2

Windows 7 Home Premium
 
 

bs449,

Try the following, it is a "cookie monster"!

Please download SuperAntiSpyware Free Version
SUPERAntiSpyware Download
Save to the Desktop
Install the program: Express Install

At the program console, click: Check for updates
Once the update is finished, on the main screen, Check: Quick Scan
Next, click: Scan your computer

Superantispyware scans the computer, and when finished, lists whatever is found.
Make sure everything found has a check next to it, and let the scanner fix it.

Obtain the SuperAntiSpyware report by clicking the following at the main program console: View Scan Logs
Double-click the log shown, and it opens in Notepad.

Please copy the information in the SuperAntiSpyware log and post in your reply.
My System SpecsSystem Spec
08 Sep 2013   #3

Windows 7 Ultimate x64, XP Mode, W8.1 Preview VM - 7 Pro x64 second remote tower
 
 

One of the other things you can try is clearing the cookies and other offline content by going into the Tools/Internet/Browsing history options and checking off the Delete browsing history on exit box along with the Delete button to clear things out.

Switching home pages from Google to Bing will help on top of that since Google is known for adwares/adbots. That particular site isn't good but not any immediate threat just to let you know however. It comes up flagged at various security and antivirus support sites and appears to be a site that was shutdown. http://support.clean-mx.de/clean-mx/...ain=betrad.com

Other information is a site advisor report seen at(not that I am too confident in McAFails evaluations of course ) betrad.com | McAfee SiteAdvisor Software

You may want to check the Programs & Features as well as the IE addons to see if it shows up there at all since it will likely be ignored by most antispyware/antivirus programs as a rule since no malwares are evident.
My System SpecsSystem Spec
.


09 Sep 2013   #4

Windows 7 Professional 64 bit
 
 

Thanks chaps

I deleted my preload history, cookies and ALL the temp files; set my browser to no script and betrad has not appeared today. If it appears I will do your suggestions.

Thank you for the advice and its good to know that betrad is no longer working. Maybe my data was not 'copied'.

Regards
My System SpecsSystem Spec
09 Sep 2013   #5

Windows 7 Ultimate x64, XP Mode, W8.1 Preview VM - 7 Pro x64 second remote tower
 
 

Sounds like a minor intrusion and you know you are glad not to be seeing it. Sometimes the offline browsing history can act like favorites/bookmarks depending on the browser being used and needs to be cleared out entirely. Your browsing habits collected for marketing usually turn out to be the cookies which reveal the sites you visit and should be dumped every so often to avoid "bugs" of one type or another.
My System SpecsSystem Spec
17 Jun 2014   #6

Win 8.1 Pro
 
 

Thanks for the Forum help. Found on a search for "betrad".
Just wanted to post a little more info I found. I could not rid my computer of c.betrad cookie.
Searched computer and found betrad in:
C:\Users\DavidJ\AppData\Local\Packages\windows_ie_ac_001\AC\Microsoft\Internet Explorer\DOMStore\3WR66FJC - Replace "davidj" above with your username.
Could only delete it from there.
You need to check the "show hidden files" to see app data.
But even with show hidden files, I could not manually go to the above folder. Inside the Internet Explorer folder showed nothing. Only showed when I searched for the file in my entire pc.
Seams to store itself away from any cookie removal tools. CCleaner and ADWCleaner did not remove it.
In Internet explorer 11, tools/internet options/advanced
uncheck Load sites and content in the background and
uncheck enable dom storage(mine was unchecked but it still loaded the c.betrad)
Thanks again for the help, hope this helps someone else.
My System SpecsSystem Spec
Reply

 Hunt for malware c.betrad.com




Thread Tools



Similar help and support threads for2: Hunt for malware c.betrad.com
Thread Forum
Duplicate files hunt and destroy Music, Pictures & Video
Welcome to bullyware: Malware gets more aggressive in money hunt Security News
My hunt for Icons. Customization
Hunt for a laptop General Discussion
Online scavenger hunt i'm in..winner takes all!!! Chillout Room

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 11:02 AM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33