7201 Adware On Install ?

detoxa

New member
Local time
4:58 PM
Messages
66
Location
London ,England
I just did a clean install of 7201 and am going through the process of setting up my toys just the way i like them :D.

Unfortunately after running a Malwarebytes scan i have found 6 reg keys infected with ad-ware , So after deleting them i ran a scan with Spy-Bot and found another item of ad-ware on my w7 partition.

See attachments below for full details.

Seems very odd that i should have them on my notebook as its a "clean install". I did use IE8 briefly to set it up the way i like but all my security was inplace before hand.

Do you think these could be false positives/possible bug Ive inherited from the the shortcuts i transfered from 7137 ? Seems unlikely because i do regular scans and i always get a clean bill of health. (Hence why its so odd to me)
Any help/suggestions much appreciated as I'm curious as to whats happened please ?

Malwarebytes log :

Malwarebytes' Anti-Malware 1.37
Database version: 2227
Windows 6.1.7201
04/06/2009 04:34:25
mbam-log-2009-06-04 (04-34-25).txt
Scan type: Quick Scan
Objects scanned: 68661
Time elapsed: 2 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\kqzyfj.com (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com (Adware.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
 

Attachments

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5720 Notebook.
OS
W7 Build 7201 / Vista Home SP2 ( Both x86)
CPU
Intel Core Duo T7300 @ 2.00GHZ
Motherboard
Acer Nettling v1.07
Memory
2 GB DDR2 / 2 GB ReadyBoost
Hard Drives
260 GB ( 4 Partitions.)
300 GB External HDD.
Mouse
In the kitchen ;o)
Internet Speed
Sloooooooow
Other Info
Anyone seen the plumber ? lol
That's not on the 7201 build. You got nailed running IE somehow. Confirmed using a fresh x64 build.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build/Mod
OS
Windows 7 Home Premium x64
CPU
Intel QX9650 Extreme 4.0 GHz
Motherboard
ASUS Rampage Extreme Rev2
Memory
8GB (4x2) Corsair Dominator DDR3
Graphics Card(s)
2x Radeon R390X [8GB]
Sound Card
SupremeFX X-Fi
Monitor(s) Displays
Dell 2408WFP 26" Panel
Screen Resolution
1920x1200
Hard Drives
4x WD 2TB (8TB+ Total)
2x Crucial SSD 128GB (RAID-0)
1x LG Blu-ray read/write
1x Phillips LightScribe DVD read/write
PSU
Corsair HX1000
Case
CoolerMaster - Cosmos S
Cooling
Custom Liquid - 320mm rad w/ 3x 80mm fans, CPU/NB/SB Blocks
Keyboard
Logitech Illuminater Pro
Mouse
Logitech
Internet Speed
Fractional T1 - 125Mbps
Antivirus
ESET Security Suite / Microsoft Security Essentials
Browser
Cyberfox Intel x64
Other Info
OC'd to 5.0GHz @ 44c under full load
Wasnt suggesting its in the build , just wondering how i got 7 lots of adware setting up IE 8 ?
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5720 Notebook.
OS
W7 Build 7201 / Vista Home SP2 ( Both x86)
CPU
Intel Core Duo T7300 @ 2.00GHZ
Motherboard
Acer Nettling v1.07
Memory
2 GB DDR2 / 2 GB ReadyBoost
Hard Drives
260 GB ( 4 Partitions.)
300 GB External HDD.
Mouse
In the kitchen ;o)
Internet Speed
Sloooooooow
Other Info
Anyone seen the plumber ? lol
IE was your first mistake. Sorry, run Firefox and use AdBlock Plus.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build/Mod
OS
Windows 7 Home Premium x64
CPU
Intel QX9650 Extreme 4.0 GHz
Motherboard
ASUS Rampage Extreme Rev2
Memory
8GB (4x2) Corsair Dominator DDR3
Graphics Card(s)
2x Radeon R390X [8GB]
Sound Card
SupremeFX X-Fi
Monitor(s) Displays
Dell 2408WFP 26" Panel
Screen Resolution
1920x1200
Hard Drives
4x WD 2TB (8TB+ Total)
2x Crucial SSD 128GB (RAID-0)
1x LG Blu-ray read/write
1x Phillips LightScribe DVD read/write
PSU
Corsair HX1000
Case
CoolerMaster - Cosmos S
Cooling
Custom Liquid - 320mm rad w/ 3x 80mm fans, CPU/NB/SB Blocks
Keyboard
Logitech Illuminater Pro
Mouse
Logitech
Internet Speed
Fractional T1 - 125Mbps
Antivirus
ESET Security Suite / Microsoft Security Essentials
Browser
Cyberfox Intel x64
Other Info
OC'd to 5.0GHz @ 44c under full load
Thanks for the advice lol.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5720 Notebook.
OS
W7 Build 7201 / Vista Home SP2 ( Both x86)
CPU
Intel Core Duo T7300 @ 2.00GHZ
Motherboard
Acer Nettling v1.07
Memory
2 GB DDR2 / 2 GB ReadyBoost
Hard Drives
260 GB ( 4 Partitions.)
300 GB External HDD.
Mouse
In the kitchen ;o)
Internet Speed
Sloooooooow
Other Info
Anyone seen the plumber ? lol
that a good idea cap zero i'll use the advice too
 

My Computer

Computer Manufacturer/Model Number
Home Made
OS
windows 7 rc 64bit and vista 32bit
CPU
Intel Core 2 Duo e6700
Motherboard
ASUS Rampage extreme
Memory
3Gig DDR3 kingston 1066mhz
Graphics Card(s)
2x ASUS ATI HD4830 crossfired
Sound Card
Creative X-FI Fatality Audio
Monitor(s) Displays
Samsung 913c 21inch
Hard Drives
2 x Western Digital WD3200AAKS
PSU
1200w Thermaltake tough power 1200w PSU
Case
Cooler master Stacker 832 Black case
Cooling
Fan
Keyboard
Logitech G11 Gaming KB
Mouse
Logitech mx610 mouse
Internet Speed
Cable
Other Info
bench mark 6.8 out of a possible 7
Hi detoxa,



I have these too on a clean 7201 x64 install. I confirmed my hashes. Do you perhaps have Spywareblaster installed as well? I don't think it's from setting up IE8, and there's nothing wrong with running IE :sarc:. I'm thinking it might be false positives from some recent Malwarebytes updates and Spywareblaster entries. I'm running further scans with other scanners, I'll post back if I find anything more. This is the first build I've encountered this with.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Hi all
Sorry to disappoint you -- it's not so much the browser itself as to what you run in it.

Also NEVER EVER run those programs that offer to scan your registry or fix your drivers from a Browser.

This is the EASIEST way ever of getting an infected system. If you must run these wretched type of programs (they are usually sneakware -- you get things like problems found but you need to "upgrade" to a PRO (i.e PAY) version to use the feature you want) run then stand alone first (i.e from an .EXE file having scanned it carefully first).

Switch off all things like accelerators etc etc in Browsers -- ideally have as few plugins as possible -- with the speed of the Internet these days it doesn't take much longer to download a file such as a PDF / HTML or wahtever and run it in stand alone mode on your PC in a dedicated application.

Same (or especially true) for multi media files -- run these also from within a dedicated application and not within a browser.

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
These entries don't appear in my reg. But... I also haven't run IE, not once, since a clean install. My point earlier is that it doesn't appear to have come with the OS unless it's something that's installed on first-run or something that's loaded from MSN.com when it loads. No other ideas on this one.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build/Mod
OS
Windows 7 Home Premium x64
CPU
Intel QX9650 Extreme 4.0 GHz
Motherboard
ASUS Rampage Extreme Rev2
Memory
8GB (4x2) Corsair Dominator DDR3
Graphics Card(s)
2x Radeon R390X [8GB]
Sound Card
SupremeFX X-Fi
Monitor(s) Displays
Dell 2408WFP 26" Panel
Screen Resolution
1920x1200
Hard Drives
4x WD 2TB (8TB+ Total)
2x Crucial SSD 128GB (RAID-0)
1x LG Blu-ray read/write
1x Phillips LightScribe DVD read/write
PSU
Corsair HX1000
Case
CoolerMaster - Cosmos S
Cooling
Custom Liquid - 320mm rad w/ 3x 80mm fans, CPU/NB/SB Blocks
Keyboard
Logitech Illuminater Pro
Mouse
Logitech
Internet Speed
Fractional T1 - 125Mbps
Antivirus
ESET Security Suite / Microsoft Security Essentials
Browser
Cyberfox Intel x64
Other Info
OC'd to 5.0GHz @ 44c under full load

My Computer

Computer Manufacturer/Model Number
Self Built
OS
XP Pro SP3 x86/Vista SP2 x64/Win7 x64 Triple-boot
CPU
AMD64 X2 AM2 5000+
Motherboard
Asus MSN-X Plus
Memory
Corsair TWX 2Gb (2x1Gb) DDR2 800Mhz
Graphics Card(s)
PCI-X 2.0 Inno3D (NVidia) 9500GT 1Gb DDR2
Sound Card
Onboard Realtec ALC662-GR
Monitor(s) Displays
Relisys 17' CRT (model unknown)
Screen Resolution
1024x768
Hard Drives
750Gb Samsung 7200-3Gb/s 32Mb Cache SATA
PSU
500W
Cooling
Standard AMD CPU Fan, One side, front and rear case fan.
Keyboard
Microsoft Multimedia Keyboard
Mouse
Samsung Optical
Internet Speed
10M
Here is an entry on Malwarebytes support forum. I'm betting these are false positives from a recent Malwarebytes update. Probably malwarebytes/Spywareblaster entry FPs. Some others reporting it, no mention of them using Win 7 at all.

Are These FP's? - Malwarebytes Forum
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5

My Computer

Computer Manufacturer/Model Number
Self Built
OS
XP Pro SP3 x86/Vista SP2 x64/Win7 x64 Triple-boot
CPU
AMD64 X2 AM2 5000+
Motherboard
Asus MSN-X Plus
Memory
Corsair TWX 2Gb (2x1Gb) DDR2 800Mhz
Graphics Card(s)
PCI-X 2.0 Inno3D (NVidia) 9500GT 1Gb DDR2
Sound Card
Onboard Realtec ALC662-GR
Monitor(s) Displays
Relisys 17' CRT (model unknown)
Screen Resolution
1024x768
Hard Drives
750Gb Samsung 7200-3Gb/s 32Mb Cache SATA
PSU
500W
Cooling
Standard AMD CPU Fan, One side, front and rear case fan.
Keyboard
Microsoft Multimedia Keyboard
Mouse
Samsung Optical
Internet Speed
10M
What I suspected. FP's with Spywareblaster entries.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Just an update.


The false positives have been fixed in the latest Malwarebytes update. if you update MB, you can scan again and it won't pick it up. ;)
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
ad-ware

did you import anything from the previous installation? sometimes things look like shortcuts but really are either java or a disguised exe.

Good Luck

Ken
 

My Computer

Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up
They're just Spywareblaster entries being picked up as false positives. No danger.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Airbot 2.0
OS
Windows 7 Ultimate x64 SP1
CPU
Core i7 920 (D0) @ 4Ghz, *26c idle *65c full load on air
Motherboard
Asus P6X58D Premium - Sata 6Gb/s - USB 3.0
Memory
12GB DDR3 Corsair Dominator -CMD12GX3M6A1600C8 at 1600MHz
Graphics Card(s)
Zotac Geforce GTX 770
Sound Card
ASUS Xonar D2X
Monitor(s) Displays
1 LG 24" Flatron W2453V-PF 1 Samsung 24" P2450H both 2ms RT
Screen Resolution
1920x1080@60hz
Hard Drives
1 Samsung 250GB 840 Evo SSD
1 OCZ Vertex2 180GB SSD
1 TB Samsung Spinpoint F1 7200RPM 32MB cache
2 500GB WD Caviar Blacks 7200RPM 32MB cache (WD5001AALS)

Pioneer DVD Burner DVR-S18M
PSU
Corsair HX1000W
Case
Cooler Master HAF 932
Cooling
Case Fans *3 230mm, *1 140mm/CPU - *Tuniq Tower 120 Extreme
Keyboard
Logitech Wireless MK700
Mouse
Logitech Wireless MK700
Internet Speed
DL 15 Mbps UL 0.98 Mbps
Antivirus
None
Browser
Firefox Nightly
Other Info
Processor-7.7 *RAM- 7.9 *Graphics-7.9 *Gaming Graphics- 7.9 *SSD- 7.8 W.E.I final score= 7.7
*Phone- LG Nexus 5
Also NEVER EVER run those programs that offer to scan your registry or fix your drivers from a Browser.

This is the EASIEST way ever of getting an infected system. If you must run these wretched type of programs (they are usually sneakware -- you get things like problems found but you need to "upgrade" to a PRO (i.e PAY) version to use the feature you want) run then stand alone first (i.e from an .EXE file having scanned it carefully first).
I wholeheartedly concur.
Almost every 'warning' of that kind is usually a Trojan in disguise.
Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites
 

My Computer

Computer Manufacturer/Model Number
Lenovo ThinkPad T61p
OS
Windows 7 Professional x64 RTM
CPU
Intel Core 2 Duo T8300 2.4GHz
Memory
4GB Corsair DDR2-667 (2x2GB)
Graphics Card(s)
NVIDIA Quadro FX 570M
Screen Resolution
1680x1050
Hard Drives
Seagate 160GB 7200rpm SATA
Mouse
Logitech MX518
Internet Speed
DSL 6Mbps
I wholeheartedly concur.
Almost every 'warning' of that kind is usually a Trojan in disguise.
Spyware Warrior: Rogue/Suspect Anti-Spyware Products & Web Sites

Thanks for all the advice as it really annoyed me that i got infected for no good reason . I have learnt the hard way over the years and i kinda pride myself by not getting any nasties on my system. Ive installed various leaks from this forum and they have all been as "clean as a whistle" and i know that the sources are trusted by the more experienced users that use this forum.

Ive just read my original post again and if it came across that i was blaming the build or the original source (Sukonka) i apologise.

Thanks again :D

Sean.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5720 Notebook.
OS
W7 Build 7201 / Vista Home SP2 ( Both x86)
CPU
Intel Core Duo T7300 @ 2.00GHZ
Motherboard
Acer Nettling v1.07
Memory
2 GB DDR2 / 2 GB ReadyBoost
Hard Drives
260 GB ( 4 Partitions.)
300 GB External HDD.
Mouse
In the kitchen ;o)
Internet Speed
Sloooooooow
Other Info
Anyone seen the plumber ? lol
Back
Top