Accidentally clicked "Download"...

I went to a website where you can get free worksheets/materials for teachers. The website appears to be intentionally misleading; underneath the worksheet you want, there is a button that says “download”. On first glance, one assumes to get the worksheet you click “download”. However, in tiny print, it says it is an advertisement, and not related to the website itself.

I clicked “download”, twice, but something didn’t seem right and I didn’t continue with the installation process. However, some weird programs popped up (a PDF reader, a zip extractor).

Have I potentially harmed my computer? Here is the site/specific page in question:

Here is the other one…a program called “Open PDF”. Like I said, I clicked “download”, then “run”…but both times I didn’t go any further than that. Not sure if I’ve done any damage or downloaded any potentially harmful programs.

It’s really disappointing that the website SEEMS to have made the process to get their “free” materials intentionally misleading to get people to download potentially unwanted programs. It still isn’t quite clear how to ACTUALLY get the materials. :frowning:


If I took that correctly, you’re a teacher correct? If so, if that is a work computer given to you by the school have your IT Department fix it.

If that computer is a home computer for personal use and you were looking for stuff at home: Follow this guide and attach the following logs. MBAM (MalwareByte)/OTL/aswMBR

Note: aswMBR is for Windows 7 only


Once this has been completed, and is considered a home computer, I can notify an expert to remove any malware/PUP/Viruses on your system.

Might be worth reading this page

Not a teacher, a speech therapist. I use my own personal computer.

I will go through the scanning again. You JUST got me straight from my last situation! Sorry! :frowning:

Malware Bytes Log:

Malwarebytes Anti-Malware

Database version: v2014.01.03.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
tech :: WENDY-PC [administrator]

1/8/2014 2:05:37 PM
mbam-log-2014-01-08 (14-05-37).txt

Scan type: Full scan (C:|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 374971
Time elapsed: 1 hour(s), 4 minute(s), 19 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 3
C:\Users\tech\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S0VVRUH3\ZipExtractorSetup.exe (PUP.Optional.InstallCore) → Quarantined and deleted successfully.
C:\Users\tech\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TX53VTC4\pdf_14315_2210.exe (PUP.Optional.InstallIQ) → Quarantined and deleted successfully.
C:\Users\tech\AppData\Local\Temp\ICReinstall_ZipExtractorSetup.exe (PUP.Optional.InstallCore) → Quarantined and deleted successfully.


If you could run the OTL scan I will take a look see :slight_smile:

Here is the OTL log:

You have delta search in chrome

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

Some tips for the Future if I may.

  1. When downloading programs, either legit or not legit. Make sure you un-tick the “Optional” Options.

  2. Make sure all programs come from legit sources. Ex: Java comes from the homepage.

  3. Make sure Shields are active to protect against any threats.

Thank you for the tips. I was really surprised how sneaky that website was!

AdwCleaner v3.016 - Report created 09/01/2014 at 13:05:10

Updated 23/12/2013 by Xplode

Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)

Username : tech - WENDY-PC

Running from : C:\Users\tech\Desktop\AdwCleaner.exe

Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\BrowserDefender
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it!
Folder Deleted : C:\Program Files (x86)\openit
File Deleted : C:\Users\Public\Desktop\Open It!.lnk

***** [ Shortcuts ] *****

***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Key Deleted : HKLM\SOFTWARE\Classes\d
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKCU\Software\5a0df8dbd38e940
Key Deleted : HKLM\SOFTWARE\5a0df8dbd38e940
Key Deleted : HKLM\SOFTWARE\Classes\AppID{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{39CB8175-E224-4446-8746-00566302DF8D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Key Deleted : HKLM\SOFTWARE\Classes\AppID{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface{F05B12E1-ADE8-4485-B45B-898748B53C37}
Key Deleted : HKCU\Software\dsiteproducts
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OpenIt Open It!

***** [ Browsers ] *****

-\ Internet Explorer v11.0.9600.16428

-\ Google Chrome v32.0.1700.72

[ File : C:\Users\tech\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : icon_url
Deleted : search_url
Deleted : keyword

AdwCleaner[R0].txt - [2666 octets] - [09/01/2014 12:57:23]
AdwCleaner[S0].txt - [2604 octets] - [09/01/2014 13:05:10]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2664 octets] ##########

Is the computer behaving itself now :slight_smile:

Yes! :smiley: Everything seems to be doing well!

In that case methinks I will send you on your merry way :slight_smile:

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

Clear Restore Points

Go Start > All Programmes > Accessories > System tools
Right click Disc Cleanup and select run as administrator
When it pops up at the first prompt select OK after it has done some calculations the tabs will appear
Select More Options tab
Press Sytem Restore and Shadow Copies Cleanup button

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article and this article.
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware


Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?Keep safe :wave: