I was wondering if this “Ascentive Library Installer” is containing any viruses… It seems rather suspicious, but maybe someone can shed som light on it… Btw, didn’t find anything in the installer with avast free edition and free edition of SuperAntispyware!
[ scan result ]
a-squared 4.0.0.93/20090201 found nothing
AhnLab-V3 5.0.0.2/20090131 found nothing
AntiVir 7.9.0.60/20090130 found [ADSPY/EShoper.BC.1]
Authentium 5.1.0.4/20090131 found nothing
Avast 4.8.1281.0/20090201 found nothing
AVG 8.0.0.229/20090131 found nothing
BitDefender 7.2/20090201 found nothing
CAT-QuickHeal 10.00/20090131 found nothing
ClamAV 0.94.1/20090201 found nothing
Comodo 955/20090131 found nothing
DrWeb 4.44.0.09170/20090201 found nothing
eSafe 7.0.17.0/20090129 found [Win32.ADSPYEShoper.b]
eTrust-Vet 31.6.6335/20090129 found nothing
F-Prot 4.4.4.56/20090131 found nothing
F-Secure 8.0.14470.0/20090201 found nothing
Fortinet 3.117.0.0/20090131 found nothing
GData 19/20090201 found nothing
Ikarus T3.1.1.45.0/20090201 found nothing
K7AntiVirus 7.10.612/20090131 found nothing
Kaspersky 7.0.0.125/20090201 found nothing
McAfee 5512/20090131 found nothing
McAfee+Artemis 5512/20090131 found nothing
Microsoft 1.4306/20090131 found nothing
NOD32 3816/20090201 found nothing
Norman 6.00.02/20090131 found nothing
nProtect 2009.1.8.0/20090130 found nothing
Panda 9.5.1.2/20090131 found nothing
PCTools 4.4.2.0/20090131 found nothing
Prevx1 V2/20090201 found nothing
Rising 21.13.42.00/20090123 found nothing
SecureWeb-Gateway 6.7.6/20090130 found [Ad-Spyware.EShoper.BC.1]
Sophos 4.38.0/20090201 found nothing
Sunbelt 3.2.1835.2/20090116 found nothing
Symantec 10/20090201 found nothing
TheHacker 6.3.1.5.243/20090201 found nothing
TrendMicro 8.700.0.1004/20090130 found nothing
VBA32 3.12.8.12/20090201 found nothing
ViRobot 2009.1.31.1583/20090131 found nothing
VirusBuster 4.5.11.0/20090131 found nothing
Whilst this is a low level of detection and all the same. It would appear that this spys on your browsing habits to gather marketing information to deliver ads that you might be more likely to respond to. Given that and the very poor WOT ranking I would have to as how it got on your system as it seems undesirable ?
I would have though there would have been an associated uninstaller fot the “Ascentive Library Installer” That is the problem with these types of things, they are often considered opt-in as they purport to offer a service like eshopper in this case.
There is also MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.
This tool should show what is running and allow you to fix the registry entry responsible for running it, it would also show where the associated files are located (handy if there is no uninstaller or add remove programs entry).
Download and run HJT and post the contents of the log file (cut and paste or attach the log file) into this topic, you may need to split it over two or more posts depending on how large it is.
Malewarebyte didn’t find anything, and here’s the Hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:19:39, on 2009-02-01
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
I can’t see a trace from the virus… that a the bad sign I suppose. What do you recommend, is formatting the drive the best way to go (would hate to do it though).
Something looks wrong with your log file, it appears to be missing large chunks of information, e.g. there doesn’t seem to be many running processes.
There however many files reported as missing, this could well be an incompatibility with Vista SP1 and HiJackThis, I don’t know, but you should check the physical locations that the files are in fact there.
Other than that I don’t see anything obvious.
You don’t appear to have an active firewall - It should be capable of blocking unauthorised outbound Internet Connections. - What is your firewall ?
Presumably the Vista one, were the outbound checking is disabled by default - You could also enable the outbound protection of the Vista firewall, but it isn’t very friendly, is rule based and you have to create the rules. - Vista Firewall Control, check out this topic for some user friendly help for the Vista Firewall, Outbound protection, http://forum.avast.com/index.php?topic=30234.0
The built in firewall is fine, but it doesn’t enable outbound protection and you need to do that, but it isn’t very friendly, hence the link about the Vista Firewall Control info.
It shouldn’t make any difference what the log contains by not having it in the default location.
How many times have you seen it on the desktop, that is when we say it should be in a folder of its own so that backups are contained within that specific folder. So that is the only requirement it be in a folder specifically created for HJT, but it doesn’t matter where. I used to have mine in a different partition.
First of all I wanted to thank you for taking an interest in my “problem” and for helping. Secondly, just wanted to check if it’s okay to use COMDO free firewall (is it any good?) instead of the inbuilt Vista one?
Third, I use avast! (free version), SpywareBlaster (free version), COMDO Firewall (free version), SuperAntiSpyware (free version) and Malwarebytes Antimalware (free version)… is there anything I might have missed or can you find a flaw? Is there perhaps something more that I can add to my viruskilling arsenal?
Finally, any handy tips that can help me in this virus-manifested cyberworld of ours?