Paranoid about Malware (YT DL spyware?)

I have downloaded a program called “Free Youtube Downloader” from CNet

Link:http://download.cnet.com/Free-YouTube-Downloader/3000-2071_4-75219434.html?tag=dropDownForm;productListing;pop

Some misc info:
During the installation it asks me to downloader other stuff which I say no, so I only install the prog. and at the end if I accept the agreement of the program I didn’t want to download which I said no again and it installed without other progs.

What happened:
Only the prog. got installed with some suspicion. Luckily I guess it didn’t install anything else.

I used it but I decided to uninstall because it was fishy.
So after that I felt paranoid decided to search for info.
I ended up with these funny facts:

  • People try to find a virus free downloader even thought the first choice is the CNET version on google.
  • Some people got adware installed and I didn’t get nothing.
  • Some antiviruses on other PCs tagged it as a virus.
  • Lots of 1 star CNET reviews.

Strange link:
[suspicious]I also got directed onto this link: youtubedownloader.com/xx/uninstalled[/suspicious]

Paranoy:
And then a block from a firewall ~/Temp/_iu14D2N.tmp flagged as Install Hook.

During a download from CNET, CNET needed to install their download manager, and shoved Wajam down my throat, without my consent (unless it’s in their many page tiny print EULA that I din’t read) The only thing that caught this was my avast! Firewall, as Wajam attempted an outside connection. I am very disappointed in CNET now, as it is no longer a safe download site.

J.R. Guthrie

most of the longtime users of this forum have stoped using CNET bc the downloader also install some browser/toolbar/adware crap

you may run AdwCleaner to clear it out http://forum.avast.com/index.php?topic=53253.0

I cleared it.
I was very lucky that the installer didn’t install anything visible I guess (anything with UI) and the installer tricks you into installing their adware. (Notice the, “Accept the adware crap name EULA?” box even if you select no?)

There is nothing happening to my computer yet and everything is smooth to me.

Here’s my log, I hope it’s all OK:

# AdwCleaner v2.105 - Logfile created 01/10/2013 at 20:30:41 # Updated 08/01/2013 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : removed # Boot Mode : Normal # Running from : C:\Users\removed\Desktop\adwcleaner.exe # Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

Folder Deleted : C:\Users\removed\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes{2FA28606-DE77-4029-AF96-B231E3B8F827}

***** [Internet Browsers] *****

-\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\ Opera v12.2.1578.0

File : C:\Users\removed\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.


AdwCleaner[R1].txt - [1415 octets] - [10/01/2013 20:27:55]
AdwCleaner[R2].txt - [1475 octets] - [10/01/2013 20:30:06]
AdwCleaner[S2].txt - [1272 octets] - [10/01/2013 20:30:41]

########## EOF - C:\AdwCleaner[S2].txt - [1332 octets] ##########

Edit:

This just seems real-time? lmao