Announcement

Collapse
No announcement yet.

TS472 Low Noise Mic Preamp

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • #16
    Malware found these:

    Registry Key: 9
    PUP.Optional.DriverIdentifier, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL \{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1, No Action By User, 1148, 368276, , , ,
    PUP.Optional.Restoro, HKU\S-1-5-21-4062412232-2938986799-297749370-1000\SOFTWARE\Restoro, No Action By User, 776, 551610, 1.0.27963, , ame,
    PUP.Optional.Restoro, HKU\S-1-5-21-4062412232-2938986799-297749370-1000\SOFTWARE\Local AppWizard-Generated Applications\Restoro, No Action By User, 776, 551612, 1.0.27963, , ame,
    PUP.Optional.InstallCore, HKU\S-1-5-21-4062412232-2938986799-297749370-1000\SOFTWARE\CSASTATS\ic, No Action By User, 505, 586068, 1.0.27963, , ame,
    PUP.Optional.Restoro, HKLM\SOFTWARE\Restoro, No Action By User, 776, 551614, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, HKLM\SOFTWARE\CLASSES\driveruploader, No Action By User, 1148, 368278, 1.0.27963, , ame,
    PUP.Optional.Restoro, HKLM\SOFTWARE\CLASSES\CLSID\{BA827421-E282-479E-AE60-34796877B8AE}, No Action By User, 776, 551619, , , ,
    PUP.Optional.Restoro, HKLM\SOFTWARE\CLASSES\Restoro.Engine.1, No Action By User, 776, 551619, , , ,
    PUP.Optional.Restoro, HKLM\SOFTWARE\CLASSES\Restoro.Engine, No Action By User, 776, 551619, 1.0.27963, , ame,

    Registry Value: 0
    (No malicious items detected)

    Registry Data: 0
    (No malicious items detected)

    Data Stream: 0
    (No malicious items detected)

    Folder: 7
    PUP.Optional.Babylon, C:\Users\jjj\AppData\Local\Babylon\Setup, No Action By User, 397, 339640, , , ,
    PUP.Optional.Babylon, C:\USERS\JJJ\APPDATA\LOCAL\BABYLON, No Action By User, 397, 339640, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\PROGRAM FILES\DRIVER IDENTIFIER, No Action By User, 1148, 368276, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVER IDENTIFIER, No Action By User, 1148, 368277, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\USERS\JJJ\APPDATA\ROAMING\DRIVERIDENTIFIER, No Action By User, 1148, 368279, 1.0.27963, , ame,
    PUP.Optional.MailRu, C:\USERS\JJJ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, No Action By User, 259, 454830, , , ,
    Adware.Elex.ShrtCln, C:\USERS\JJJ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\LevelDB, No Action By User, 296, 454693, , , ,

    File: 38
    PUP.Optional.Babylon, C:\USERS\JJJ\APPDATA\LOCAL\BABYLON\SETUP\SETUP2.ZPB, No Action By User, 397, 339640, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\7z.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\7z.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\devcon.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\devcon64.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\DriverIdentifier.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\info.data, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\libeay32.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\libssh2.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\MyDriverUploader.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\php.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\php.ini, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\php5.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\php_curl.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\php_mbstring.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\psvince.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\ssleay32.dll, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\unins000.dat, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\Program Files\Driver Identifier\unins000.exe, No Action By User, 1148, 368276, , , ,
    PUP.Optional.DriverIdentifier, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Identifier\Driver Identifier.lnk, No Action By User, 1148, 368277, , , ,
    PUP.Optional.DriverIdentifier, C:\Users\jjj\AppData\Roaming\driveridentifier\log.txt, No Action By User, 1148, 368279, , , ,
    PUP.Optional.Restoro, C:\WINDOWS\RESTORO.INI, No Action By User, 776, 551609, 1.0.27963, , ame,
    HackTool.WinActivator, C:\USERS\JJJ\APPDATA\ROAMING\WINDOWSLOADER\WINDOWS 7 LOADER.EXE, No Action By User, 7918, 352889, 1.0.27963, , ame,
    PUP.Optional.Restoro, C:\USERS\JJJ\APPDATA\LOCAL\TEMP\RESTOROTEMP.EXE, No Action By User, 776, 551611, 1.0.27963, , ame,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000005.ldb, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\005245.ldb, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\005247.ldb, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\005249.log, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\005250.ldb, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\CURRENT, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\Users\jjj\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\MANIFEST-000001, No Action By User, 259, 454830, , , ,
    PUP.Optional.MailRu, C:\USERS\JJJ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, No Action By User, 259, 454830, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\USERS\JJJ\DESKTOP\PC-TOOLS\DRIVER IDENTIFY\DRIVERIDENTIFIER_SETUP.EXE, No Action By User, 1148, 368275, 1.0.27963, , ame,
    PUP.Optional.DriverIdentifier, C:\USERS\JJJ\DESKTOP\STORE\DRIVER IDENTIFY\DRIVERIDENTIFIER_SETUP.EXE, No Action By User, 1148, 368275, 1.0.27963, , ame,
    Adware.Elex.ShrtCln, C:\USERS\JJJ\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Secure Preferences, No Action By User, 296, 454693, 1.0.27963, , ame,

    I'm not sure if there's is true malware among it?
    I now changed my PW for this forum...
    Last edited by jjj; 08-05-2020, 08:24 AM.

    Comment


    • #17
      Your computer is infected with Babylon. maybe more. It's not a subject I know much about.
      Experience is something you get, just after you really needed it.

      Comment


      • #18
        Yes. As nickb said, you are definitely infected. Is that post from a Malwarebytes scan? If so, did you direct Malwarebytes to remove the malware? If so, did you rescan to see if anything was still there?
        "I took a photo of my ohm meter... It didn't help." Enzo 8/20/22

        Comment


        • #19
          I thought 'Babylon' was just a toolbar extension.

          Comment


          • #20
            It's an especially nasty piece of adware.

            "Babylon Toolbar is an annoying browser toolbar that changes your Internet browser default search engine, homepage, and displays deceptive ads. This toolbar self-installs on all major browsers including Google Chrome, Internet Explorer, and Mozilla Firefox. While this toolbar is not malware or a virus, it is categorized as a potentially unwanted program or adware."

            Anything that self installs is malware in my book.
            Experience is something you get, just after you really needed it.

            Comment


            • #21
              Thanks for the clarification.

              Comment

              Working...
              X