This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Inquiry for help to remove malware/viruses after installing Freecorder

Hello,

I am writing for some help. After doing a Sophos scan on my computer, 4 bad items were found which are listed below. These items were moved to the quarantine and are classified as "controlled Applications" and not as a virus/spyware, suspicious behavior, suspicious files, or adaware or PUAs.

1. Yontoo Apps

has detected components C:\Users\garyy\AppData\Local\Temp\nsk59C8.tmp\9\dropdowndeals_132013.exe

2. Google Chrome Frame

has detected components:

C:\program files (x86)\Google\Chrome\application\22.0.1229.94\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\23.0.1271.64\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\23.0.1271.91\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\23.0.1271.95\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\23.0.1271.97\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\24.0.1312.52\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\24.0.1312.57\npchrome_frame.dll

C:\program files (x86)\Google\Chrome\application\24.0.1312.56\npchrome_frame.dll

3. Conduit Toolbars

has detected components:

C:\Program Files (x86)\freecorder.exe

C:\Program Files (x86)\Freecorder\Freecorder.exe

C:\Users\garyy\AppData\Local\Temp\_ir_sf_temp_1\ConduitInstaller.exe

4. Blekko Toolbar

has detected components

C:\Program Files (x86)\freecordertoolbar\vmntemplate.dll

Just some background. I installed Freecorder version 7 which had malware and viruses, which I did not know about until I did a Sophos scan. Using Add/Remove programs in Windows Control Panel, I next removed the Freecorder program from my computer hoping that would remove the associated bad items, but it left some orphan files. I am trying to remove these bad items (viruses, malware, etc.) from my computer. Can anyone help? I am using Sophos Enpoint Security and Control version 10.0.

I tried to perform the action to delete or clean up these items, but the "perform action" button is grayed out. After clicking the "more" link, it says "manual cleanup required".

Questions:

1. What is the best and easiest way to manually remove these bad items and any associated items?

What I was about to do was to manually delete all the files that are listed as part of each detected component(s).   However, there might be more steps required like deleting registry entries and so forth, but again I do not know what I should do.

2. I also believe there were changes made to my registry which also needs to be cleaned up but again I don't know what needs to be deleted for each of the above bad items.

By the way, none of the 4 items are listed in my add/remove programs list (Using Add/Remove programs in Windows Control Panel) either so I can't remove them through that normal process. I am guessing these items were installed when I installed Freecorder (maybe bundled with the software or installed without my knowledge) but I don't know how to get these items off my computer.

Can anyone help in providing suggestions on how to clean these items off my computer? Thanks in advance.

For now, though, the items are in quarantine which I guess is a good thing but I suspect there might still be problems until I get these items off my computer.

Thanks.

:37953


This thread was automatically locked due to age.
Parents
  • Hello knotslanding,

    Application Control is different from the other features in several ways. It can't be configured locally but is only set via a central policy. There are no cleanup routines associated with the detections. The applications are considered legitimate - arguably some of them could be seen as Adware or PUAs (like certain toolbars).

    As legitimate applications they should be removable (perhaps Chrome's UI) - thus the freecorder.exe should no longer be there after uninstall. Note that the item (alert) is not removed from quarantine when you uninstall so you should check if the items are indeed still there.

    Controlled Applications should be removable either with Add/Remove Programs or their own uninstaller (the third category - part of the OS - doesn't apply here). If they aren't then Support should look into them (it has to be your site's representative/Sophos administrator who contacts them).

    Christian 

    :37965
Reply
  • Hello knotslanding,

    Application Control is different from the other features in several ways. It can't be configured locally but is only set via a central policy. There are no cleanup routines associated with the detections. The applications are considered legitimate - arguably some of them could be seen as Adware or PUAs (like certain toolbars).

    As legitimate applications they should be removable (perhaps Chrome's UI) - thus the freecorder.exe should no longer be there after uninstall. Note that the item (alert) is not removed from quarantine when you uninstall so you should check if the items are indeed still there.

    Controlled Applications should be removable either with Add/Remove Programs or their own uninstaller (the third category - part of the OS - doesn't apply here). If they aren't then Support should look into them (it has to be your site's representative/Sophos administrator who contacts them).

    Christian 

    :37965
Children
No Data