Solved Spigot Inc problem

Discussion in 'Virus, Spyware and Malware Removal' started by tomcal25, Sep 26, 2011.


Thread Status:
Not open for further replies.
  1. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
    Hi, I have McAfee anti-virus for AOL and Ad-Aware installed on my Dell PC running Windows XP. From time to time I get a Hacker Alert that says "A program on your PC is trying to access the enternet" Not knowing what it is, I block it each time. Below is information McAffee displays;

    Program: Application Updater
    Location: C:\program files\application
    Updater\applicationUpdater.exe version 4.6

    I looked a properties and it say "Spigot Inc" Installed August 2011



    What is Spigot Inc? Should it be removed and how?

    Another issue which I don't know if it's related is my AOL mail account was hacked and remotely sending out spam to everyone in my address book. I changed my password and removed my user name and other unkown names in my address book per AOL help. That seemed to help. Sigot install date and AOL spam problem seemed to happen around the same time.

    Thanks in advance for your help .... Tom
  2. driver_ian PCHF SMR Graduate.

    PCHF Staff
    Message Count:
    6,985
    Likes Received:
    993
    My System
    Loading...
    Hi tomcal and welcome to the forum,
    We have a tried and trusted method of malware removal here at PCHF therefore I would like you do the Prework (follow the link at the bottom of this post) and post the resulting logs back here. Once we have the logs the security team will check them and advise you of your next course of action.

    Thanks for your patience.
  3. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
    Thanks for your quick reply. The two logs are shown below. I noticed 'Application Updater in both logs.... Tom


    Windows IP Configuration

    Host Name . . . . . . . . . . . . : FAMILY
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel(R) 82562V-2 10/100 Network Connection
    Physical Address. . . . . . . . . : 00-1D-09-90-C7-14
    Dhcp Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    IP Address. . . . . . . . . . . . : 192.168.1.100
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 192.168.1.1
    DHCP Server . . . . . . . . . . . : 192.168.1.1
    DNS Servers . . . . . . . . . . . : 167.206.254.2
    167.206.254.1
    Lease Obtained. . . . . . . . . . : Tuesday, September 27, 2011 11:35:06 AM
    Lease Expires . . . . . . . . . . : Monday, October 03, 2011 11:35:06 AM

    Pinging 194.119.131.66 with 32 bytes of data:

    Reply from 194.119.131.66: bytes=32 time=98ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=97ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=96ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=96ms TTL=54

    Ping statistics for 194.119.131.66:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 96ms, Maximum = 98ms, Average = 96ms

    Pinging plus.net [212.159.8.2] with 32 bytes of data:

    Reply from 212.159.8.2: bytes=32 time=103ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=101ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=102ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=101ms TTL=243

    Ping statistics for 212.159.8.2:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 101ms, Maximum = 103ms, Average = 101ms

    Tracing route to cns1.uk.vianw.net [194.119.131.66]
    over a maximum of 30 hops:

    1 * * * Request timed out.
    2 9 ms 9 ms 7 ms dstswr1-vlan2.rh.stjmny.cv.net [167.206.39.161]
    3 10 ms 14 ms 9 ms rtr4-ge1-10.mhe.hcvlny.cv.net [167.206.39.137]
    4 11 ms 11 ms 11 ms rtr4-tg11-3.wan.hcvlny.cv.net [64.15.4.37]
    5 11 ms 11 ms 11 ms 64.15.1.54
    6 11 ms 11 ms 12 ms g4-1-tn-cr1.router.us.clara.net [198.32.160.187]
    7 100 ms 97 ms 97 ms g1-1-0-t6-br1.router.uk.clara.net [195.8.68.101]
    8 99 ms 97 ms 98 ms ge-3-1-t6-cr2.router.uk.clara.net [195.157.6.201]
    9 97 ms 98 ms 97 ms ten0-0-0-t40-cr1.router.uk.clara.net [195.8.68.117]
    10 101 ms 96 ms 98 ms g5-1-t40-ar12.router.uk.clara.net [195.157.6.177]
    11 95 ms 95 ms 95 ms cns1.uk.vianw.net [194.119.131.66]

    Trace complete.
    These Windows services are started:
    AOL Connectivity Service
    AOL TopSpeed Monitor
    Apple Mobile Device
    Application Layer Gateway Service
    Application Updater
    Automatic Updates
    Background Intelligent Transfer Service
    COM+ Event System
    Computer Browser
    Cryptographic Services
    DCOM Server Process Launcher
    DHCP Client
    Distributed Link Tracking Client
    DNS Client
    Error Reporting Service
    Event Log
    Fast User Switching Compatibility
    Help and Support
    iPod Service
    IPSEC Services
    Java Quick Starter
    Lavasoft Ad-Aware Service
    Logical Disk Manager
    Machine Debug Manager
    McAfee Firewall Core Service
    McAfee Network Agent
    McAfee Personal Firewall Service
    McAfee Proxy Service
    McAfee Services
    McAfee Validation Trust Protection Service
    McAfee VirusScan Announcer
    McShield
    Network Connections
    Network Location Awareness (NLA)
    Plug and Play
    Print Spooler
    Protected Storage
    Remote Access Connection Manager
    Remote Procedure Call (RPC)
    Remote Registry
    Secondary Logon
    Security Accounts Manager
    Security Center
    Server
    Shell Hardware Detection
    SSDP Discovery Service
    SupportSoft Sprocket Service (dellsupportcenter)
    System Event Notification
    System Restore Service
    Task Scheduler
    TCP/IP NetBIOS Helper
    Telephony
    Terminal Services
    Themes
    WebClient
    Windows Audio
    Windows Firewall/Internet Connection Sharing (ICS)
    Windows Image Acquisition (WIA)
    Windows Management Instrumentation
    Windows Time
    Wireless Zero Configuration
    Workstation
    The command completed successfully.

    Microsoft Windows XP [Version 5.1.2600]
    The following command was not found: interface ipv4 show subinterfaces.
    ===========================================================================
    Interface List
    0x1 ........................... MS TCP Loopback interface
    0x2 ...00 1d 09 90 c7 14 ...... Intel(R) 82562V-2 10/100 Network Connection - Packet Scheduler Miniport
    ===========================================================================
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.100 20
    127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
    192.168.1.0 255.255.255.0 192.168.1.100 192.168.1.100 20
    192.168.1.100 255.255.255.255 127.0.0.1 127.0.0.1 20
    192.168.1.255 255.255.255.255 192.168.1.100 192.168.1.100 20
    224.0.0.0 240.0.0.0 192.168.1.100 192.168.1.100 20
    255.255.255.255 255.255.255.255 192.168.1.100 192.168.1.100 1
    Default Gateway: 192.168.1.1
    ===========================================================================
    Persistent Routes:
    None

    Local Area Connection:
    Node IpAddress: [192.168.1.100] Scope Id: []

    No Connections

    ! REG.EXE VERSION 3.0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
    HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
    Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
    RTHDCPL REG_SZ RTHDCPL.EXE
    Alcmtr REG_SZ ALCMTR.EXE
    PDVDDXSrv REG_SZ "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
    dscactivate REG_SZ "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    HostManager REG_SZ C:\Program Files\Common Files\AOL\1207122118\ee\AOLSoftware.exe
    AOLDialer REG_SZ C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    CanonSolutionMenu REG_SZ C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    CanonMyPrinter REG_SZ C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    SSBkgdUpdate REG_SZ "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    OpwareSE4 REG_SZ "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
    Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    <NO NAME> REG_SZ
    SearchSettings REG_SZ "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
    mcui_exe REG_SZ "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
    ! REG.EXE VERSION 3.0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    AvgUninstallURL REG_SZ cmd.exe /c start AVG - Free Uninstall Survey
    ! REG.EXE VERSION 3.0
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
    MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
    ! REG.EXE VERSION 3.0
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    Microsoft Windows XP [Version 5.1.2600]




    Windows IP Configuration

    Host Name . . . . . . . . . . . . : FAMILY
    Primary Dns Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Unknown
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No

    Ethernet adapter Local Area Connection:

    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel(R) 82562V-2 10/100 Network Connection
    Physical Address. . . . . . . . . : 00-1D-09-90-C7-14
    Dhcp Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    IP Address. . . . . . . . . . . . : 192.168.1.100
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Default Gateway . . . . . . . . . : 192.168.1.1
    DHCP Server . . . . . . . . . . . : 192.168.1.1
    DNS Servers . . . . . . . . . . . : 167.206.254.2
    167.206.254.1
    Lease Obtained. . . . . . . . . . : Tuesday, September 27, 2011 11:35:06 AM
    Lease Expires . . . . . . . . . . : Monday, October 03, 2011 11:35:06 AM
    The following command was not found: wlan show networks mode=bssid.

    Pinging 194.119.131.66 with 32 bytes of data:

    Reply from 194.119.131.66: bytes=32 time=98ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=96ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=96ms TTL=54
    Reply from 194.119.131.66: bytes=32 time=98ms TTL=54

    Ping statistics for 194.119.131.66:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 96ms, Maximum = 98ms, Average = 97ms

    Pinging plus.net [212.159.8.2] with 32 bytes of data:

    Reply from 212.159.8.2: bytes=32 time=101ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=100ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=100ms TTL=243
    Reply from 212.159.8.2: bytes=32 time=101ms TTL=243

    Ping statistics for 212.159.8.2:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
    Minimum = 100ms, Maximum = 101ms, Average = 100ms

    Tracing route to cns1.uk.vianw.net [194.119.131.66]
    over a maximum of 30 hops:

    1 * * * Request timed out.
    2 8 ms 9 ms 8 ms dstswr1-vlan2.rh.stjmny.cv.net [167.206.39.161]
    3 9 ms 10 ms 10 ms rtr4-ge1-10.mhe.hcvlny.cv.net [167.206.39.137]
    4 12 ms 11 ms 11 ms rtr4-tg11-3.wan.hcvlny.cv.net [64.15.4.37]
    5 11 ms 11 ms 11 ms 64.15.1.54
    6 10 ms 15 ms 11 ms g4-1-tn-cr1.router.us.clara.net [198.32.160.187]
    7 105 ms 96 ms 96 ms g1-1-0-t6-br1.router.uk.clara.net [195.8.68.101]
    8 102 ms 96 ms 98 ms ge-3-1-t6-cr2.router.uk.clara.net [195.157.6.201]
    9 101 ms 97 ms 97 ms ten0-0-0-t40-cr1.router.uk.clara.net [195.8.68.117]
    10 100 ms 97 ms 97 ms g5-1-t40-ar12.router.uk.clara.net [195.157.6.177]
    11 101 ms 95 ms 95 ms cns1.uk.vianw.net [194.119.131.66]

    Trace complete.
    These Windows services are started:
    AOL Connectivity Service
    AOL TopSpeed Monitor
    Apple Mobile Device
    Application Layer Gateway Service
    Application Updater
    Automatic Updates
    Background Intelligent Transfer Service
    COM+ Event System
    Computer Browser
    Cryptographic Services
    DCOM Server Process Launcher
    DHCP Client
    Distributed Link Tracking Client
    DNS Client
    Error Reporting Service
    Event Log
    Fast User Switching Compatibility
    Help and Support
    iPod Service
    IPSEC Services
    Java Quick Starter
    Lavasoft Ad-Aware Service
    Logical Disk Manager
    Machine Debug Manager
    McAfee Firewall Core Service
    McAfee Network Agent
    McAfee Personal Firewall Service
    McAfee Proxy Service
    McAfee Services
    McAfee Validation Trust Protection Service
    McAfee VirusScan Announcer
    McShield
    Network Connections
    Network Location Awareness (NLA)
    Plug and Play
    Print Spooler
    Protected Storage
    Remote Access Connection Manager
    Remote Procedure Call (RPC)
    Remote Registry
    Secondary Logon
    Security Accounts Manager
    Security Center
    Server
    Shell Hardware Detection
    SSDP Discovery Service
    SupportSoft Sprocket Service (dellsupportcenter)
    System Event Notification
    System Restore Service
    Task Scheduler
    TCP/IP NetBIOS Helper
    Telephony
    Terminal Services
    Themes
    WebClient
    Windows Audio
    Windows Firewall/Internet Connection Sharing (ICS)
    Windows Image Acquisition (WIA)
    Windows Management Instrumentation
    Windows Time
    Wireless Zero Configuration
    Workstation
    The command completed successfully.

    Microsoft Windows XP [Version 5.1.2600]
    The following command was not found: interface ipv4 show subinterfaces.
    ===========================================================================
    Interface List
    0x1 ........................... MS TCP Loopback interface
    0x2 ...00 1d 09 90 c7 14 ...... Intel(R) 82562V-2 10/100 Network Connection - Packet Scheduler Miniport
    ===========================================================================
    ===========================================================================
    Active Routes:
    Network Destination Netmask Gateway Interface Metric
    0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.100 20
    127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
    192.168.1.0 255.255.255.0 192.168.1.100 192.168.1.100 20
    192.168.1.100 255.255.255.255 127.0.0.1 127.0.0.1 20
    192.168.1.255 255.255.255.255 192.168.1.100 192.168.1.100 20
    224.0.0.0 240.0.0.0 192.168.1.100 192.168.1.100 20
    255.255.255.255 255.255.255.255 192.168.1.100 192.168.1.100 1
    Default Gateway: 192.168.1.1
    ===========================================================================
    Persistent Routes:
    None

    Local Area Connection:
    Node IpAddress: [192.168.1.100] Scope Id: []

    No Connections

    ! REG.EXE VERSION 3.0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
    HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
    Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
    RTHDCPL REG_SZ RTHDCPL.EXE
    Alcmtr REG_SZ ALCMTR.EXE
    PDVDDXSrv REG_SZ "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
    dscactivate REG_SZ "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    HostManager REG_SZ C:\Program Files\Common Files\AOL\1207122118\ee\AOLSoftware.exe
    AOLDialer REG_SZ C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    CanonSolutionMenu REG_SZ C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
    CanonMyPrinter REG_SZ C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
    SSBkgdUpdate REG_SZ "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    OpwareSE4 REG_SZ "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
    iTunesHelper REG_SZ "C:\Program Files\iTunes\iTunesHelper.exe"
    Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    <NO NAME> REG_SZ
    SearchSettings REG_SZ "C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe"
    mcui_exe REG_SZ "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
    ! REG.EXE VERSION 3.0
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
    AvgUninstallURL REG_SZ cmd.exe /c start AVG - Free Uninstall Survey
    ! REG.EXE VERSION 3.0
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    DellSupportCenter REG_SZ "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
    MSMSGS REG_SZ "C:\Program Files\Messenger\msmsgs.exe" /background
    ! REG.EXE VERSION 3.0
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
  4. Google Advertisement

  5. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    I think you've posted the wrong logs. You ran Wireless Test and Network Test
  6. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
  7. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Did you run aswmbr as well?
  8. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
  9. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Ok. I haven't had a chance to look at your logs as I am at work. However, if you know you have P2P programs please remove them
  10. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
    Hi, I've removed all P2P programs that I'm aware of. Thanks, look forward to your review of my logs.
  11. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Hi,

    Does Spigot appear in the Add/Remove Programs? It shows up in the OTL logs
  12. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
    Sorry for delayed reply. I've been away from the infected computer. I don't see it in the Add/Remove programs. The only thing I see that I'm not sure of is, Net Waiting by BVRP Inc. , Earthlink setup files and Sansoft OwniPage SE 4 by Nuance Communications.
  13. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Thanks. I'll do some more rearch tonight as i'm currently at work
  14. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Hi,

    I've looked a bit more into the actual file and it is indeed malicious. Let's see if this will pick it up


    [IMG] Please download Malwarebytes Anti-Malware from Malwarebytes.org.
    Alternate link: Download Mirror

    (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!)

    Double Click mbam-setup.exe to install the application.

    (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)


    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. If you are prompted to restart, please allow it to restart your computer. Failure to do this, will cause the infection to still be active on the computer.
    • Please save the log to a location you will remember.
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found at C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
    • Copy and paste the entire report in your next reply.

    If Malwarebytes fails to download please use the following link:

    http://malwarebytes.org/mbam-download-exe-random.php
  15. tomcal25 Bronze Member

    Bronze
    Message Count:
    14
    Likes Received:
    0
    My System
    Loading...
    Hi, In my last reply I said Sigot Inc was not in my Add/ Remove Programs. That's correct, I've never observed Sigot Inc in Add/remove. However, in between posts I did remove YOU TUBE Downloader. I've read that YOU TUbe downloader can install Sigot Inc and Dealeo toolbar ( I think it's hidden in you tube downloader somewhere). So I ran another OTL scan and now Sigot Inc updater appears to be gone in the log . I'm not sure I've removed it completely by uninstalling you tube downloader. I'm really a computer beginner. Let me know what you think? Should I send you a new OTL log? What the hectic is Sigot Inc any way, a virus or trojan?
  16. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,377
    Likes Received:
    3,759
    My System
    Loading...
    Hi,

    Did you see my above post? Let's just make sure it is completely gone, and if it doesn't come up in the scan from Post 14 we'll get new logs

Spigot Inc problem

Thread Status:
Not open for further replies.