I tried to download a Taipei game from download.com. When I ran the install file, it put up several screens asking if I wanted other software like Reg Pro Cleaner and something like Desktop Manager. None of the screens had a cancel button and the X icon was greyed out. I got suspicious, so I tried to close it down. It wouldn't let me, so I forced it using Task Manager.
Then I opened the Add/Remove software applet. It showed that Reg Pro Cleaner was installed. I clicked the Remove butten, but that just restarted the program. It looked like it was trying to install more software, so I forced it again. I also noticed that the browser where I got the file was running something called trovi.com. And the install program kept restarting, so I forced a shutdown from the DOS box, rebooted in safe mode, and ran Malwarebytes. It ran for 2 hours and found something like 241 "non-malware" items. I saved the log and let it quarantine them all.
When it finished, I rebooted in safe mode, then opened the Add/Remove programs applet and found that Reg Pro Cleaner is still there.
On my other computer (where I am posting now), I searched for trovi.com and found that it is malware and that Malwearebytes should remove it. I checked the log and it says it was quarantined. The log also shows the that it qwuarantined Desktop%20Taipei.exe, which is the name of the install file mI downloaded, I think.
So now my questions are:
- Have I done everything right so far?
- Is there anything more I need to do?
- What do I need to do to get rid of Reg Pro Cleaner? I am reluctant to run the Remove program from Add/Remove programs.
And finally, what can I do to punish download.com? But we can deal with that later.