Win.Adware.Somoto in google chrome config files?

asked 2014-11-17 09:49:55 -0500

phobos13 gravatar image


I checked my home directory with ClamAV:

$clamscan -ri
/home/foo/.config/google-chrome/Default/File System/000/t/00/00000000: Win.Adware.Somoto FOUND

I doubted and checked the file type:

/home/foo/.config/google-chrome/Default/File System/000/t/00/00000000: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, Nullsoft Installer self-extracting archive

So this file is really a windows executable!

Any ideas how this file end up in my google chrome config files and what to do with it?

Best regards, André

3 Answers

answered 2014-11-17 16:51:52 -0500

phobos13 gravatar image

Found Adware belongs to HTML5 enabled storage of google chrome. I see...

Do you have references to share?

randomuser gravatar imagerandomuser ( 2014-11-17 18:05:23 -0500 )edit

I found this and removed the site data as described here.

phobos13 gravatar imagephobos13 ( 2014-11-18 05:01:21 -0500 )edit

Ah, it's cached content from a webpage you visited, ok.

randomuser gravatar imagerandomuser ( 2014-11-18 23:40:59 -0500 )edit

answered 2014-11-17 11:46:28 -0500

pnadk gravatar image

Without Wine it might not be able to do much damage to your system since it is a Windows executable but since it is malware you should remove it. If you google the name you will find hints to how you might have gotten it.

I can't find any hint to how I might have gotten it. Did you?

phobos13 gravatar imagephobos13 ( 2014-11-17 12:09:25 -0500 )edit

answered 2017-02-06 06:42:23 -0500

updated 2017-02-07 02:30:19 -0500

