hii guys….since last few hours my laptop is acting funny…everytime i open any browser it automatically opens a pop up ( singles in your area/porn ) n its a same pop up everytime…
LINK REMOVED
that made me run malwarebytes…n it shows one file found which is trojan.dropper.bcminer….i removed it but it keeps coming back n pop doesnt stop…i close it comes back after 5-10 mins…i read few stuff about this trojan type n it looks bad…please help me out if you can..thanks..
here are the OTL reports..
My name is Satchfan and I would be glad to help you with your computer problem.
Please read the following guidelines which will help to make cleaning your machine easier:
please follow all instructions in the order posted
please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
if you don't understand something, please don't hesitate to ask for clarification before proceeding
the fixes are specific to your problem and should only be used for this issue on this machine.
please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
P2P - I see you have P2P software, (BitTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.
Should you decide to keep it, please don’t use it until we have finished up here.
copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL
:Services
:OTL
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\windows._cacheinvalidation.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._gdi_.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pysqlite2._sqlite.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32com.shell.shell.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pyexpat.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32api.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_elementtree.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_ctypes.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._html2.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_socket.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32crypt.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._core_.pyd () – supposed to be \_MEI34842\wx._core_.pyd- http://systemexplorer.net/filereviews.php?fid=11587646 – can be anything as another was MEI21082
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._controls_.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._windows_.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._misc_.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_ssl.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\unicodedata.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\pythoncom26.dll ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\_hashlib.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\wx._wizard.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32file.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\PyWinTypes26.dll ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32inet.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32process.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32pdh.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\win32event.pyd ()
MOD - C:\Users\Owner\AppData\Local\Temp\_MEI35242\select.pyd ()
MOD - \\?\globalroot\systemroot\syswow64\mswsock.DLL ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
O3 - HKLM\..\Toolbar: (no name) - {b278d9f8-0fa9-465e-9938-0c392605d8e3} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30CEEEA2-3742-40E4-85DD-812BF1CBB83D} - No CLSID value found.
O4:[b]64bit:[/b] - HKLM..\Run: [] File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:[b]64bit:[/b] - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O16:[b]64bit:[/b] - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab (Reg Error: Key error.)
:Commands
[purity]
[Reboot]
click the Run Fix button at the top
let the program run unhindered, reboot when it is done
post a new OTL log (don't check the boxes beside LOP Check or Purity this time)
only if Malicious objects are found then ensure Cure is selected. Do not change it to Delete or Quarantine as it may delete infected files that are required for Windows to operate properly.
click Continue > Reboot now
copy and paste the log in your next reply
a copy of the log will be saved automatically to the root of the drive (typically C:\) called TDSSKiller_***(*** denotes version & date)
Download Combofix from either of the links below, and save it to your desktop.
Link 1 Link 2
**Note: It MUSTbe saved directly to your desktop. Choose save as and then make sure you choose Desktop
——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–
Double click on ComboFix.exe & follow the prompts.
when finished, it will produce a report for you.
please post the C:\ComboFix.txt for further review.
thanks for your help..
foe tddskiller..found one treat..but as you said to cure..none of that option came..all i had to pick from is skip..delete or quar…so i skip..it said treat was locked..anyways report is here for all 3..
i went to c driven \otl to get this log..as nothing has opened like last time..let me know if any changes needs to be made..thanks..
foe tddskiller..found one treat..but as you said to cure..none of that option came..all i had to pick from is skip..delete or quar…so i skip..it said treat was locked..anyways report is here for all 3..
i went to c driven \otl to get this log..as nothing has opened like last time..let me know if any changes needs to be made..thanks..
hey the file you wanted me to find on virus total…doesnt exist when i went ahead n did windows/system32/drivers…
here the report from cks
CKScanner - Additional Security Risks - These are not necessarily bad
c:\qoobox\quarantine\c\users\owner\microsoft office 2007 keygen –coded by melinda–.exe.vir
scanner sequence 3.NA.11.TKAPJH
—– EOF —–
hey here is the report after the last combofix scan…
in terms of my laptop…since this morning i havent seen that auto pop up coming up….so i guess its a good thing…
let me know what needs to be done if any after you see the report…
I noticed that you had MBAM on your system: if you no longer have it, you can download it from here:
start Malwarebytes-Anti-Malware and update it, (“Update” tab}
once it is updated, click on “Scanner” tab, select Perform quick scan, then click Scan.
when the scan is complete, click OK, then Show Results to view the results.
be sure that everything is checked, and click Remove Selected.
when removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
the log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
copy and paste the contents of that report in your next reply and exit MBAM.
NOTE: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Hi ankitt. You've done good but although it all seems OK, I'd like another scan.
Run ESET Online Scan
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan 1. Click the Eset online Scanner button.
2. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
• Click on esetinstaller.exe to download the ESET Smart Installer. Save it to your desktop.
• Double click on the Eset installer icon on your desktop.
3. Check Yes, I accept the Terms of Use
4. Click the Start button.
5. Accept any security warnings from your browser.
6. Check Scan archives
7. Push the Start button.
8. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
9. When the scan completes, push List of found threats
10. Push Export to Text file and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. Note - when ESET doesn't find any threats, no report will be created.
11. Push the back button.
12. Push Finish
If a log has been produced post it in your next reply.
NOTE. If Eset doesn't find any threats, it won't produce a log.
Satchfan
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI