I have a HP laptop running Vista and recently received an alert that the Trojan JS/iFrame.JY.2 was found.
Using Avira, it was removed.
A couple hours later I received the same alert and again removed it when i enter my website
It did this a few more times before it stopped finding the trojan alert.
But since that time the computer run very, very, slowly.
The are also a few programs that I tried to uninstall that I had difficulty removing.
I'm not sure any of these have been removed
I think I'm infected.
Thank you in advance for any help or suggestions you may offer.
Rui Silva
Lets run a few scans and see whats going on
Download
aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Download
DDS from one of the links below to your desktop
Link 1
Link 2
Double click the tool to run it.A black Screen will open, just read the contents and do nothing. When the tool finishes, it will open 2 reports, DDS.txt and attach.txt Copy/Paste the contents of 'DDS.txt' into your post. 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Here is my log file.
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-01 09:49:07
—————————–
09:49:07.463 OS Version: Windows 6.0.6002 Service Pack 2
09:49:07.463 Number of processors: 2 586 0x1706
09:49:07.463 ComputerName: RUISILVA-NOVO UserName: Rui Silva
09:49:09.585 Initialize success
09:49:13.287 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
09:49:13.287 Disk 0 Vendor: WDC_WD32 12.0 Size: 305245MB BusType: 3
09:49:13.334 Disk 0 MBR read successfully
09:49:13.334 Disk 0 MBR scan
09:49:13.334 Disk 0 unknown MBR code
09:49:13.334 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 297151 MB offset 63
09:49:13.365 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 8090 MB offset 608567296
09:49:13.365 Disk 0 scanning sectors +625135616
09:49:13.443 Disk 0 scanning C:\Windows\system32\drivers
09:50:20.578 Service scanning
09:51:30.683 Modules scanning
09:52:00.485 Disk 0 trace - called modules:
09:52:00.515 ntkrnlpa.exe CLASSPNP.SYS disk.sys hpdskflt.sys hal.dll iaStor.sys
09:52:00.518 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89292ac8]
09:52:00.522 3 CLASSPNP.SYS[807d58b3] -> nt!IofCallDriver -> [0x88cd7340]
09:52:00.526 5 hpdskflt.sys[8d9b6f92] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x88194028]
09:52:00.530 Scan finished successfully
09:52:11.938 Disk 0 MBR has been saved successfully to "C:\Users\Rui Silva\Desktop\MBR.dat"
09:52:11.948 The log file has been saved successfully to "C:\Users\Rui Silva\Desktop\aswMBR.txt"
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.19272 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 9:58:58 on 2012-08-01
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.sapo.pt/
uSearch Page =
uWindow Title = Windows Internet Explorer disponibilizado por MSN and Bing
uSearch Bar =
mStart Page = hxxp://www.bigseekpro.com/bsprpc/{F53B940D-7FD5-4985-9805-2246B45281C0}
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=pt_pt&c=83&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
uURLSearchHooks: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTor.dll
mURLSearchHooks: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTor.dll
BHO: {043c5167-00bb-4324-af7e-62013faedacf} - vShare Toolbar
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
BHO: IEExtension.VDownloaderBHO: {7b523e7c-f096-4e36-a0cb-7efeb5c675c1} - mscoree.dll
BHO: ZoneAlarm Security Engine Registrar: {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~3\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTor.dll
TB: vShare Toolbar: {043c5167-00bb-4324-af7e-62013faedacf} -
TB: ZoneAlarm Security Engine: {ee2ac4e5-b0b0-4ec6-88a9-bca1a32ab107} - c:\program files\checkpoint\zaforcefield\trustchecker\bin\TrustCheckerIEPlugin.dll
TB: uTorrentBar_PT Toolbar: {e0301295-ab3e-4af3-979f-3d453c5f9f48} - c:\program files\utorrentbar_pt\prxtbuTor.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
TB: {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [F.lux] "c:\users\rui silva\local settings\apps\f.lux\flux.exe" /noshow
uRun: []
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
mRun: [WirelessAssistant] c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [SysTrayApp] c:\program files\idt\wdm\sttray.exe
mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden"
mRun: [ZoneAlarm] "c:\program files\checkpoint\zonealarm\zatray.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [Realtime Audio Engine] "mmrtkrnl.exe" /i
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: EnableLinkedConnections = 1 (0x1)
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&nviar para o OneNote - c:\progra~1\micros~3\office14\ONBttnIE.dll/105
IE: E&xportar para o Microsoft Excel - c:\progra~1\micros~3\office14\EXCEL.EXE/3000
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
DPF: {59E937ED-AC7E-407D-B40B-6545B1EECDE7} - hxxp://www.weareautobots.com/pt/plugin/DFusionWeb.Installer.exe
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Bejeweled%202/Images/armhelper.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldpt-br.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{67472128-9B47-4B69-A758-796FBF5B1927} : DhcpNameServer = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
STS: MsasperiDsk: {30abd9ec-b010-4fa8-a71c-2310d47b72d2} - MsasperiDsk.Msasperi
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~3\office14\GROOVEEX.DLL
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\rui silva\appdata\roaming\mozilla\firefox\profiles\b7tsxc42.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Web Search…
FF - prefs.js: browser.startup.homepage - hxxp://www.sapo.pt
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&q=
FF - plugin: c:\progra~1\common~1\nero\browse~1\npBrowserPlugin.dll
FF - plugin: c:\progra~1\micros~3\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~3\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\acrobat 10.0\acrobat\air\nppdf32.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\microsoft\web platform installer\NPWPIDetector.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nprpplugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\nptidfusionplugin.dll
FF - plugin: c:\program files\real\realplayer\netscape6\nprpplugin.dll
FF - plugin: c:\program files\vdownloader\addons\npVDownloader.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\users\rui silva\appdata\local\facebook\video\skype\npFacebookVideoCalling.dll
FF - plugin: c:\users\rui silva\appdata\local\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\users\rui silva\appdata\roaming\mozilla\firefox\profiles\b7tsxc42.default\extensions\{e0301295-ab3e-4af3-979f-3d453c5f9f48}\plugins\np-mswmp.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-07-31 23:52:06 6891424 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{14774acf-d3a9-4370-9705-ccb6b36cbd55}\mpengine.dll
2012-07-30 23:02:55 ——– d—–w- c:\users\rui silva\appdata\local\{52857263-9F9D-48BE-933E-115CAA9E4671}
2012-07-30 23:02:22 ——– d—–w- c:\users\rui silva\appdata\local\{2D9DFD33-BB46-42DD-83D9-2F8F48F37822}
2012-07-28 18:09:35 ——– d—–w- c:\program files\Conduit
2012-07-28 18:09:34 ——– d—–w- c:\users\rui silva\appdata\local\Conduit
2012-07-28 18:09:33 ——– d—–w- c:\program files\uTorrentBar_PT
2012-07-26 13:55:21 ——– d—–w- c:\program files\GridinSoft Trojan Killer
2012-07-26 13:54:35 ——– d—–w- c:\programdata\Simply Super Software
2012-07-26 13:31:54 ——– d—–w- c:\users\rui silva\appdata\local\{7EFAD344-CEE1-4165-867C-E277FEB4F2A1}
2012-07-26 13:31:44 ——– d—–w- c:\users\rui silva\appdata\local\{6FCA9B3E-211C-4316-A2B8-169968F35203}
2012-07-26 13:28:15 39272 —-a-w- c:\windows\system32\drivers\fssfltr.sys
2012-07-26 13:20:47 15712 —-a-w- c:\program files\common files\windows live\.cache\780f31311cd6b3103\MeshBetaRemover.exe
2012-07-26 13:20:46 89944 —-a-w- c:\program files\common files\windows live\.cache\77a39e211cd6b3102\DSETUP.dll
2012-07-26 13:20:46 537432 —-a-w- c:\program files\common files\windows live\.cache\77a39e211cd6b3102\DXSETUP.exe
2012-07-26 13:20:46 1801048 —-a-w- c:\program files\common files\windows live\.cache\77a39e211cd6b3102\dsetup32.dll
2012-07-26 13:19:09 ——– d—–w- c:\users\rui silva\appdata\local\{1CE49693-1BF0-4495-9FA8-ADE2A0FB92CA}
2012-07-26 13:18:39 ——– d—–w- c:\users\rui silva\appdata\local\{45B91F7F-67D5-4BD7-B109-C15B5BC4F053}
2012-07-25 10:46:53 ——– d—–w- C:\P_ESPEC_TOM_JERRY1_17_SCN
2012-07-25 08:25:23 ——– d—–w- c:\program files\ESET
2012-07-24 13:04:09 22344 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-07-24 13:04:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-07-20 21:34:35 ——– d—–w- c:\program files\FairBot
2012-07-20 11:11:58 ——– d—–w- c:\program files\common files\xing shared
2012-07-20 11:11:25 129176 —-a-w- c:\program files\mozilla firefox\plugins\nprpplugin.dll
2012-07-16 13:13:46 151552 —-a-w- c:\windows\KMSEmulator.exe
2012-07-16 13:13:29 ——– d—–w- c:\windows\AutoKMS
2012-07-11 22:55:59 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-07-11 12:48:03 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll
2012-07-11 12:47:59 1401856 —-a-w- c:\windows\system32\msxml6.dll
2012-07-11 12:47:59 1248768 —-a-w- c:\windows\system32\msxml3.dll
2012-07-11 12:47:21 440704 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2012-07-11 12:47:21 278528 —-a-w- c:\windows\system32\schannel.dll
2012-07-11 12:47:21 204288 —-a-w- c:\windows\system32\ncrypt.dll
2012-07-02 11:49:41 ——– d—–w- c:\users\rui silva\appdata\roaming\AlcaTech
2012-07-02 11:49:29 102400 —-a-w- c:\windows\system32\Setup.dll
2012-07-02 11:49:22 ——– d—–w- c:\programdata\AlcaTech
.
==================== Find3M ====================
.
2012-07-20 11:11:12 348160 —-a-w- c:\windows\system32\msvcr71.dll
2012-06-02 22:12:32 2422272 —-a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:12:13 88576 —-a-w- c:\windows\system32\wudriver.dll
2012-06-02 14:19:42 171904 —-a-w- c:\windows\system32\wuwebv.dll
2012-06-02 14:12:20 33792 —-a-w- c:\windows\system32\wuapp.exe
2012-05-31 11:25:14 237072 ——w- c:\windows\system32\MpSigStub.exe
2012-05-18 07:23:27 32655688 —-a-w- c:\users\rui silva\FastDraw_Basketball_windows_4_1_0.exe
2012-05-15 06:37:49 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-15 06:32:25 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-15 06:32:00 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2012-05-15 06:31:44 109056 —-a-w- c:\windows\system32\iesysprep.dll
2012-05-15 06:31:43 71680 —-a-w- c:\windows\system32\iesetup.dll
2012-05-15 05:01:56 385024 —-a-w- c:\windows\system32\html.iec
2012-05-15 03:26:05 133632 —-a-w- c:\windows\system32\ieUnatt.exe
2012-05-15 03:23:41 1638912 —-a-w- c:\windows\system32\mshtml.tlb
2010-01-26 10:11:08 444283 —-a-w- c:\program files\common files\WinPcapNmap.exe
2008-02-05 23:44:56 200704 —-a-w- c:\program files\BorisFXUI.fex
.
============= FINISH: 10:00:41,82 ===============
I cant attach zip files.
Here is txt. file
Hi,
You most likely picked up infections using File Sharing, your downloading that file from an unknown source and most contain malware or some sort or another, you need to uninstall uTorrent and stay away from any file sharing, its like playing Russian Roulette malwarewise.
One of your entries is related to a password stealing trojan, you need to access a known clean computer and change all your passwords for sites you frequent especially if you do online shopping with a credit card or any banking.
You have Malwarebytes installed, open it, go to the update tab and check for updates and then run a FULL scan and post the log please
Then run this free online virus scanner
ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan Click the [external image: Posted Image] button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop. Double click on the [external image: Posted Image] icon on your desktop. Check [external image: Posted Image] Click the [external image: Posted Image] button. Accept any security warnings from your browser. Check [external image: Posted Image] Make sure that the option "Remove found threats" is Unchecked Push the Start button. ESET will then download updates for itself, install itself, and begin
scanning your computer. Please be patient as this can take some time. When the scan completes, push [external image: Posted Image] Push [external image: Posted Image] , and save the file to your desktop using a unique name, such as
ESETScan. Include the contents of this report in your next reply. Push the [external image: Posted Image] button. Push [external image: Posted Image] Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
Malewarebyte file.
Malwarebytes Anti-Malware (Período de Avaliação) 1.62.0.1300
www.malwarebytes.org
Versão da base de dados: v2012.08.03.06
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19272
Rui Silva :: RUISILVA-NOVO [administrador]
Protecção: Desactivada
03-08-2012 18:20:31
mbam-log-2012-08-04 (09-23-35).txt
Tipo de pesquisa: Completa (C:\|D:\|)
Opções de pesquisa activadas: Memoria | Arranque | Registo | Sistema de Ficheiros | Heurísticos/Extra | Heurísticos/Shuriken | PPI | MPI
Opções de pesquisa desactivadas: P2P
Objectos verificados: 696902
Tempo decorrido: 9 hora(s), 30 minuto(s), 27 segundo(s)
Processos de memória Detectados: 0
(Nenhum item malicioso detectado)
Módulos de Memória Detectados: 0
(Nenhum item malicioso detectado)
Chaves do Registo Detectadas: 0
(Nenhum item malicioso detectado)
Valores do Registo Detectados: 0
(Nenhum item malicioso detectado)
Itens de dados do Registo Detectados: 0
(Nenhum item malicioso detectado)
Pastas Detectadas: 0
(Nenhum item malicioso detectado)
Ficheiros Detectados: 1
C:\PC Rui Silva\Basquetebol\Maia Basket Clube\2011_2012\Joomla 1.5\php-5.3.6\ext\standard\tests\file\windows_acls\tiny.exe (RiskWare.TinyPE.gen) -> Nenhuma acção tomada.
(fim)
Hi,
Just copy and paste the logs and reports we ask for into the thread and please do not attach them unless otherwise asked.
Help me out here, I dont speak portuguese
Nenhuma acção tomada. <–Does this mean no action taken, you need to rerun Malwarebytes and let it remove it
Lets see what ESET finds
C:\Windows\KMSEmulator.exe a variant of Win32/HackKMS.A application
C:\Windows\AutoKMS\AutoKMS.exe a variant of Win32/HackKMS.B application
Lets try running this scanner
Download
CKScanner by
askey127 from
Here &
save it to your Desktop .
Doubleclick CKScanner.exe then click Search For Files When the cursor hourglass disappears, click Save List To File A message box will verify the file saved Please Run this program only once Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Malwarebytes Anti-Malware (Período de Avaliação) 1.62.0.1300
www.malwarebytes.org
Versão da base de dados: v2012.08.03.08
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19272
Rui Silva :: RUISILVA-NOVO [administrador]
Protecção: Desactivada
04-08-2012 18:09:40
mbam-log-2012-08-04 (18-09-40).txt
Tipo de pesquisa: Completa (C:\|D:\|)
Opções de pesquisa activadas: Memoria | Arranque | Registo | Sistema de Ficheiros | Heurísticos/Extra | Heurísticos/Shuriken | PPI | MPI
Opções de pesquisa desactivadas: P2P
Objectos verificados: 697139
Tempo decorrido: 4 hora(s), 28 minuto(s), 45 segundo(s)
Processos de memória Detectados: 0
(Nenhum item malicioso detectado)
Módulos de Memória Detectados: 0
(Nenhum item malicioso detectado)
Chaves do Registo Detectadas: 0
(Nenhum item malicioso detectado)
Valores do Registo Detectados: 0
(Nenhum item malicioso detectado)
Itens de dados do Registo Detectados: 0
(Nenhum item malicioso detectado)
Pastas Detectadas: 0
(Nenhum item malicioso detectado)
Ficheiros Detectados: 0
(Nenhum item malicioso detectado)
(fim)
CKScanner - Additional Security Risks - These are not necessarily bad
c:\pc rui silva\nokia\n81\psiloc.irremote.v1.03.s60v3.symbianos9.1\bin-6001\drm.common.solutions.v3.11.crack.sis
c:\pc rui silva\nokia\n81\psiloc.irremote.v1.03.s60v3.symbianos9.1\bin-6001\psiloc.irremote.v1.03.s60v3.symbianos9.1.unsigned.cracked-binpda.sis
c:\program files\adobe\adobe dreamweaver cs5.5\configuration\taglibraries\html\keygen.vtm
c:\program files\adobe\adobe flash catalyst cs5.5\plugins\com.adobe.thermo.core_1.5.0.308731\com\adobe\thermo\undo\thermoundosystem$undoabledocumentchangecracker.class
c:\program files\jdownloader\jd\plugins\hoster\crackedcom.class
c:\program files\pinnacle\studio 11\plugins\rtfx\studioxml\rtfx volume 2\crackedslab-gpu.xml
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack1 h.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack1 v.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack2 h.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack2 v.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack3 h.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack3 v.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack4 d.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack4 h.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack5 d.spg
c:\program files\pinnacle\studio 15\pixelan\creativease\spices\400 extra spices pack\split\sp crack6 d.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\saved settings\cutting edge\crackstretch1.smf
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack1 h.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack1 v.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack2 h.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack2 v.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack3 h.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack3 v.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack4 d.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack4 h.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack5 d.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\spices\spices\split\sp crack6 d.spg
c:\program files\pinnacle\studio 15\pixelan\spicemaster 2.5\system\cutting edge\crackstretch1.smf
c:\program files\pinnacle\studio 15\plugins\rtfx\3dserver\filtersplus3d\crackedslab3d.xml
c:\program files\pinnacle\studio 15\plugins\rtfx\hfxxml\crackers.xml
c:\program files\pinnacle\studio 15\plugins\rtfx\hfxxml\firecracker.xml
c:\program files\pinnacle\studio 15\plugins\rtfx\studioxml\rtfx volume 2\crackedslab-gpu.xml
c:\program files\registry winner\utilities\favorites\hacker msn hotmail hacker2009 stolen msn hotmail cracker20099 msn.url
c:\program files\registry winner\utilities\favorites\warez\allseek.info the ultimate cracks search engine.url
c:\program files\registry winner\utilities\favorites\warez\any cracks for any time cracks,serials,keygen,patches archive.url
c:\program files\registry winner\utilities\favorites\warez\any cracks for any time crackz, serials, keygen, patch archives.url
c:\users\rui silva\favorites\hacker msn hotmail hacker2009 stolen msn hotmail cracker20099 msn.url
c:\users\rui silva\favorites\warez\allseek.info the ultimate cracks search engine.url
c:\users\rui silva\favorites\warez\any cracks for any time cracks,serials,keygen,patches archive.url
c:\users\rui silva\favorites\warez\any cracks for any time crackz, serials, keygen, patch archives.url
scanner sequence 3.ZZ.11.NSNATA
—– EOF —–
Let me explain how you infected your system. You downloaded and installed illegal software, this software is basically stolen. You also have a program on your system to hack into MSN Hotmail to steal passwords. Not 25%, or 50% or 75% , but 100% of illegal cracked / warez / keygens downloaded programs are infected. This forum as well as all the other malware removal forums do not support the use of illegal stolen software except for there removal. If I was to continue to help you it could be construed in the eyes of the law as aiding and abetting a crime. We sometimes ask people if they want to continue with the cleaning to uninstall all the illegal stuff but looking at the Hotmail Password cracker sealed the deal on closing this thread. No more help will be offered.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html
and start a New Topic.