Jump to content

Trojan/Malware get in my computer through cmd. It's automatically send messenger from Discord, Steam Friendlist to my friends.


Recommended Posts

Posted

Someday when i was downloading an audio file from y2mate . com (the website which when you paste youtube link into it, you can download mp4, mp3...from that youtube video). 

Then i got a captcha that request 3 steps:
1 - Run cmd on my computer

2- Copy and paste the text from the captcha to cmd window

3- Enter

I didn't know what is it. though it was captcha test. 

And then i got problem. I remember some text like "PowerShell..."

The virus automatically send link (virus inside website ask victim login). The link is fake to steamcommunity website.

Please help me get out of it. image.thumb.png.b7a615f8e8e06ed4f742b589695f307d.png

harlan4096
Posted

Welcome to Kaspersky Community.

 

Do you have K. product installed?

 

Since that site it is detected here:

 

image.png.cce508c1bec9b3a40886bb8f4467041f.png

  • Like 1
Posted
6 minutes ago, harlan4096 said:

Welcome to Kaspersky Community.

 

Do you have K. product installed?

 

Since that site it is detected here:

 

image.png.cce508c1bec9b3a40886bb8f4467041f.png

Hi Harlan, i get K standard and begin scanning, 2 trojan of them was killed after. Now, im still waiting for the result at allimage.png.a0c48a15335607481b323be85eb4889f.png

  • Like 1
Posted

I did scanning all computer yesterday. Though it's been cleaned. But today, it appear again by automatically sending virus link on steam chat. Really need help now. Thank you

image.thumb.png.ff010ee672ab70114678df4c41098469.png

Posted

Here it is

Quote

 

# -------------------------------
# Malwarebytes AdwCleaner 8.4.2.0
# -------------------------------
# Build:    03-04-2024
# Database: 2024-03-04.1 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    09-06-2024
# Duration: 00:00:14
# OS:       Windows 10 (Build 19045.4780)
# Scanned:  32053
# Detected: 19


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.DriveTheLife       C:\ProgramData\DRIVERTALENT
PUP.Optional.DriveTheLife       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DRIVER TALENT
PUP.Optional.DriveTheLife       C:\Users\DANG HUYNH PHAT\AppData\Roaming\DRIVERTALENT
PUP.Optional.DriverTalent       C:\Program Files (x86)\OSTotoSoft
PUP.Optional.Legacy             C:\Users\DANG HUYNH PHAT\AppData\Roaming\Hola

***** [ Files ] *****

PUP.Optional.CosmosSystemCare   C:\ProgramData\Microsoft\Windows\Start Menu\Cosmos.lnk
PUP.Optional.CosmosSystemCare   C:\Users\DANG HUYNH PHAT\Desktop\Cosmos.lnk
PUP.Optional.GoodGame           C:\Users\DANG HUYNH PHAT\Desktop\GOODGAME EMPIRE.URL

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.DriveTheLife       HKLM\Software\Wow6432Node\\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|DRIVERTALENT.EXE
PUP.Optional.DriveTheLife       HKLM\System\Setup\FirstBoot\Services\LDRVSVC
PUP.Optional.DriverTalent       HKCU\Software\OSTotoSoft
PUP.Optional.DriverTalent       HKLM\Software\Wow6432Node\OSTotoSoft
PUP.Optional.Legacy             HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
PUP.Optional.Legacy             HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\browser.exe
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Active Setup\Installed Components\{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\MediaPlayer\ShimInclusionList\browser.exe
PUP.Optional.SpeedBrowser       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\browser.exe
PUP.Optional.SpeedBrowser       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\App Paths\browser.exe

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

PUP.Optional.Legacy             Conduit Search

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

 

 

harlan4096
Posted

Delete all those registry keys, also try to find in Your full system these 2 exe files:

 

DRIVERTALENT.EXE

browser.exe

  • Like 1
Posted

Not that one. I installed it (cracked) for scanning missing driver long time ago. That is not the way that i killed some cracked software on my computer, the problem still there from 2 days ago after i command it (text with trojan/malware) to cmd like i said. 

Kaspersky's seem to being not worked after i've scanned yesterday. Please help

harlan4096
Posted

Did You have Kaspersky installed when You did that steps in Your 1st posts? because Kaspersky detects all those malicious sites, so, or You did not have K. installed, or You ignored the warnings 🙄

 

What versions of Kaspersky do You installed now?

  • Like 1
Posted (edited)

Not yet at that post. But after your 1st commend, i did scanning and kill some trojan/malware from Disk C, not include some software that i've known it safe. But now the trojan is still alive

 

You please take a look at this log

image.thumb.png.4cb670e21a04c139ed9973b0da581af6.png

I got standard K for personal/home for 1 PC a year version.

 

Edited by Clouding
Posted

I got some problem which not be fixed in Drive C\Windows\Installer\"name".msi

image.thumb.png.091ce6b02be1b1f7b0bed7af9aa42019.png

harlan4096
Posted

I can't understand anything in that captures, please change into English Your K. (being with main application window open) pressing SHIFT + F12, and upload again the detection captures.

 

Also, go to Microsoft Store, find Sysinternals Suite, and install it.

 

Find tool AutoRuns, once executed as Administrator rights, go to Options -> Scan Options, and:

 

image.png.05f3e48e17b6874eb665a67494a03b55.png

 

Go to tabs: WinLogon, Logon and Scheduled Tasks, and check if something suspicious, checking column VirusTotal.

  • Like 1
Posted

Here you are

 

image.thumb.png.648232e89479693800546d401e6a6409.png

  • Like 1
harlan4096
Posted

Not Processed does not mean any error or issue, those files were ignored probably because matching different rules: legit system files, etc.

Posted

I have an idea. Would you please using Ultraviewer and connect for take a look at my PC? I'll be glad if everything's done. 

harlan4096
Posted

This should be done by official Kaspersky Support staff: K. Support

  • Like 1
Posted

Im getting insane with this virus problem. Hope it's been fixed soon

otherwise, this is from autoruns

image.thumb.png.c8caaf8feb364236f3bbe58f9fde8ee1.png

  • Like 1
harlan4096
Posted

What about the other 2 tabs?

harlan4096
Posted

Also, open Windows Admin Tasks -> tab StartUp, check what's enabled there.

Posted

Everything's ok in startup. Today, the virus make my discord logging out. Maybe it wants me relogging in by typing password, but i scan QR from my phone. image.thumb.png.27a83f7319be17f1a1afa24d94e78d4e.png

harlan4096
Posted

Can you go to Intrusion Prevention -> Manage Applications, and show a capture of the apps located at Low, High and Untrusted groups?

Posted

Excute me, how to get there? 

 

harlan4096
Posted

Being in main K. window -> go to Security in the left -> scroll down a bit -> Intrusion Prevention -> Manage Applications

Posted

Here you are

image.thumb.png.270ece846aad1ae5cfbccace700363ba.png

  • Like 1
harlan4096
Posted

I guess that Windows Launcher (HunGame.exe) is legit 🤔?

 

Try to download this tool: https://www.kaspersky.com/downloads/free-virus-removal-tool

 

Run it, enable the 3 checkboxes -> Accept

 

Then go to Change Parameters -> Add Object, find Your C : drive and add, one by one, these 2 additional entries:

 

Quote

 

C:\ProgramData

C:\Users

 

 

It should show like this:

 

image.thumb.png.30193bf0394aa5844fdfde79fbaafae9.png

 

Then click Ok -> Start Scan

 

Send detections (if any) once ended.

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...