Skip to content
View in the app

A better way to browse. Learn more.

Kaspersky Support Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Trojan/Malware get in my computer through cmd. It's automatically send messenger from Discord, Steam Friendlist to my friends.

Someday when i was downloading an audio file from y2mate . com (the website which when you paste youtube link into it, you can download mp4, mp3...from that youtube video). 

Then i got a captcha that request 3 steps:
1 - Run cmd on my computer

2- Copy and paste the text from the captcha to cmd window

3- Enter

I didn't know what is it. though it was captcha test. 

And then i got problem. I remember some text like "PowerShell..."

The virus automatically send link (virus inside website ask victim login). The link is fake to steamcommunity website.

Please help me get out of it. image.thumb.png.b7a615f8e8e06ed4f742b589695f307d.png

Featured Replies

Welcome to Kaspersky Community.

 

Do you have K. product installed?

 

Since that site it is detected here:

 

image.png.cce508c1bec9b3a40886bb8f4467041f.png

  • Author
6 minutes ago, harlan4096 said:

Welcome to Kaspersky Community.

 

Do you have K. product installed?

 

Since that site it is detected here:

 

image.png.cce508c1bec9b3a40886bb8f4467041f.png

Hi Harlan, i get K standard and begin scanning, 2 trojan of them was killed after. Now, im still waiting for the result at allimage.png.a0c48a15335607481b323be85eb4889f.png

  • Author

I did scanning all computer yesterday. Though it's been cleaned. But today, it appear again by automatically sending virus link on steam chat. Really need help now. Thank you

image.thumb.png.ff010ee672ab70114678df4c41098469.png

  • Author

Here it is

Quote

 

# -------------------------------
# Malwarebytes AdwCleaner 8.4.2.0
# -------------------------------
# Build:    03-04-2024
# Database: 2024-03-04.1 (Cloud)
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start:    09-06-2024
# Duration: 00:00:14
# OS:       Windows 10 (Build 19045.4780)
# Scanned:  32053
# Detected: 19


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.DriveTheLife       C:\ProgramData\DRIVERTALENT
PUP.Optional.DriveTheLife       C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DRIVER TALENT
PUP.Optional.DriveTheLife       C:\Users\DANG HUYNH PHAT\AppData\Roaming\DRIVERTALENT
PUP.Optional.DriverTalent       C:\Program Files (x86)\OSTotoSoft
PUP.Optional.Legacy             C:\Users\DANG HUYNH PHAT\AppData\Roaming\Hola

***** [ Files ] *****

PUP.Optional.CosmosSystemCare   C:\ProgramData\Microsoft\Windows\Start Menu\Cosmos.lnk
PUP.Optional.CosmosSystemCare   C:\Users\DANG HUYNH PHAT\Desktop\Cosmos.lnk
PUP.Optional.GoodGame           C:\Users\DANG HUYNH PHAT\Desktop\GOODGAME EMPIRE.URL

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.DriveTheLife       HKLM\Software\Wow6432Node\\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|DRIVERTALENT.EXE
PUP.Optional.DriveTheLife       HKLM\System\Setup\FirstBoot\Services\LDRVSVC
PUP.Optional.DriverTalent       HKCU\Software\OSTotoSoft
PUP.Optional.DriverTalent       HKLM\Software\Wow6432Node\OSTotoSoft
PUP.Optional.Legacy             HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
PUP.Optional.Legacy             HKLM\SOFTWARE\Microsoft\MediaPlayer\ShimInclusionList\browser.exe
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\Active Setup\Installed Components\{7D2B3E1D-D096-4594-9D8F-A6667F12E0AC}
PUP.Optional.Legacy             HKLM\Software\Wow6432Node\\Microsoft\MediaPlayer\ShimInclusionList\browser.exe
PUP.Optional.SpeedBrowser       HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\browser.exe
PUP.Optional.SpeedBrowser       HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\App Paths\browser.exe

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

PUP.Optional.Legacy             Conduit Search

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

 

 

Delete all those registry keys, also try to find in Your full system these 2 exe files:

 

DRIVERTALENT.EXE

browser.exe

  • Author

Not that one. I installed it (cracked) for scanning missing driver long time ago. That is not the way that i killed some cracked software on my computer, the problem still there from 2 days ago after i command it (text with trojan/malware) to cmd like i said. 

Kaspersky's seem to being not worked after i've scanned yesterday. Please help

Did You have Kaspersky installed when You did that steps in Your 1st posts? because Kaspersky detects all those malicious sites, so, or You did not have K. installed, or You ignored the warnings ?

 

What versions of Kaspersky do You installed now?

  • Author

Not yet at that post. But after your 1st commend, i did scanning and kill some trojan/malware from Disk C, not include some software that i've known it safe. But now the trojan is still alive

 

You please take a look at this log

image.thumb.png.4cb670e21a04c139ed9973b0da581af6.png

I got standard K for personal/home for 1 PC a year version.

 

Edited by Clouding

  • Author

I got some problem which not be fixed in Drive C\Windows\Installer\"name".msi

image.thumb.png.091ce6b02be1b1f7b0bed7af9aa42019.png

I can't understand anything in that captures, please change into English Your K. (being with main application window open) pressing SHIFT + F12, and upload again the detection captures.

 

Also, go to Microsoft Store, find Sysinternals Suite, and install it.

 

Find tool AutoRuns, once executed as Administrator rights, go to Options -> Scan Options, and:

 

image.png.05f3e48e17b6874eb665a67494a03b55.png

 

Go to tabs: WinLogon, Logon and Scheduled Tasks, and check if something suspicious, checking column VirusTotal.

  • Author

Here you are

 

image.thumb.png.648232e89479693800546d401e6a6409.png

Not Processed does not mean any error or issue, those files were ignored probably because matching different rules: legit system files, etc.

  • Author

I have an idea. Would you please using Ultraviewer and connect for take a look at my PC? I'll be glad if everything's done. 

This should be done by official Kaspersky Support staff: K. Support

  • Author

Im getting insane with this virus problem. Hope it's been fixed soon

otherwise, this is from autoruns

image.thumb.png.c8caaf8feb364236f3bbe58f9fde8ee1.png

What about the other 2 tabs?

Also, open Windows Admin Tasks -> tab StartUp, check what's enabled there.

  • Author

Everything's ok in startup. Today, the virus make my discord logging out. Maybe it wants me relogging in by typing password, but i scan QR from my phone. image.thumb.png.27a83f7319be17f1a1afa24d94e78d4e.png

Can you go to Intrusion Prevention -> Manage Applications, and show a capture of the apps located at Low, High and Untrusted groups?

  • Author

Excute me, how to get there? 

 

Being in main K. window -> go to Security in the left -> scroll down a bit -> Intrusion Prevention -> Manage Applications

  • Author

Here you are

image.thumb.png.270ece846aad1ae5cfbccace700363ba.png

I guess that Windows Launcher (HunGame.exe) is legit ??

 

Try to download this tool: https://www.kaspersky.com/downloads/free-virus-removal-tool

 

Run it, enable the 3 checkboxes -> Accept

 

Then go to Change Parameters -> Add Object, find Your C : drive and add, one by one, these 2 additional entries:

 

Quote

 

C:\ProgramData

C:\Users

 

 

It should show like this:

 

image.thumb.png.30193bf0394aa5844fdfde79fbaafae9.png

 

Then click Ok -> Start Scan

 

Send detections (if any) once ended.

  • Author

Huntgame is my current game. Hunt Showdown. It's safe

Please sign in to comment

You will be able to leave a comment after signing in

Sign In Now

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.