Bitcoin Forum
June 15, 2024, 04:13:34 AM *
News: Voting for pizza day contest
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: HELP please. Infected pc.  (Read 451 times)
slavo (OP)
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
January 04, 2014, 06:44:13 AM
 #1

Hi everyone.

3 days ago I was trapped here like a noob by a post about pts gpu miner. I downloaded it; and now I'm infected.

I have a process running (a fake jhproto process i assume) which can't be killed without killing the session and make the pc hard reboot.

I made a malwarebyte and antivirus scan without success.

I have disconnected that pc since I installed this shit. I would like to avoid reinstalling the 40000000 wallets on it so if it could be cleared without reinstalling that'd be great.

Could someone help me with this ? Thanks.

Slavo
Snard
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
January 04, 2014, 06:51:58 AM
 #2

I played with that. It was an autoit script. If I remember correctly this was installed in %appdata% but could be wrong.

Go visit the people at http://www.bleepingcomputer.com. They rock and can help you with this easily.
slavo (OP)
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
January 04, 2014, 06:57:46 AM
 #3

Yes that's an autoit.

I'll check bleepingcomputer thanks.
PyroTekNeks
Member
**
Offline Offline

Activity: 70
Merit: 10


View Profile
January 04, 2014, 07:01:12 AM
 #4

Check your /appdata or your /temp files. Look for anything weird. Does it show on your process explorer?

http://scrypt.cc?ref=baaai
^^^SCRYPT CLOUD MINING SITE!!!^^^
slavo (OP)
Hero Member
*****
Offline Offline

Activity: 784
Merit: 500



View Profile
January 05, 2014, 09:13:48 AM
 #5

yes it's on the process explorer, but i have a bsod if i try to close it
Snard
Full Member
***
Offline Offline

Activity: 140
Merit: 100


View Profile
January 05, 2014, 02:58:55 PM
 #6

Find its path from procexp. Reboot into safe mode with networking. Rename the folder. Reboot
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!