• All Community
    • All Community
    • Forums
    • Ideas
    • Blogs
Advanced

Not what you are looking for? Ask the experts!

This forum thread needs a solution.
Kudos0

Report virus / trojan

* I don't speak so much english, please excuse my mistakes.

Hi,

somedays ago a girl come to my cyber to print a file, when I plug in the Flash Drive I noticed that have a virus / trojan, I don't care too much about that until next day when I start up my PC I noticed that was taking so much in load the MBR. I scan my pc with 3 distinct antivirus and no one detect the trojan, so I started to look by myself and this is what I find.

I start the 'Process Explorer' application developed by Sysinternals to find processes that might be a bit strange, and I did, I found a Windows installation process that would connect the flash memory system logs in addition to performing actions on it. After that open the msconfig and looked for any service or application that is open at system startup and I seem weird, and I did again, I find a key, and this is what he had.

The key YIOS is encoded in base64, so I decoded online with www.base64decode.org

http://pastebin.com/7JkrwEwQ

Unfortunately I do not know the language of Powershell, so I could not go further.

I think that the variable $ OCBTIZTYSZFRYUFB wqDfasZVujcjBaUU needs the function to be properly deciphered by a tour of bytes.

Greetings, I hope some help.

Replies

Kudos0

Re: Report virus / trojan

You have a virus similar to Poweliks.  If you have a full time antivirus do a full system scan with that.  You can try Norton Power Eraser ( available here ; please read the notice and instructions carefully ).  There is also instructions on manually removing Poweliks available here.  Otherwise, please visit a Virus / Spyware Removal Forum in your language / area for removal support.

Win10 x64; Proud graduate of GeeksToGo
Kudos0

Re: Report virus / trojan

Hello

Here is a list of free malware removal sites. Pick one and stay with them until they say your computer is clean.

Please see this link for an up to date description of these sites plus the addition of a newly listed site formed by one of our successful malware remover users. The new site is listed first in this link.

https://community.norton.com/en/forums/malware-removal-forum-recommendations

Thanks.




 

Success always occurs in private and failure in full view. Windows 10 Pro 64 bit Norton Core Security Plus 22.17.3.50 Core Firmware 282 I E 11 Chrome latest version.
Kudos0

Re: Report virus / trojan

I had to deny that postimage site four times,sheesh
Kudos0

Re: Report virus / trojan

Good afternoon,

Really I appreciate your answers, I delete this manually cause no antivirus detect it, I will scan again with the tools you say to me.

Thanks.

This thread is closed from further comment. Please visit the forum to start a new thread.