Solved "Virus" - GET ALL PASSWORDS

Kathy

New member
Local time
2:16 AM
Messages
33
Location
Israel
Hello all
I got OS: Windows 7 Ultimate

Everytime i start-up my laptop appears an icon on the desktop named "GET ALL PASSWORDS" , and it an "exe" format.

I dunno if its a virus but i guess yes, I scanned it and there're no problems in there.
I scanned with AVG , Malwarebytes.

I checked the Startup Items, there's no strange services
I looked
I did all the things that i should do, and nothing helps.


Help me please.
 

Attachments

  • Gap.jpg
    Gap.jpg
    120.8 KB · Views: 70

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
Baby please don't click.......:shock:

try to locate before in your Program Files/ Program Files (x86) but don't even think double clicking!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
Baby please don't click.......:shock:

try to locate before in your Program Files/ Program Files (x86) but don't even think double clicking!

I wont click, I scanned all the computer and didn't find any errors or viruses ;S :( :(
Help please,
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
Oh :O Dangerous :(
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps

My Computer

Computer Manufacturer/Model Number
HP m8000n
OS
Windows 7 Ultimate x86
CPU
DualCore AMD Athlon 64 X2, 2600 MHz 5200+
Motherboard
Asus M2N68-LA (Narra)
Memory
Samsung 2GB DDR2
Graphics Card(s)
Onboard NVIDIA GeForce 6150SE nForce 430
Sound Card
Onboard nVIDIA nForce 6100-430 (MCP61P)
Monitor(s) Displays
Westinghouse 19" LED
Screen Resolution
1280x1024
Hard Drives
SATA II Seagate Barracuda 500GB
USB II WD Elements 500GB
USB II WD My Book 1TB
USB II WD My Book 2TB
PSU
Stock (HP)
Case
Stock (HP)
Cooling
Stock
Keyboard
Logitech Classic KB 200
Mouse
Standard HP opticle USB mouse
Oh :O Dangerous :(

Maybe not so (if you don't use it), but you better double check in "Program & Features" if there's an uninstaller there....
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
Upload that file to virustotal.
 

My Computer

Computer Manufacturer/Model Number
HCL
OS
Winbdows 7 ultimate x64 | Ubuntu 12.04 x64 LTS
CPU
Core 2 Duo e7400 @ 2.90GHz
Motherboard
Gigabyte G31M-ES2L
Memory
3GB DDR2
Graphics Card(s)
Asus Nvidia GTX 560Ti 1GB
Sound Card
On-board
Monitor(s) Displays
HCL eZeeBee 18.5" LCD
Screen Resolution
1366x768 @ 60Hz
Hard Drives
Western Digital 320GB
PSU
Corsair CX500 V2 500W
Cooling
Stock
Keyboard
Stock
Mouse
Stock
Internet Speed
15-25kBps D/L | 10kBps U/L | Hey Don't laugh
just to be safe id check your processes and services, and see if anything fishy named like it is running. It doesn't look like you installed it though, it just looks downloaded.
 

My Computer

OS
Windows 7 pro 64 bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz
Motherboard
MSI P55-GD80 LGA 1156
Memory
Gskill 8 gig, 4x2gig
Graphics Card(s)
ASUS EAH5850
Sound Card
built in HD
Monitor(s) Displays
HP 23 inch
Hard Drives
1tbHDD,500HDD,500HDD,30SSD no RAID...
Case
Cooler master HAF 932
Cooling
4 case fans, v6 cpu cooler
Keyboard
Logitech G110
Mouse
Razer Death Adder
Internet Speed
never fast enough
SledgeDG, I prefer not to delete it this way .. cause i tried this before and it cames back everytime :)
NoN, Thank you for supporting
EzioAuditore, I did .. what the next step?
bmcdevitt, I can attach my process, but the services it's too long list.. to attach it in jpeg images?
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
Hi Kathy,

Firstly, you did exactly the right thing by not clicking it - the first step to good security is awareness.

Can you tell us a bit about this laptop please? Acer? Gateway? Has that password thing always been there since you bought it?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Oh, it been removed now... suddenly i can't see it on desktop :S
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
Go in start menu then click run and type, msconfig go in start up tab...you can slice the list with screenshots using the capture tool...

So then, reboot and see if it reappears!!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
HP Pavillion dv5
I see this icon everytime i startup the computer.
Sometimes it suddenly disappears, but this time it took so much time than ever to let me Prntscrn of it .
and now .. it disappeared again ..
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
MSConfig - Startup
 

Attachments

  • MSconfig.jpg
    MSconfig.jpg
    107.3 KB · Views: 27

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
Kathy: in that case you either have a so called "Dropper" on your system or you visit pages that upload that exe to your computer again and again...
If you have Malwarebytes run a full scan and it doesn't find the dropper, there is no way of knowing what really causes this file to reappear.

If it comes through the browser, I would switch off Javascript, stay away from any P2P Soft for the time being
It could even come through some Flashplayer etc...

You could also test some online AVs from this thread:
http://www.sevenforums.com/security-basics/8557-online-file-scanner-sites.html

-DG
 

My Computer

Computer Manufacturer/Model Number
HP m8000n
OS
Windows 7 Ultimate x86
CPU
DualCore AMD Athlon 64 X2, 2600 MHz 5200+
Motherboard
Asus M2N68-LA (Narra)
Memory
Samsung 2GB DDR2
Graphics Card(s)
Onboard NVIDIA GeForce 6150SE nForce 430
Sound Card
Onboard nVIDIA nForce 6100-430 (MCP61P)
Monitor(s) Displays
Westinghouse 19" LED
Screen Resolution
1280x1024
Hard Drives
SATA II Seagate Barracuda 500GB
USB II WD Elements 500GB
USB II WD My Book 1TB
USB II WD My Book 2TB
PSU
Stock (HP)
Case
Stock (HP)
Cooling
Stock
Keyboard
Logitech Classic KB 200
Mouse
Standard HP opticle USB mouse
Mmm......I wonder if this is some form of bloatware. Is your Windows an OEM version?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Ok guys, I'll do all steps you wrote..
I'll check after Online scanning and rebooting if it appears another time, If yes, so I'll replay back..
 

My Computer

Computer Manufacturer/Model Number
HP Pavilion Enterainment PC dv5
OS
Windows 7 Ultimate 32-bit SP1
CPU
Intel Core2 Duo T5800 @ 2.00GHz
Memory
2.0GB RAM
Graphics Card(s)
NVIDIA GeForce 9200M GS
Screen Resolution
12800x800
Internet Speed
3.1Mbps
Thought that first of bloatwares password recovery from the manufacturer...but if it isn't inside an uninstaller then...might be a malware.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
CPU
Ivy Bridge Core i5 3570K (Delidded)
Motherboard
Asus P8Z77-V LE PLUS
Memory
G.Skill "Ares" DDR3 PC3-12800 - 1600MHz (16Gb)
Graphics Card(s)
Asus Dual-RX480-O4G
Sound Card
Creative Sound Blaster Z w/5.1 sound system
Monitor(s) Displays
Asus IPS 23"
Screen Resolution
16/9
Hard Drives
Internal:
500Go Sata 6Gb/s (x2)
500Go Sata 3Gb/s (x2)
SSD 60Go Sata 6Gb/s
PSU
In Win C 900W Series 80+ Platinum
Case
Thermaltake Chaser A71
Cooling
Custom Water Cooling Loop
Keyboard
Cooler Master QuickFire XTi
Mouse
Razer Imperator 2012 (4G)
Antivirus
MSE
Browser
IE 11.0.xxx Rtm
Other Info
"Raid0" with Intel Smart Response Technology (HDD/SSD)
one more idea in case the culprit can't been found:
Make sure you see extensions of known files

next time when the exe reappears, delete it and then take any Text file, name it "GET ALL PASSWORDS.EXE"
Set it to read only and see if that malware file comes back by getting around this "construct"
I bet it doesn't ;)
-DG
 

My Computer

Computer Manufacturer/Model Number
HP m8000n
OS
Windows 7 Ultimate x86
CPU
DualCore AMD Athlon 64 X2, 2600 MHz 5200+
Motherboard
Asus M2N68-LA (Narra)
Memory
Samsung 2GB DDR2
Graphics Card(s)
Onboard NVIDIA GeForce 6150SE nForce 430
Sound Card
Onboard nVIDIA nForce 6100-430 (MCP61P)
Monitor(s) Displays
Westinghouse 19" LED
Screen Resolution
1280x1024
Hard Drives
SATA II Seagate Barracuda 500GB
USB II WD Elements 500GB
USB II WD My Book 1TB
USB II WD My Book 2TB
PSU
Stock (HP)
Case
Stock (HP)
Cooling
Stock
Keyboard
Logitech Classic KB 200
Mouse
Standard HP opticle USB mouse
Back
Top