Solved Windows Activation Technologies Pop-up

Re: Malware issues. Suggest getting help in the System Security thread.

If you like you can also run a scan with Ultra Adware Killer. You can launch it from UVK's welcome screen. Do not select anything for removal. When the scan completes select "Menu" then "Open Log" - upload the file.

UAKr.jpg

You could also run scans with the other built in apps. Scan with MBAM and ADW Cleaner. Do not use the other apps!

Welcome Screen > System Repair > Third Party Apps.

It will download the app or update to the latest version if you already have the app installed.
UVK - Apps.jpg
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
I looked at your log. Can you confirm what is in this folder?

C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}

Two files:

amstream.dll, 8-Oct-15 14:10, Application Extension, 267 KB

8afc49b02429a, 8-Oct-15 14:32, File, 178 KB

Do you think this is the virus? If so, should I manually delete it?

Regards
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I've contacted ESET tech support and they have opened a case with elevated tech support. We weren't able to do a chat support, so we've switched to email. I've emailed them a compendium of log files gathered by one of their ESET utilities. They're supposed to give me a call or email back after they've analyzed the logs.

I will move this topic to the malware forum, because that is what this is all about.

Regards
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I looked at your log. Can you confirm what is in this folder?

C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}

Two files:

amstream.dll, 8-Oct-15 14:10, Application Extension, 267 KB

8afc49b02429a, 8-Oct-15 14:32, File, 178 KB

Do you think this is the virus? If so, should I manually delete it?

Regards

I think it's legit and should be left alone. It's just that that GUID could have contained some malware. In this case - it doesn't. Thanks for having a look!
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
The MGADiag is clear - and shows no significant changes in the past year or so (compared to your earlier thread).
KB971033 is installed - and happy ;)
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Thank you Noel.

When I clicked on that UAC pop-up, I immediately started having a virus problem. Presently, neither ESET Smart Security 8, Windows Defender nor SuperAntiSpyware have been able to eradicate it.

This virus downloads temp file junk at an alarming rate. It also causes the system to behave very sluggishly when navigating with Windows Explorer. When I shutdown, I get a few moments of webpage ads visible in flashes.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
This was a Trojan.Bedep virus variation. ESET tech support removed it and repaired the damage. Without their support, I would have had to restore the system. However, as I had deleted all my restore points, I would have had to reload the OS.

It all started when I clicked "Yes" on that User Account Control box. Whenever something like that pops up for no reason, you should start scanning.

Regards
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
The Task Scheduler indicates it was last run 11-Sep-15 06:15:10.

If I understand that correctly, it wasn't running when I started this thread or when I clicked the "Yes" button.

Therefore, it must have been a fake indication of a run.

Is that correct?
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
You would ONLY have got that popup for one reason - you were attempting to install the update.
The update is signed, and as such, if there had been a problem with it, you would have seen a very different popup describing certificate errors.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
I wasn't installing anything. I think that pop-up was an impostor and I was tricked into clicking yes. Once I clicked yes, all the trouble started.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
Well I kind of agree with Noel however that doesn't explain why task scheduler doesn't show that it ran when you clicked on the UAC pop up! Instead in shows 11 September which doesn't seem right.
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
Well I kind of agree with Noel however that doesn't explain why task scheduler doesn't show that it ran when you clicked on the UAC pop up! Instead in shows 11 September which doesn't seem right.

If it was an impostor, it seems right. The UAC didn't run, but a pop-up that appeared to be the UAC did run and when I clicked on "Yes," the back door was wide open for all the riff-raff.

I thought it was very strange for that pop-up to occur. That's why I started this thread, but I didn't wait long enough to read the replies, before I got curious and clicked "Yes."

The two were definately related.

It's been so long since I've been hit like that that I got stupid.

Regards
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
I clicked yes too

Hey tjg79, I fell for it too even after checking the cert (expired) and researching WAT. When I saw that it did not update the file(s) it said it was going to, I immediately pull the system from the network and reimaged it. I also changed my user name and password. I still haven't solved my account lockout problem this caused though. :eek:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 N x64
Antivirus
Endpoint Securoty by Bitdefender
Browser
IE 11
Hey tjg79, I fell for it too even after checking the cert (expired) and researching WAT. When I saw that it did not update the file(s) it said it was going to, I immediately pull the system from the network and reimaged it. I also changed my user name and password. I still haven't solved my account lockout problem this caused though. :eek:

I think this virus is new. It's very sophisticated, because the pop-up is high quality and looks legit.

When ESET tech support cleaned my system, they collected what information they could about this virus. Hopefully, it will be incorporated into their virus definitions soon.

Regards
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Professional x64 SP1
CPU
Intel i7-980x @ 3.6GHz
Motherboard
Intel DX58SO
Memory
Corsair 12GB DDR3 RAM (3x4GB)
Graphics Card(s)
EVGA NVIDIA GeForce GTX 760 SC
Sound Card
Intel High Definition 7.1 Audio Subsystem - Realtek ALC889
Monitor(s) Displays
Dual Display - LG Electronics Flatron L227WTG
Screen Resolution
1680 x 1050 60Hz 32-bit
Hard Drives
2 Seagate Constellation ST1000NM0033 1TB SATA 6Gb/s HDDs configured as Intel SATA Array 0, RST RAID 1, Vol. 0 (C:\) & Vol. 1 (D:\), & 2 Seagate Barracuda ST500DM002 500GB SATA 6Gb/s HDDs configured as Intel SATA Array 1 RST RAID 1, Vol. 0 (E:\)
PSU
Corsair HX850W
Case
Antec P182
Cooling
Stock Intel i7-980x Cooling Solution + 4 120mm Case Fans
Keyboard
Microsoft Wireless Multimedia Keyboard 1.1
Mouse
Microsoft Standard Wireless Optical Mouse
Internet Speed
DSL - 3.0 Mb/s download 768 Kb/s upload
Antivirus
ESET Smart Security 12, Defender & SuperAntiSpyware Pro
Browser
Firefox Quantum 64-bit
Other Info
Optical Drives: Pioneer DVR-216R & TSSTcorp SH-S223Q, Anker USB 3.0 PCI-E Card, Hauppauge WinTV-HVR 2250 Dual TV Tuner Board for Windows Media Center, Bose Companion 3 Series II multimedia speaker system, APC Smart-UPS SMT1500
FYI-we believe the payload came from camelcap.com/work/home/index.php. Since I re-imaged the system, that was all we could find. I also solved my account lockout issue which was fortunately only caused by my username change.

Cheers
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell
OS
Windows 7 N x64
Antivirus
Endpoint Securoty by Bitdefender
Browser
IE 11
FYI-we believe the payload came from camelcap.com/work/home/index.php. Since I re-imaged the system, that was all we could find. I also solved my account lockout issue which was fortunately only caused by my username change.

Cheers

Well I tried to find that payload in order to try to infect my machine and study it but I get:

404 Not Found.jpg
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
ASUS
OS
Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
CPU
AMD C-60 APU with Radeon(tm) HD Graphics
Motherboard
ASUSTeK COMPUTER INC. X501U
Memory
4.00 GB
Graphics Card(s)
AMD Radeon HD 6290 Graphics
Sound Card
(1) AMD High Definition Audio Device (2) Realtek High Defi
Screen Resolution
1366 x 768 x 32 bits (4294967296 colors) @ 60 Hz
Hard Drives
Hitachi HTS545050A7E380 SATA Disk Device
Antivirus
Comodo CIS & FW, SecureAplus App Whitelisting, Threatfire
Browser
Cyberfox 64bit, Opera 64bit, Airfox
Other Info
Spy-The-Spy, HitmanPro.Alert, Norton Connect Safe, MJRegWatcher, BitDefender TrafficLight, Voodoo Shield, Zemana AntiMalware
The who.is data on camelcap is interesting -
originally registered 16/9/15 - so only 1 month old.
Registrar is in China
Registered owner is in the UK (!) - the post code is actually for ebuyer.com (!!) - but the address is Skelton, a couple of miles away, and appears not to exist (at least according to the Royal Mail postcode finder service).
 

My Computer My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Asus K52F or Lenovo B51-80
OS
Win 7 x64 Home Premium (and x86 VirtualBox VM)/Win10
CPU
i3 370M/i7 6500U
Motherboard
Asus/Lenovo
Memory
8GB - finally :)/8GB
Graphics Card(s)
it's an i3, dude!/dual Intel&nVidia
Sound Card
onboard
Monitor(s) Displays
15.6" built-in
Screen Resolution
1366x768/1920x1080
Hard Drives
750GB Seagate internal
Sundry external drives attached to other computers on the local network
1TB SSD on the Lenovo
PSU
n/a
Internet Speed
as much as I can get - usually on a dongle/phone, so <1MB/s
Antivirus
MSE/Defender
Browser
IE11/12/Edge/Chrome/FF(if I must)
Back
Top