Author

Topic: HELP please. Infected pc. (Read 469 times)

full member
Activity: 140
Merit: 100
January 05, 2014, 09:58:55 AM
#6
Find its path from procexp. Reboot into safe mode with networking. Rename the folder. Reboot
hero member
Activity: 784
Merit: 500
January 05, 2014, 04:13:48 AM
#5
yes it's on the process explorer, but i have a bsod if i try to close it
member
Activity: 70
Merit: 10
January 04, 2014, 02:01:12 AM
#4
Check your /appdata or your /temp files. Look for anything weird. Does it show on your process explorer?
hero member
Activity: 784
Merit: 500
January 04, 2014, 01:57:46 AM
#3
Yes that's an autoit.

I'll check bleepingcomputer thanks.
full member
Activity: 140
Merit: 100
January 04, 2014, 01:51:58 AM
#2
I played with that. It was an autoit script. If I remember correctly this was installed in %appdata% but could be wrong.

Go visit the people at http://www.bleepingcomputer.com. They rock and can help you with this easily.
hero member
Activity: 784
Merit: 500
January 04, 2014, 01:44:13 AM
#1
Hi everyone.

3 days ago I was trapped here like a noob by a post about pts gpu miner. I downloaded it; and now I'm infected.

I have a process running (a fake jhproto process i assume) which can't be killed without killing the session and make the pc hard reboot.

I made a malwarebyte and antivirus scan without success.

I have disconnected that pc since I installed this shit. I would like to avoid reinstalling the 40000000 wallets on it so if it could be cleared without reinstalling that'd be great.

Could someone help me with this ? Thanks.

Slavo
Jump to: