Interesting File

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Whizpopthat, Apr 20, 2012.

  1. Whizpopthat

    Whizpopthat Private E-2

    I ran scans & HTJ one day because I wanted to check to see if my work computer was clean. Picked up a few trojans (I just started working here), well when I ran HTJ I ran into a file named "evlomypv.exe" I cannot find any information on it online and it was found in /system32/ with the hidden box checked. It says 'IPsec Session Window Firewall - Unknown Owner - etc ..."
    But that's not very convincing beings I cannot find information the .exe file name itself. Main issue why I was looking at this because when I go to load the website for my school, I log into chemeketa.blackboard.com and then as soon as I do Firefox exits and if I try in IE it refreshes like an infinite loop but stops to say so. So I tried seeing if maybe it was java related and so I loaded runescape.com and clicked play now and as soon as I clicked that, poof Firefox gone just like before, same in IE (infinite loop). Any solutions?

    HTJ logs attached
    If anyone wants to examine the evlomypv.exe file and knows how to, I have uploaded it online; be my guest just PM me for det's if you want a link provided.
     

    Attached Files:

  2. Whizpopthat

    Whizpopthat Private E-2

    I might as well post these logs too, just found time to run MBR & TDSS.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to rerun TDSSKillr and have it fix this:
    Attach the new log.

    Now you need to follow these directions:

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. Whizpopthat

    Whizpopthat Private E-2

    Doing the READ & RUN ME now. Just out of question, any knowledge of that .exe file I was talking about?
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just a random malware file. You can zip it up for me if you like so that I can further examine it. Attach it here for me. Call it badfile.zip
     
  6. Whizpopthat

    Whizpopthat Private E-2

    Just got to work now, am starting the cleaning process; file attached.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  8. Whizpopthat

    Whizpopthat Private E-2

    Thanks for examining that file. It looks like after I ran DeFogger and ran Malwarebytes, it picked out the file like a sniper. :) Thanks.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So can you attach the log from MalwareBytes as well as the other requested logs or do you no longer require my assistance? :confused
     
  10. Whizpopthat

    Whizpopthat Private E-2

    If you want I can attach the logs on Thursday when I go back to work. My main concern was that file and after I finished disabling the emulators, it finally popped up in the scan and got it all removed. Like I said though if you want the logs I can post them, otherwise I appreciate your help :)
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Choice is yours of course. If you want to be thorough and have me check for any remnants go ahead and attach them when possible. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds