I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

Anonymous
2016-07-22T05:22:03+00:00

I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

SHA256: 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e
Tên tập tin: SECOH-QAD.dll
Tỷ lệ phát hiện: 18 / 54
Ngày phân tích: 2016-07-22 05:07:40 UTC ( 2 phút trước )

43

47

AVware Trojan.Win32.Generic!BT 20160722
AegisLab Nettool.Win64.Rpchook!c 20160721
Antiy-AVL RiskWare[NetTool:not-a-virus]/Win64.RPCHook 20160722
CAT-QuickHeal NetTool.RPCHook.r4 (Not a Virus) 20160721
ESET-NOD32 Win64/HackKMS.D potentially unsafe 20160722
GData Win64.Application.Agent.YQQKJO 20160722
Ikarus PUA.NetTool.RPCHook 20160721
Jiangmin NetTool.RPCHook.k 20160722
K7AntiVirus Hacktool ( 000047b11 ) 20160721
K7GW Hacktool ( 000047b11 ) 20160722
Kaspersky not-a-virus:NetTool.Win64.RPCHook.a 20160722
McAfee Generic HTool.b 20160721
McAfee-GW-Edition Generic HTool.b 20160722
NANO-Antivirus Riskware.Win64.HackKMS.dzkjpw 20160722
VIPRE Trojan.Win32.Generic!BT 20160722
ViRobot RPCHook.3584[h] 20160722
Yandex Riskware.NetTool! 20160721
nProtect Trojan/W32.Agent.3584.MQ 20160721
ALYac 20160722
AVG 20160722
Ad-Aware 20160722
AhnLab-V3 20160721
Alibaba 20160722
Arcabit 20160722
Avast 20160722
Avira (no cloud) 20160721
Baidu 20160721
BitDefender 20160722
Bkav 20160721
CMC 20160715
ClamAV 20160722
Comodo 20160722
Cyren 20160722
DrWeb 20160722
Emsisoft 20160722
F-Prot 20160722
F-Secure 20160722
Fortinet 20160722
Kingsoft 20160722
Malwarebytes 20160722
eScan 20160722
Microsoft 20160722
Panda 20160721
Qihoo-360 20160722
SUPERAntiSpyware 20160722
Sophos 20160722
Symantec 20160722
Tencent 20160722
TheHacker 20160720
TrendMicro 20160722
TrendMicro-HouseCall 20160722
VBA32 20160721
Zillya 20160721
Zoner 20160722
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

84 answers

Sort by: Newest
  1. Anonymous
    2016-07-26T09:17:48+00:00

    I used  freefixer scan have some errors?

    FreeFixer v1.13 log

    http://www.freefixer.com/

    Operating system: Windows 10

    Log dated 2016-07-26 15:59

    Browser Helper Objects (2 whitelisted)

    ======================================

    32-bit, {1E871FF8-029C-4732-8AA7-39E3D3872057}, EGet Class, C:\Program Files (x86)\EagleGet\eagleSniffer.dll, signer: [unsigned]

    Registry Startups (3 whitelisted)

    =================================

    HKLM..\Run, ETDCtrl = C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]

    HKCU..\Run, UniKey = C:\Program Files\UniKey\UniKeyNT.exe, signer: [unsigned]

    Scheduled tasks (62 whitelisted)

    ================================

    FreeFixer background scan, C:\Program Files\FreeFixer\freefixer.exe -bgscan, signer: [unsigned]

    klcp_update, "C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe" /verysilent /update /freq=30, signer: [unsigned]

    Autostart shortcuts

    ===================

    Adobe Gamma.lnk, , C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe, signer: [unsigned]

    Processes (60 whitelisted)

    ==========================

    C:\ProgramData\MobileBrServ\mbbService.exe, signer: Huawei Technologies Co., Ltd. [valid]

    C:\Program Files\Elantech\ETDService.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files (x86)\EagleGet\EGMonitor.exe, signer: [unsigned]

    C:\Program Files (x86)\EagleGet\EGMonitor.exe, signer: [unsigned]

    C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\Elantech\ETDTouch.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\Elantech\ETDCtrlHelper.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe, signer: [unsigned]

    C:\Program Files\WindowsApps\Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe, signer: [unsigned]

    C:\Program Files\UniKey\UniKeyNT.exe, signer: [unsigned]

    C:\Program Files\FreeFixer\freefixer.exe, signer: [unsigned]

    Application modules (83 whitelisted)

    ====================================

    C:\Program Files\UniKey\UKHook40.dll, signer: [unsigned]

    Services (60 whitelisted)

    =========================

    egGetSvc, egGetSvc, c:\program files (x86)\eagleget\egmonitor.exe, signer: [unsigned]

    ETDService, Elan Service, c:\program files\elantech\etdservice.exe, signer: ELAN Microelectronics Corporation [valid]

    Mobile Broadband HL Service, Mobile Broadband HL Service, c:\programdata\mobilebrserv\mbbservice.exe, signer: Huawei Technologies Co., Ltd. [valid]

    Explorer.exe Modules (254 whitelisted)

    ======================================

    C:\WINDOWS\SYSTEM32\igd10iumd64.dll, signer: IntelVPGSigning2014 [valid]

    C:\WINDOWS\SYSTEM32\igdusc64.dll, signer: IntelVPGSigning2014 [valid]

    C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll, signer: [unknown]

    Error getting translation table with 'VerQueryValue' for the file 'C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll'. cbTranslate: 0. Data size: 188. System error message: The specified resource type cannot be found in the image file. Error code: 1813.

    C:\Program Files\UniKey\UKHook40.dll, signer: [unsigned]

    Drivers (108 whitelisted)

    =========================

    epp, epp, c:\users\mypc\downloads\emsisoftemergencykit\bin64\epp.sys, signer: Emsisoft Ltd [valid]

    HWiNFO32, HWiNFO32/64 Kernel Driver, c:\windows\system32\drivers\hwinfo64a.sys, signer: Martin Malik - REALiX [valid]

    Partizan, Partizan, C:\WINDOWS\system32\drivers\partizan.sys (file is missing)

    Chrome Extensions

    =================

    Google Slides, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json, signer: [unsigned]

    Google Docs, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json, signer: [unsigned]

    Google Sheets, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\manifest.json, signer: [unsigned]

    Google Docs Offline, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\manifest.json, signer: [unsigned]

    Avira SafeSearch Plus, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp\1.4.1_0\manifest.json, signer: [unsigned]

    Recently created/modified files (3 whitelisted)

    ===============================================

    1 hour, c:\Users\MyPC\AppData\Local\Temp~nsu.tmp\Au_.exe, signer: [unknown]

    Failed to calculate hash for 'c:\Users\MyPC\AppData\Local\Temp~nsu.tmp\Au_.exe' using 'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System error message: %1 is not a valid Win32 application. Error code: 2147942593.

    1 hour, c:\Program Files (x86)\FormatFactory\uninst.exe, signer: [unknown]

    Failed to calculate hash for 'c:\Program Files (x86)\FormatFactory\uninst.exe' using 'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System error message: %1 is not a valid Win32 application. Error code: 2147942593.

    1 hour, c:\Users\MyPC\AppData\Local\Temp\FFSetupLatest.exe, signer: Free Time Co., Ltd. [valid]

    2 hours, c:\Program Files\FreeFixer\Uninstall.exe, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\CurvesTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PicsArt.UWP.exe, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PicsArt.UWP.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PDDC.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\NativeEffects.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\NativeEffects.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\MotionTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\MotionTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\CurvesTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\ColorSplash.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\ColorSplash.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\BorderTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\BorderTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PDDC.winmd, signer: [unsigned]

    20 hours, c:\Users\MyPC\Downloads\EmsisoftEmergencyKit\bin64\epp.sys, signer: Emsisoft Ltd [valid]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\716433ca145eef176e9213782df3368d\UIAutomationProvider.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\10fa2167d8a5d8e968bc708ca8dfbd0e\Accessibility.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.28b9ef5a#\8240c0da061be9a162af2b5f135f0735\System.Web.Extensions.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\e3ac0db4995bfca8a7f12afdc5e0602b\System.Web.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\e95c04a954155809c430a0c604a6416e\System.ServiceModel.Internals.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\3e6c997c0f5d4d89a00c29e535fbddfb\System.IdentityModel.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\84f2250c582e8bafeaf4fd9e407ba22a\SMDiagnostics.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\088bdb586012457f9e88c8c055b7c42d\WindowsFormsIntegration.ni.dll, signer: [unsigned]

    Errors

    ======

    Problems opening folder 'c:\ProgramData\Microsoft\Windows\SystemData' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Users\MyPC\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\CSC' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\System32\LogFiles\WMI\RtBackup' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    End of FreeFixer log

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-07-26T07:23:05+00:00

    Thank you very much

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-07-25T14:41:22+00:00

    cracked/keygens are one of the fastest ways of infecting your system,  100% of Cracked/KeyGen software contains some form of malicious code.

    Good

    Proshow Producer v-7.0.3527 Full + Patch should be uninstalled/deleted

    These 2 files/folders need to go

    C:\Users\MyPC\Downloads\Proshow Producer v-7.0.3527 Full + Patch\Patch.exe

    C:\WINDOWS\SECOH-QAD.dll

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-07-25T13:56:51+00:00

    Emsisoft Emergency Kit - Version 11.0

    Last update: 7/25/2016 8:13:29 PM

    User account: MAYTINH-1Q20GA5\MyPC

    Scan settings:

    Scan type: Malware Scan

    Objects: Rootkits, Memory, Traces, Files

    Detect PUPs: On

    Scan archives: Off

    ADS Scan: On

    File extension filter: Off

    Advanced caching: On

    Direct disk access: Off

    Scan start: 7/25/2016 8:22:49 PM

    C:\Users\MyPC\Downloads\ccsetup519.exe detected: Application.Toolbar (A)

    C:\Users\MyPC\Downloads\Proshow Producer v-7.0.3527 Full + Patch\Patch.exe detected: Dropped:Trojan.Generic.15028225 (B)

    C:\WINDOWS\SECOH-QAD.dll detected: Riskware.NetTool (A)

    Scanned 79103

    Found 3

    Scan end: 7/25/2016 8:27:09 PM

    Scan time: 0:04:20

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-07-25T11:51:09+00:00

    • Download EmsisoftEmergencyKit
    • run the exe and extract the content in a folder of your choice like (C:\EEK) by clicking the Extract button.
    • Double-click the desktop-shortcut called Start Emsisoft Emergency Kitto start the tool.
    • Click on the "Yes" button when asked to obtain the latest malware definitions.
    • Once the update is complete click "Scan".
    • Click on the "Yes" button when asked to enable the scan for Potentially Unwanted Applications.
    • Next click on the Full Scan. When the scan complete, click on the View Report button (don't delete or quarantine anything).
    • Please copy and paste the content of the report in your next reply.

    Was this answer helpful?

    0 comments No comments