Thank you very much
I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???
I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???
| SHA256: | 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e |
|---|---|
| Tên tập tin: | SECOH-QAD.dll |
| Tỷ lệ phát hiện: | 18 / 54 |
| Ngày phân tích: | 2016-07-22 05:07:40 UTC ( 2 phút trước ) |
43
47
| AVware | Trojan.Win32.Generic!BT | 20160722 |
|---|---|---|
| AegisLab | Nettool.Win64.Rpchook!c | 20160721 |
| Antiy-AVL | RiskWare[NetTool:not-a-virus]/Win64.RPCHook | 20160722 |
| CAT-QuickHeal | NetTool.RPCHook.r4 (Not a Virus) | 20160721 |
| ESET-NOD32 | Win64/HackKMS.D potentially unsafe | 20160722 |
| GData | Win64.Application.Agent.YQQKJO | 20160722 |
| Ikarus | PUA.NetTool.RPCHook | 20160721 |
| Jiangmin | NetTool.RPCHook.k | 20160722 |
| K7AntiVirus | Hacktool ( 000047b11 ) | 20160721 |
| K7GW | Hacktool ( 000047b11 ) | 20160722 |
| Kaspersky | not-a-virus:NetTool.Win64.RPCHook.a | 20160722 |
| McAfee | Generic HTool.b | 20160721 |
| McAfee-GW-Edition | Generic HTool.b | 20160722 |
| NANO-Antivirus | Riskware.Win64.HackKMS.dzkjpw | 20160722 |
| VIPRE | Trojan.Win32.Generic!BT | 20160722 |
| ViRobot | RPCHook.3584[h] | 20160722 |
| Yandex | Riskware.NetTool! | 20160721 |
| nProtect | Trojan/W32.Agent.3584.MQ | 20160721 |
| ALYac | 20160722 | |
| AVG | 20160722 | |
| Ad-Aware | 20160722 | |
| AhnLab-V3 | 20160721 | |
| Alibaba | 20160722 | |
| Arcabit | 20160722 | |
| Avast | 20160722 | |
| Avira (no cloud) | 20160721 | |
| Baidu | 20160721 | |
| BitDefender | 20160722 | |
| Bkav | 20160721 | |
| CMC | 20160715 | |
| ClamAV | 20160722 | |
| Comodo | 20160722 | |
| Cyren | 20160722 | |
| DrWeb | 20160722 | |
| Emsisoft | 20160722 | |
| F-Prot | 20160722 | |
| F-Secure | 20160722 | |
| Fortinet | 20160722 | |
| Kingsoft | 20160722 | |
| Malwarebytes | 20160722 | |
| eScan | 20160722 | |
| Microsoft | 20160722 | |
| Panda | 20160721 | |
| Qihoo-360 | 20160722 | |
| SUPERAntiSpyware | 20160722 | |
| Sophos | 20160722 | |
| Symantec | 20160722 | |
| Tencent | 20160722 | |
| TheHacker | 20160720 | |
| TrendMicro | 20160722 | |
| TrendMicro-HouseCall | 20160722 | |
| VBA32 | 20160721 | |
| Zillya | 20160721 | |
| Zoner | 20160722 |
Windows for home | Windows 10 | Security and privacy
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
84 answers
Sort by: Most helpful
-
Anonymous
2016-08-11T15:00:24+00:00 -
Anonymous
2016-08-08T10:24:10+00:00 I am not familiar with FreeFixer
What you can do is delete temp files
c:\Users\MyPC\AppData\Local\Temp
go to the above folder, delete the files inside (not the folder)
-
Anonymous
2016-08-08T06:19:57+00:00 I new updates to Windows 10 to the new version 1607
I used FreeFixer to scan it out some errors this?
FreeFixer v1.13 log
Operating system: Windows 10
Log dated 2016-08-08 12:01
KnownDlls
=========
DllDirectory=\system32 is missing
DllDirectory32=\syswow64 is missing
Browser Helper Objects (2 whitelisted)
======================================
32-bit, {1E871FF8-029C-4732-8AA7-39E3D3872057}, EGet Class, C:\Program Files (x86)\EagleGet\eagleSniffer.dll, signer: [unsigned]
Registry Startups (4 whitelisted)
=================================
HKLM..\Run, ETDCtrl = C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]
HKCU..\Run, CocCoc Update = "C:\Users\MyPC\AppData\Local\CocCoc\Update\CocCocUpdate.exe" /c, signer: COC COC COMPANY LIMITED [valid]
Scheduled tasks (76 whitelisted)
================================
CocCocUpdateTaskUserS-1-5-21-2467849759-2362741521-3472617361-1001Core, C:\Users\MyPC\AppData\Local\CocCoc\Update\CocCocUpdate.exe /c, signer: COC COC COMPANY LIMITED [valid]
CocCocUpdateTaskUserS-1-5-21-2467849759-2362741521-3472617361-1001UA, C:\Users\MyPC\AppData\Local\CocCoc\Update\CocCocUpdate.exe /ua /installsource scheduler, signer: COC COC COMPANY LIMITED [valid]
FreeFixer background scan, C:\Program Files\FreeFixer\freefixer.exe -bgscan, signer: [unsigned]
klcp_update, "C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe" /verysilent /update /freq=30, signer: [unsigned]
Autostart shortcuts
===================
Adobe Gamma.lnk, , C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe, signer: [unsigned]
Processes (57 whitelisted)
==========================
C:\Program Files\Elantech\ETDService.exe, signer: ELAN Microelectronics Corporation [valid]
C:\ProgramData\MobileBrServ\mbbService.exe, signer: Huawei Technologies Co., Ltd. [valid]
(no file specified)
QueryFullProcessImageName failed while trying to get a process full path. Process handle: 0000000000000624. System error message: A device attached to the system is not functioning. Error code: 31.
C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]
C:\Program Files\Elantech\ETDTouch.exe, signer: ELAN Microelectronics Corporation [valid]
C:\Program Files\Elantech\ETDCtrlHelper.exe, signer: ELAN Microelectronics Corporation [valid]
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe\HxMail.exe, signer: [unsigned]
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6965.41051.0_x64__8wekyb3d8bbwe\HxTsr.exe, signer: [unsigned]
C:\Program Files\WindowsApps\Microsoft.WindowsStore_11606.1001.39.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe, signer: [unsigned]
C:\Program Files\FreeFixer\freefixer.exe, signer: [unsigned]
Services (63 whitelisted)
=========================
egGetSvc, egGetSvc, c:\program files (x86)\eagleget\egmonitor.exe, signer: [unsigned]
ETDService, Elan Service, c:\program files\elantech\etdservice.exe, signer: ELAN Microelectronics Corporation [valid]
Mobile Broadband HL Service, Mobile Broadband HL Service, c:\programdata\mobilebrserv\mbbservice.exe, signer: Huawei Technologies Co., Ltd. [valid]
Explorer.exe Modules (250 whitelisted)
======================================
C:\WINDOWS\SYSTEM32\igd10iumd64.dll, signer: IntelVPGSigning2014 [valid]
C:\WINDOWS\SYSTEM32\igdusc64.dll, signer: IntelVPGSigning2014 [valid]
C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll, signer: [unknown]
Error getting translation table with 'VerQueryValue' for the file 'C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64\ClientTelemetry.dll'. cbTranslate: 0. Data size: 188. System error message: The specified resource type cannot be found in the image file. Error code: 1813.
Drivers (111 whitelisted)
=========================
HWiNFO32, HWiNFO32/64 Kernel Driver, c:\windows\system32\drivers\hwinfo64a.sys, signer: Martin Malik - REALiX [valid]
ZAM_Guard, ZAM Guard Driver, c:\windows\system32\drivers\zamguard64.sys, signer: Zemana Ltd. [valid]
Chrome Extensions
=================
Google Slides, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json, signer: [unsigned]
Google Docs, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json, signer: [unsigned]
Google Sheets, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\manifest.json, signer: [unsigned]
Avira Browser Safety, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk\1.11.0_0\manifest.json, signer: [unsigned]
Google Docs Offline, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\manifest.json, signer: [unsigned]
Chrome Media Router, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5116.418.1.13_0\manifest.json, signer: [unsigned]
Filesystem Internet Shortcuts
=============================
C:\Users\MyPC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\C?c C?c.lnk =
An exception occured when trying to load the shortcut C:\Users\MyPC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\C?c C?c.lnk
HRESULT: -2147024773
C:\Users\MyPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C?c C?c.lnk =
An exception occured when trying to load the shortcut C:\Users\MyPC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C?c C?c.lnk
HRESULT: -2147024773
C:\Users\MyPC\Desktop\C?c C?c.lnk =
An exception occured when trying to load the shortcut C:\Users\MyPC\Desktop\C?c C?c.lnk
HRESULT: -2147024773
Recently created/modified files (27 whitelisted)
================================================
12 minutes, c:\Program Files\FreeFixer\Uninstall.exe, signer: [unsigned]
35 minutes, c:\Users\MyPC\AppData\Local\Temp~nsu.tmp\Au_.exe, signer: [unsigned]
17 hours, c:\Users\MyPC\AppData\Local\Temp\PotUpdate\PotPlayerSetup64_58.exe, signer: [unknown]
Failed to calculate hash for 'c:\Users\MyPC\AppData\Local\Temp\PotUpdate\PotPlayerSetup64_58.exe' using 'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System error message: %1 is not a valid Win32 application. Error code: 2147942593.
Errors
======
Problems opening folder 'c:\ProgramData\Microsoft\Windows\SystemData' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\ProgramData\Microsoft\Windows Defender Advanced Threat Protection' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Users\MyPC\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows\CSC' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows\System32\LogFiles\WMI\RtBackup' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows.old\ProgramData\Microsoft\Windows\SystemData' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows.old\Users\MyPC\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
Problems opening folder 'c:\Windows.old\WINDOWS\System32\LogFiles\WMI\RtBackup' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.
End of FreeFixer log
-
Anonymous
2016-08-07T12:07:18+00:00 6 reputable antivirus pick up that it's an unsafe file, my personal opinion is to remove it from the computer.
-
Anonymous
2016-08-07T10:40:47+00:00 I download the free software KraFunStudio 1.20 to do video
I use Avira, Windows Defender, Hitmanpro, AdwCleaner, Malwarebytes, ESET Smart Installer to scan this software , but no virus
I use VirusTotal to scan it out results like this ?
Should I use this software no??
SHA256: 8bcc09cf8f4a16c1504e4cd646931f197a4a0b26465de0a38a7697168a6def8a File name: KaraFunStudio1.20.exe Detection ratio: 6 / 53 Analysis date: 2016-07-31 07:05:37 UTC ( 1 week ago ) 0
0
AVware Trojan.Win32.Generic!BT 20160731 AegisLab Troj.Gen!c 20160731 McAfee Artemis!17D01133C931 20160731 McAfee-GW-Edition BehavesLike.Win32.BadFile.wc 20160730 Symantec Trojan.Gen.SMH.2 20160731 VIPRE Trojan.Win32.Generic!BT 20160731 ALYac 20160731 AVG 20160731 Ad-Aware 20160731 AhnLab-V3 20160730 Alibaba 20160730 Antiy-AVL 20160731 Arcabit 20160731 Avast 20160731 Avira (no cloud) 20160730 Baidu 20160730 BitDefender 20160731 Bkav 20160727 CAT-QuickHeal 20160730 CMC 20160728 ClamAV 20160731 Comodo 20160731 Cyren 20160731 DrWeb 20160731 ESET-NOD32 20160730 Emsisoft 20160731 F-Prot 20160731 F-Secure 20160731 Fortinet 20160731 GData 20160731 Ikarus 20160730 Jiangmin 20160731 K7AntiVirus 20160731 K7GW 20160731 Kaspersky 20160731 Kingsoft 20160731 Malwarebytes 20160731 eScan 20160731 Microsoft 20160731 NANO-Antivirus 20160731 Panda 20160730 Qihoo-360 20160731 SUPERAntiSpyware 20160731 Sophos 20160731 Tencent 20160731 TheHacker 20160729 TrendMicro 20160731 TrendMicro-HouseCall 20160731 VBA32 20160729 ViRobot 20160731 Zillya 20160730 Zoner 20160731 nProtect 20160729 Blog | Twitter | ******@virustotal.com| Google groups | ToS | Privacy policy
