I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

Anonymous
2016-07-22T05:22:03+00:00

I used VirusTotal to scan file SECOH-QAD.dll it out a notice dangerous this ???

SHA256: 0398221231cff97e1fdc03d357ac4610afb8f3cdde4c90a9ec4d7823b405699e
Tên tập tin: SECOH-QAD.dll
Tỷ lệ phát hiện: 18 / 54
Ngày phân tích: 2016-07-22 05:07:40 UTC ( 2 phút trước )

43

47

AVware Trojan.Win32.Generic!BT 20160722
AegisLab Nettool.Win64.Rpchook!c 20160721
Antiy-AVL RiskWare[NetTool:not-a-virus]/Win64.RPCHook 20160722
CAT-QuickHeal NetTool.RPCHook.r4 (Not a Virus) 20160721
ESET-NOD32 Win64/HackKMS.D potentially unsafe 20160722
GData Win64.Application.Agent.YQQKJO 20160722
Ikarus PUA.NetTool.RPCHook 20160721
Jiangmin NetTool.RPCHook.k 20160722
K7AntiVirus Hacktool ( 000047b11 ) 20160721
K7GW Hacktool ( 000047b11 ) 20160722
Kaspersky not-a-virus:NetTool.Win64.RPCHook.a 20160722
McAfee Generic HTool.b 20160721
McAfee-GW-Edition Generic HTool.b 20160722
NANO-Antivirus Riskware.Win64.HackKMS.dzkjpw 20160722
VIPRE Trojan.Win32.Generic!BT 20160722
ViRobot RPCHook.3584[h] 20160722
Yandex Riskware.NetTool! 20160721
nProtect Trojan/W32.Agent.3584.MQ 20160721
ALYac 20160722
AVG 20160722
Ad-Aware 20160722
AhnLab-V3 20160721
Alibaba 20160722
Arcabit 20160722
Avast 20160722
Avira (no cloud) 20160721
Baidu 20160721
BitDefender 20160722
Bkav 20160721
CMC 20160715
ClamAV 20160722
Comodo 20160722
Cyren 20160722
DrWeb 20160722
Emsisoft 20160722
F-Prot 20160722
F-Secure 20160722
Fortinet 20160722
Kingsoft 20160722
Malwarebytes 20160722
eScan 20160722
Microsoft 20160722
Panda 20160721
Qihoo-360 20160722
SUPERAntiSpyware 20160722
Sophos 20160722
Symantec 20160722
Tencent 20160722
TheHacker 20160720
TrendMicro 20160722
TrendMicro-HouseCall 20160722
VBA32 20160721
Zillya 20160721
Zoner 20160722
Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

84 answers

Sort by: Most helpful
  1. Anonymous
    2016-07-26T12:42:48+00:00

    I think you should run another scan with MalwareBytes,  click the update button first

    Go to the Settings Tab

    Under Setting go to [b]Detection and Protection

    Under PUP and PUM make sure both are set to show Treat Detections as Malware

    Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked

    Then on the Dashboard click on Scan

    Make sure to select THREAT SCAN

    Then click on Scan

    If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.

    ******************

    Instructions on how to backup your Favourites/Bookmarks and other data can be found below.

    Export-Bookmarks-from-Chrome]Backup Chrome Bookmarks

    Proceed with the reset once done

    Chrome- Reset Browser settings

    *****

    Do you have Java installed on your computer?

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2016-07-26T09:17:48+00:00

    I used  freefixer scan have some errors?

    FreeFixer v1.13 log

    http://www.freefixer.com/

    Operating system: Windows 10

    Log dated 2016-07-26 15:59

    Browser Helper Objects (2 whitelisted)

    ======================================

    32-bit, {1E871FF8-029C-4732-8AA7-39E3D3872057}, EGet Class, C:\Program Files (x86)\EagleGet\eagleSniffer.dll, signer: [unsigned]

    Registry Startups (3 whitelisted)

    =================================

    HKLM..\Run, ETDCtrl = C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]

    HKCU..\Run, UniKey = C:\Program Files\UniKey\UniKeyNT.exe, signer: [unsigned]

    Scheduled tasks (62 whitelisted)

    ================================

    FreeFixer background scan, C:\Program Files\FreeFixer\freefixer.exe -bgscan, signer: [unsigned]

    klcp_update, "C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe" /verysilent /update /freq=30, signer: [unsigned]

    Autostart shortcuts

    ===================

    Adobe Gamma.lnk, , C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe, signer: [unsigned]

    Processes (60 whitelisted)

    ==========================

    C:\ProgramData\MobileBrServ\mbbService.exe, signer: Huawei Technologies Co., Ltd. [valid]

    C:\Program Files\Elantech\ETDService.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files (x86)\EagleGet\EGMonitor.exe, signer: [unsigned]

    C:\Program Files (x86)\EagleGet\EGMonitor.exe, signer: [unsigned]

    C:\Program Files\Elantech\ETDCtrl.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\Elantech\ETDTouch.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\Elantech\ETDCtrlHelper.exe, signer: ELAN Microelectronics Corporation [valid]

    C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe, signer: [unsigned]

    C:\Program Files\WindowsApps\Microsoft.BingNews_4.11.156.0_x86__8wekyb3d8bbwe\Microsoft.Msn.News.exe, signer: [unsigned]

    C:\Program Files\UniKey\UniKeyNT.exe, signer: [unsigned]

    C:\Program Files\FreeFixer\freefixer.exe, signer: [unsigned]

    Application modules (83 whitelisted)

    ====================================

    C:\Program Files\UniKey\UKHook40.dll, signer: [unsigned]

    Services (60 whitelisted)

    =========================

    egGetSvc, egGetSvc, c:\program files (x86)\eagleget\egmonitor.exe, signer: [unsigned]

    ETDService, Elan Service, c:\program files\elantech\etdservice.exe, signer: ELAN Microelectronics Corporation [valid]

    Mobile Broadband HL Service, Mobile Broadband HL Service, c:\programdata\mobilebrserv\mbbservice.exe, signer: Huawei Technologies Co., Ltd. [valid]

    Explorer.exe Modules (254 whitelisted)

    ======================================

    C:\WINDOWS\SYSTEM32\igd10iumd64.dll, signer: IntelVPGSigning2014 [valid]

    C:\WINDOWS\SYSTEM32\igdusc64.dll, signer: IntelVPGSigning2014 [valid]

    C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll, signer: [unknown]

    Error getting translation table with 'VerQueryValue' for the file 'C:\Users\MyPC\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll'. cbTranslate: 0. Data size: 188. System error message: The specified resource type cannot be found in the image file. Error code: 1813.

    C:\Program Files\UniKey\UKHook40.dll, signer: [unsigned]

    Drivers (108 whitelisted)

    =========================

    epp, epp, c:\users\mypc\downloads\emsisoftemergencykit\bin64\epp.sys, signer: Emsisoft Ltd [valid]

    HWiNFO32, HWiNFO32/64 Kernel Driver, c:\windows\system32\drivers\hwinfo64a.sys, signer: Martin Malik - REALiX [valid]

    Partizan, Partizan, C:\WINDOWS\system32\drivers\partizan.sys (file is missing)

    Chrome Extensions

    =================

    Google Slides, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\manifest.json, signer: [unsigned]

    Google Docs, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\manifest.json, signer: [unsigned]

    Google Sheets, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\manifest.json, signer: [unsigned]

    Google Docs Offline, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\manifest.json, signer: [unsigned]

    Avira SafeSearch Plus, C:\Users\MyPC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp\1.4.1_0\manifest.json, signer: [unsigned]

    Recently created/modified files (3 whitelisted)

    ===============================================

    1 hour, c:\Users\MyPC\AppData\Local\Temp~nsu.tmp\Au_.exe, signer: [unknown]

    Failed to calculate hash for 'c:\Users\MyPC\AppData\Local\Temp~nsu.tmp\Au_.exe' using 'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System error message: %1 is not a valid Win32 application. Error code: 2147942593.

    1 hour, c:\Program Files (x86)\FormatFactory\uninst.exe, signer: [unknown]

    Failed to calculate hash for 'c:\Program Files (x86)\FormatFactory\uninst.exe' using 'CryptCATAdminCalcHashFromFileHandle' while verifying trust. System error message: %1 is not a valid Win32 application. Error code: 2147942593.

    1 hour, c:\Users\MyPC\AppData\Local\Temp\FFSetupLatest.exe, signer: Free Time Co., Ltd. [valid]

    2 hours, c:\Program Files\FreeFixer\Uninstall.exe, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\CurvesTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PicsArt.UWP.exe, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PicsArt.UWP.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PDDC.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\NativeEffects.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\NativeEffects.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\MotionTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\MotionTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\CurvesTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\ColorSplash.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\ColorSplash.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\BorderTool.winmd, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\BorderTool.dll, signer: [unsigned]

    6 hours, c:\Program Files\WindowsApps\2FE3CB00.PicsArt-PhotoStudio_3.3.0.0_x86__crhqpqs3x1ygc\PDDC.winmd, signer: [unsigned]

    20 hours, c:\Users\MyPC\Downloads\EmsisoftEmergencyKit\bin64\epp.sys, signer: Emsisoft Ltd [valid]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationProvider\716433ca145eef176e9213782df3368d\UIAutomationProvider.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\Accessibility\10fa2167d8a5d8e968bc708ca8dfbd0e\Accessibility.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.28b9ef5a#\8240c0da061be9a162af2b5f135f0735\System.Web.Extensions.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\e3ac0db4995bfca8a7f12afdc5e0602b\System.Web.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\e95c04a954155809c430a0c604a6416e\System.ServiceModel.Internals.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\3e6c997c0f5d4d89a00c29e535fbddfb\System.IdentityModel.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\84f2250c582e8bafeaf4fd9e407ba22a\SMDiagnostics.ni.dll, signer: [unsigned]

    20 hours, c:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsForm0b574481#\088bdb586012457f9e88c8c055b7c42d\WindowsFormsIntegration.ni.dll, signer: [unsigned]

    Errors

    ======

    Problems opening folder 'c:\ProgramData\Microsoft\Windows\SystemData' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Users\MyPC\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\CSC' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Ngc' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    Problems opening folder 'c:\Windows\System32\LogFiles\WMI\RtBackup' to enumerate files. FindFirstFile failed. System error message: Access is denied. Error code: 5.

    End of FreeFixer log

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2016-07-26T07:23:05+00:00

    Thank you very much

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2016-07-25T14:41:22+00:00

    cracked/keygens are one of the fastest ways of infecting your system,  100% of Cracked/KeyGen software contains some form of malicious code.

    Good

    Proshow Producer v-7.0.3527 Full + Patch should be uninstalled/deleted

    These 2 files/folders need to go

    C:\Users\MyPC\Downloads\Proshow Producer v-7.0.3527 Full + Patch\Patch.exe

    C:\WINDOWS\SECOH-QAD.dll

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2016-07-25T13:56:51+00:00

    Emsisoft Emergency Kit - Version 11.0

    Last update: 7/25/2016 8:13:29 PM

    User account: MAYTINH-1Q20GA5\MyPC

    Scan settings:

    Scan type: Malware Scan

    Objects: Rootkits, Memory, Traces, Files

    Detect PUPs: On

    Scan archives: Off

    ADS Scan: On

    File extension filter: Off

    Advanced caching: On

    Direct disk access: Off

    Scan start: 7/25/2016 8:22:49 PM

    C:\Users\MyPC\Downloads\ccsetup519.exe detected: Application.Toolbar (A)

    C:\Users\MyPC\Downloads\Proshow Producer v-7.0.3527 Full + Patch\Patch.exe detected: Dropped:Trojan.Generic.15028225 (B)

    C:\WINDOWS\SECOH-QAD.dll detected: Riskware.NetTool (A)

    Scanned 79103

    Found 3

    Scan end: 7/25/2016 8:27:09 PM

    Scan time: 0:04:20

    Was this answer helpful?

    0 comments No comments