wuaudit.exe trojan bitcoinminer and browser homepage redirects to v9.com

hello you didn’t stop your protections like it’s asked for the use of the tool

i’ve turned off any antivirus and firewall
is there anything else?

ok but some actions couldn’t be done…

launch the program again , select “Diag” and attach c:\pre_diag_xx_xx_xx.txt please

done, and i forgot to mention that i always get a error popup on startup (screenshot attached)

uninstall adobe reader 9

==

Selects all text in bold below and then CTRL + C
[b]
Kill::
All

Key::
[HKU\S-1-5-21-1715567821-682003330-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]|[tsiVideo]
[HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Adobe Reader Speed Launcher]
[HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\ApnTBMon]
[HKU\S-1-5-21-1715567821-682003330-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Toolbar]|[Locked]
[HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Toolbar]|[Locked]
[HKU\S-1-5-21-1715567821-682003330-839522115-1003\Software\SMAD?V]
[HKU\S-1-5-21-1715567821-682003330-839522115-1003\Software\Microsoft\QXtVXvpBUVUU87sQGpnUOROd+tux2Icqajs++sYT2YJPUSvBSIG81hWw86iqPUcK]
[HKLM\Software\0]
[HKLM\Software\11]
[HKLM\Software\14cd]
[HKLM\Software\54c]
[HKLM\Software\Trymedia Systems]
[HKLM\Software\ukwxp]
[HKLM\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]|[1900:UDP]
[HKLM\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]|[2869:TCP]
[HKLM\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]|[6112:TCP]
[HKLM\System\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]|[4116:TCP]

File|Fold::
E:\eula.*
E:\install.*
E:\f56d36fabb1ceec4693d90bd75c8
E:\3c9343b22d3eb02378fbff1924
E:\WINDOWS*.tmp
E:\WINDOWS\sys2d
E:\WINDOWS\sys
E:\Documents and Settings\Jessica\Application Data\bitlord_log.txt
E:\Documents and Settings\Jessica\Application Data\WinRARPass*.com
E:\Documents and Settings\All Users\Application Data\xml_param
E:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
E:\Documents and Settings\Jessica\Local Settings\Application Data\WinRARPas*.com

Driver::
WSYSSVC

MBR::
yes

Clean::
yes

Reboot::
yes[/b]

Recovery Pre_scan then choose the “Script” option tool will work instantly
black windows may flash, this is normal, this is the program that works
post Pre_Script_date_hour.txt that appear at the root of the system drive (usually C: ) at the end of work

am I clean now?

I think you didn’t switch off your protections doing the script…

killed the avastsvc.exe before running the script this time

hello ok is there still any problem ?

all seems good now, thank you for your assistance ;D
btw, what was the wuaudit.exe trojan and what’ll it do? i’m a bit curious to what was infecting my computer :-\

hello

I don’t know all the infections but I know destroy them ^^
but you’ve to be care for you navigation and always read before clicking , Especially when you install a program ( lot of things are given with , and it’s not always very good ^^ )

download delfix : http://www.aht.li/2115988/delfix.exe , check all and execute

update flashplayer
update java and deactivate it on your browsers

in fact it’s all written in this page if you understand “Google traduction” ^^ :

http://translate.google.fr/translate?sl=fr&tl=en&js=n&prev=_t&hl=fr&ie=UTF-8&u=http%3A%2F%2Fsecurity-helpzone.com%2Fgen-hackman%2Fnettoyage-en-fin-de-desinfection%2F

thank you once again, i’ll be more careful from now on
i’m so glad that avast anti-virus and malware team helped me :smiley:
and i think i know what program last installed that brings them, the utorrent installation :wink:

yes , In France , if we don’t care , it installs 3 differents toolbars ( if we don’t uncheck ) it’s vicious , cause in the choices , there’s a button witch works to install bad programs and another to decline installation of bad programs but it’s grey … well when you see that , you never think that the grayed button could work…but it works ^^

did you understand ?

it works? lol i never imagined that
seems like a dirty trick, but i get the figure ;D
this should make me more careful when installing something

exactly what I wanted you understand !