Search the Community
Showing results for tags 'ivaljsim'.
If anyone is running PokerStars.net on their PC, they have installed a hack that will run in the background even when your not running Pokerstars. It will open 2 sessions of Internet Explorer in the background and send them information without your knowledge. If you run HiJackThis you will see one of the hack softwares ivaljsim which needs to be removed. There are 2 pieces to this. ivaljsim.exe and vpknu.exe which they put into "Application Data\Microsoft\Ivaljsim\ivaljsim.exe" and "Application Data\Microsoft\vpknu\vpknu.exe". These need to be removed as well in safemode. You will also need to eliminate the entries it puts in your register. I removed the Pokerstars software as well. I had to use HitmanPro to find it. I manually eliminated it from all of the places but everything looks good now.
Has anyone run across this yet? This keeps getting back into my system after I have gone through and cleaned it out from top to bottom. Malwarebytes will not detect it but I was able to find it with Hitman Pro. What it does is run ivaljsim.exe and starts up 2 sessions of iexplorer in your task manager sending who knows what... I ran Hijackthis and found this which I cleaned up as well. O4 - HKCU\..\Run: [jgyoludb] "C:\Documents and Settings\Larry Williams\Application Data\Microsoft\Ivaljsim\ivaljsim.exe" The Trojan is that one as well as: O4 - HKCU\..\Run: [jgyoludb] "C:\Documents and Settings\Larry Williams\Application Data\Microsoft\vpknu\vpknu.exe" I searched google for all of this and came up with nothing. I can't seem to find where this keeps getting in... After I clean it up, it's fine for a couple of hours, then right back again. hijackthis.log