Posted 04 June 2012 - 02:08 PM
Just recently I have started receiving messages from Kaspersky indicating they have blocked a malicious URL from loading.
The message reads:
C:\\Windows\Explorer.Exe (PID:5084): Loading Object http:/...?worker.php?action=get%5Fscript%5Fhash...containing malicious URL
hXXp://18.104.22.168/scripts/worker.php?action=get %5F scrips %5hash&ver=1.1
Shortly afterwards, Windows Explorer shuts down and then restarts. This cycle repeats itself continuously.
Full scans using Kaspersky, Malewyrebytes, and Super-Antispyware did not detect anything. Nor did Kaspersky Rootkit Killer, which I was instructed to run by a technician in another forum -- along with Combofix, ESET, GMER and ASWMBR. All failed to detect anything, and the technician who was assisting said he was unable to determine the cause.
Have come here in the hope you can help me.