Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Suspected malware or virus.


  • This topic is locked This topic is locked
17 replies to this topic

#1 SobaBruh

SobaBruh

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 12:38 AM

Just got back from a trip and booted up my PC to find the boot up screen taking significantly longer than before which is quite odd. Haven't updated anything since the last time I touched it so I'm quite worried and would like some help to check it out.

 

I ran malwarebytes, rkill, adwcleaner and normal windows scan but nothing came up.

 

I have attached the files from FRST64 for you.

EDIT: Noticed in the Additional file that the Windows Full Scan was stopped. I might have accidentally closed it. That's my bad. Also, uploaded the right text documents this time

Futhur edits: Ran windows scan the full length this time and had nothing come up

Attached Files


Edited by SobaBruh, 20 April 2024 - 04:40 AM.


BC AdBot (Login to Remove)

 


#2 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 06:36 AM

Hello, and welcome to BC Forums. EPFGbk7.gif

I will be assisting you regarding your computer's issues. Here, we will check your computer for malware.

Please, adhere to the guidelines below, and then carefully follow, with the same order, all the instructions after:

1. Always ask before acting. Do not continue if you are not sure, or if something unexpected happens!

2. Do not run any tools unless instructed to do so. Also, do not uninstall or install any software during the procedure, unless I ask you to do so.

3. Cracked or pirated programs are not only illegal, but also can make your computer a malware target. Having such programs installed, is the easiest way to get infected. Thus, no need to clean the computer, since, soon or later, it will get infected again. If you have such programs, please uninstall them now, before we start the cleaning procedure.

4. If your computer seems to start working normally, don't abandon the topic. Even if your system is behaving normally, there may still be some malware remnants left over. Additionally, malware can re-infect the computer if some remnants are left. Therefore, please complete all requested steps to make sure any malware is successfully eradicated from your PC.

5. You have to reply to my posts within 3 days. If you need some additional time, just let me know. Otherwise, I will leave the topic due to lack of feedback. If you are able, I would request you to check this thread at least once per day so that we can resolve your issues effectively and efficiently.

6. Logs from malware diagnostic or removal programs can take some time to get analyzed. Also, have in mind that all the experts here are volunteers and may not be available to assist when you post. Please, be patient, while I analyze your logs.

 

==============

 

Currently reviewing your logs and I'll be back to you as soon as I am ready. 


waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#3 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 07:01 AM

Hi, again.
 
The logs do not show any sign of an active infection. 
 
We are going to do some checks to make sure that everything is fine. Also, some maintenance.
 
You can find below my first comments/instructions:
 
 
1. Java

There are very few reasons these days to continue having Java installed on your computer. However, if you do elect to keep Java, it needs to be updated to the latest version which you can find here: Java SE Runtime Environment 8 - Downloads.
 
For now, please uninstall the out of date version of Java: Java 8 Update 401
 
 
2. FRST fix

Please do the following to run a FRST fix.

NOTICE: This script was written specifically for this user. Running it on another machine may cause damage to your operating system

  • Select the entire contents of the code box below, from the "Start::" line to "End::", including both lines. Right-click and select "Copy ". No need to paste anything to anywhere.
Start::
CreateRestorePoint:
CloseProcesses:
AlternateDataStreams: C:\ProgramData\mntemp:8EAD8B3507 [3442]
S4 AmdTools64; \SystemRoot\System32\drivers\AmdTools64.sys [X]
CMD: DISM /Online /Cleanup-Image /RestoreHealth
CMD: SFC /scannow
EmptyTemp:
End::
  • Right-click on FRST64 on your Desktop, to run it as administrator. When the tool opens, click "yes" to the disclaimer.
  • Press the Fix button once and wait. It will take about an hour. 
  • FRST will process fixlist.txt
  • When finished, it will produce a log fixlog.txt on your Desktop.
  • Post the log in your next reply.

 

 

In your next reply please post:

  1. ​If you successfully uninstalled Java
  2. The fixlog.txt

waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#4 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 07:21 AM

Hi! I appreciate the help. 

I have uninstalled Java and installed the new version as well as attached the fixlog.

 

Attached Files



#5 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 07:29 AM

OK, I expected to take longer. 
 
Actually, I asked you to uninstall Java and not install the latest version yet. Not a big deal now, but please try to follow my instructions carefully.
 
Let's see what an online scan will show us.

Download ESET Online Scanner and save it to your desktop.

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#6 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 07:40 AM

Apologies, didn't realize I should install Java after. 

I ran the ESET as instructed and it had to install an update of some sorts after I hit scan and it abruptly disappeared after it was 2% into the update. I tried running the program again only for it to disappear once more. What should I do now?



#7 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 07:42 AM

For some reason it's working alright for now. It's back on the "Getting ready to scan..." "System is downloading module update...". I will post another reply application closing happens again.



#8 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 07:46 AM

Apologies for spamming the replies. It's not crashing anymore but it keeps going back and forth between 1% and 2%. Should I be restarting my PC and trying to run it again? Or perhaps uninstall Java? Quite confused as to what's going on with it. 



#9 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 07:46 AM

Unfortunately there was a bug with Eset Online Scanner the previous days, and it seems that they didn't fix it yet.
 
We are going to use an alternative tool.

Emsisoft Emergency Kit

  • Download and save the installation file from here: Emsisoft
  • Double-click on the Emsisoft Emergency Kit setup file to start the installation process and then click on the Install button.
  • You may be presented with a User Account Control warning, asking you if you want to run this file. Click Yes to continue.
  • The downloaded package unpacks to “C:\EEK” by default and this folder now opens on your screen.
  • To start Emsisoft, double-click on the Start Emergency Kit Scanner icon in this folder.
  • You may get another User Account Control warning. Click Yes to continue.
  • Accept the Licence Agreement.
  • When you launch the program for the first time, Emsisoft Emergency Kit will automatically download updates. The Scan tab changes from orange to green when the update process is completed.
  • Leave the settings unchanged, which include detection of Potentially Unwanted Programs.
  • Now click on Malware Scan in the Scan button.
  • When the Emsisoft scan has finished, you will see a screen reporting details of any malicious files found on your computer.(Close the pop up inviting installation of Emsisoft protection)
  • Click Quarantine selected objects. (Note, this option is only shown if malicious objects were detected during the scan)
  • You may be asked to restart your computer.
  • When the threats have been quarantined, click the View Report button in the lower-right corner and the scan log will open in Notepad. The logs can also be accessed in the left hand menu bar.
  • Please save this log on your desktop and post the contents into your next reply.
  • When you close Emsisoft Emergency Kit it asks if you wish to sign up for a newsletter. This is optional, and does not affect the malware removal process.

waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#10 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 07:52 AM

We posted our last posts at exactly the same time and didn't see your previous message. 

 

Delete the Eset Scanner from your Desktop, restart and follow the instructions about Emsisoft Emergency Kit. 


waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#11 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 07:56 AM

All good. Did as you said deleted Eset and ran the Emisoft Emergancy Kit as instructed in your previous message. Comes up clean. Nothing detected.



#12 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 08:12 AM

Do you still have issues with your computer? 


waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#13 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 08:17 AM

Things seem to be running a lot more smoothly. Booting up is back to normal as well. If there are no more steps, thank you so much for your help. I would also like to know if there are procedures for uninstalling FRST as well as Emsisoft Emergency Kit as I don't see them in my "add or remove programs". Should I just delete the folder for Emsisoft Emergency Kit and the EXE for FRST64?


Edited by SobaBruh, 20 April 2024 - 08:17 AM.


#14 DR_M

DR_M

    The Grecian Geek


  •  Avatar image
  • Malware Response Team
  • 870 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:24 PM

Posted 20 April 2024 - 08:20 AM

Glad to hear that everything is back to normal now.

The following tool will remove the tools we used as well as reset system restore points:

Download KpRm by kernel-panik and save it to your desktop.

  • Right-click kprm_(version).exe and select Run as Administrator.
  • Read and accept the disclaimer.
  • When the tool opens, ensure all boxes under Actions are checked.
  • Under Delete Quarantines select Delete Now, then click Run.
  • Once complete, click OK.
  • A log will open in Notepad titled kprm-(date).txt.
  • Please copy and paste its contents in your next reply.

Note: If there is a warning about this tool, go on to download it, since it is a false/positive. Choose More info and continue from there.


waKmk76.png    unite.png

 

Grecian Geek

 

Count your blessings, remember your prayers...

 

"In one of the stars I shall be living. In one of them I shall be laughing. And so it will be as if all the stars will be laughing when you look at the sky at night..

You, only you, will have stars that can laugh."


#15 SobaBruh

SobaBruh
  • Topic Starter

  •  Avatar image
  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:24 PM

Posted 20 April 2024 - 08:28 AM

Here you go.
 
# Run at 20/4/2024 9:28:07 pm
# KpRm (Kernel-panik) version 2.17.0
# Run by USER from C:\Users\USER\Downloads
# Computer Name: NORSE
# OS: Windows 10 X64 (19045) (10.0.19045.4291) 
# Number of passes: 1
 
- Checked options -
 
    ~ Registry Backup
    ~ Delete Tools
    ~ Restore System Settings
    ~ UAC Restore
    ~ Delete Restore Points
    ~ Create Restore Point
    ~ Delete Quarantines
 
- Create Registry Backup -
 
   ~ [OK] Hive C:\Windows\System32\config\SOFTWARE backed up
   ~ [OK] Hive C:\Users\USER\NTUSER.dat backed up
 
     [OK] Registry Backup: C:\KPRM\backup\2024-04-20-21-28-07
 
- Delete Tools -
 
 
  ## AdwCleaner
     [OK] C:\AdwCleaner deleted
 
  ## Emisoft Emergency Kit
     [OK] C:\EEK deleted
 
  ## ESET Online Scanner
     [OK] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk deleted
     [OK] C:\Users\USER\AppData\Local\ESET\ESETOnlineScanner deleted
 
  ## FRST
     [OK] C:\Users\USER\Desktop\Fixlog.txt deleted
     [OK] C:\Users\USER\Desktop\FRST64.exe deleted
     [OK] C:\Users\USER\Downloads\Fixlog.txt deleted
     [OK] C:\FRST deleted
 
  ## Rkill
     [OK] C:\Users\USER\Desktop\Rkill.txt deleted
 
- Restore System Settings -
 
     [OK] Reset WinSock
     [OK] FLUSHDNS
     [OK] Hide Hidden file.
     [OK] Show Extensions for known file types
     [OK] Hide protected operating system files
 
- Restore UAC -
 
     [OK] Set EnableLUA with default (1) value
     [OK] Set ConsentPromptBehaviorAdmin with default (5) value
     [OK] Set ConsentPromptBehaviorUser with default (3) value
     [OK] Set EnableInstallerDetection with default (0) value
     [OK] Set EnableSecureUIAPaths with default (1) value
     [OK] Set EnableUIADesktopToggle with default (0) value
     [OK] Set EnableVirtualization with default (1) value
     [OK] Set FilterAdministratorToken with default (0) value
     [OK] Set PromptOnSecureDesktop with default (1) value
     [OK] Set ValidateAdminCodeSignatures with default (0) value
 
- Clear Restore Points -
 
   ~ [OK] RP named Removed AMD Ryzen Master SDK. created at 04/14/2024 10:06:02 deleted
   ~ [OK] RP named Removed Minecraft Launcher created at 04/15/2024 16:38:55 deleted
   ~ [OK] RP named Installed Elgato Stream Deck created at 04/19/2024 04:29:53 deleted
   ~ [OK] RP named Removed Java 8 Update 401 (64-bit) created at 04/20/2024 12:02:41 deleted
     [OK] All system restore points have been successfully deleted
 
- Create Restore Point -
 
     [OK] System Restore Point created
 
- Display System Restore Point -
 
   ~ [I] RP named KpRm created at 04/20/2024 13:28:23
 
-- KPRM finished in 25.85s --


 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users