Jump to content

In task manager there's a virus that keeps appearing after deleting it (Photo 1)

I opened file location it's in c-users-name-appdata-roaming-.  And it's called NFRTHPIBBC.exe

When trying to be deleted a message as in (Photo 2) appears

I searched the hole PC for the file with the name "Port entity ..." with hidden files visible and I found nothing

 

Pls help I'm desperately trying to fix it 4h

15547470204613760925415862881497.jpg

15547472153444064043073718045227.jpg

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/
Share on other sites

Link to post
Share on other sites

You can use is Autoruns

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

 

If theres any key or item associated with it on startup, removing them should stop it from launching on boot and give a few pointers of related residing components.

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464114
Share on other sites

Link to post
Share on other sites

1 minute ago, Sylvie said:

weird question, have you tried renaming the process in your roaming appdata tree?

give that a shot. If it works, restart the system, then delete all the files associated with it.

If it doesn't, does it stop you using the system restore funcionality?

If I rename it after 1 second there will be another created near the edited one

 

And also there are many thing that are running in background that I can kill but they keep appearing at every start up such as : Suffix, Nitration, Dlaxai, Accrediting

15547487258478871849790246176523.jpg

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464116
Share on other sites

Link to post
Share on other sites

3 minutes ago, MariusIonasco said:

If I rename it after 1 second there will be another created near the edited one

 

And also there are many thing that are running in background that I can kill but they keep appearing at every start up such as : Suffix, Nitration, Dlaxai, Accrediting

okay, does it run persistently during safe mode or does that protect you?

You might be able to remove it that way.

 

Malwarebytes anti-malware may also be able to help here.

 

Failing any of these steps, what about a system restore?

 

oh, and for future reference, you can take a capture of the window you've got active with alt+prtscrn, and then just paste it into the reply box.

hi

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464129
Share on other sites

Link to post
Share on other sites

3 minutes ago, Mayushii said:

Another useful tool you can use is Autoruns

https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

 

If theres any key or item associated with it on startup, removing them should stop it from launching on boot and give a few pointers of related residing components.

I panicked when I saw the virus spawn in tons of pages on my screen and I unplugged the Ethernet cord and started safe mode and deleted all files that are created or modified this day

 

Should I plug it back and download the tool , I mean there's a process called accreditation

 

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464134
Share on other sites

Link to post
Share on other sites

2 minutes ago, Sylvie said:

okay, does it run persistently during safe mode or does that protect you?

You might be able to remove it that way.

 

Malwarebytes anti-malware may also be able to help here.

 

Failing any of these steps, what about a system restore?

 

oh, and for future reference, you can take a capture of the window you've got active with alt+prtscrn, and then just paste it into the reply box.

I unplugged the PC from the network I'm doing this on my phone and in safe mode the black what's up thing keeps being invincible for deleting but don't runs in task manager

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464139
Share on other sites

Link to post
Share on other sites

2 minutes ago, MariusIonasco said:

I panicked when I saw the virus spawn in tons of pages on my screen and I unplugged the Ethernet cord and started safe mode and deleted all files that are created or modified this day

 

Should I plug it back and download the tool , I mean there's a process called accreditation

  

if you're worried about connecting to the internet on the infected machine, you could always download some anti-malware tools from another machine and transfer them.

hi

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464140
Share on other sites

Link to post
Share on other sites

2 minutes ago, MariusIonasco said:

I unplugged the PC from the network I'm doing this on my phone and in safe mode the black what's up thing keeps being invincible for deleting but don't runs in task manager

The tool uploads items to virustotal, providing you with a general idea of how suspicious they are. But you can also do it offline and look for anything that stands out.

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464145
Share on other sites

Link to post
Share on other sites

5 minutes ago, MariusIonasco said:

I unplugged the PC from the network I'm doing this on my phone and in safe mode the black what's up thing keeps being invincible for deleting but don't runs in task manager

Oh wait it is deleting in safe mode ,anything is deleting in safe mode except of one file NTUSER.DAT (Photo)

Sorry for screen glaring and quality it gets later and darker at me 

15547501182245426397228322131669.jpg

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464172
Share on other sites

Link to post
Share on other sites

15 minutes ago, Mayushii said:

The tool uploads items to virustotal, providing you with a general idea of how suspicious they are. But you can also do it offline and look for anything that stands out.

Sorry I will use the tool tomorrow (+10h)

Cause it's late at me, I will write the results

 

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464190
Share on other sites

Link to post
Share on other sites

SOLVED

 

Oh F$%* I found it the thing was that at the beginning my windows virus and thread protection was disabled cause it was turned to some enterprises controlled shit. I turned it off in regedit. Then deleted a bunch of files and runned antivirus, but that didn't solved the problem. I started the post,but now I saw that the controlled antivirus made a lot of exclusion folder paths where the main sources are coming, deleted the exclusions and runned the antivirus so it found something like in (Photo) -who wants can protocol that 

 

THANKS for all who participated in the post , but there is one thing the start up processes that I disabled are still there, not running, but I can see them in Task Manager under Start-up

15547510165513180801318563298833.jpg

Link to comment
https://linustechtips.com/topic/1052849-virus-help-pls/#findComment-12464236
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×