Jump to content

Malware!!!!!

alexnt

I have this problem:

I have scanned with mbam, adwcleaner, junkware removal tool and tdsskiller. They detect malware so I remove the threats BUT when I reboot the task scheduler says "the remote computer was not found". The service is stopped and when I 2click it is greyed out. Then I change task scheduler service start to automatic in registry and I reboot. When I scan with the above softwares they detect the exact same threats.

 

Capture.PNG

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, itsmyjobtoknow said:

t....or format the machine and install a fresh copy of Windows

agree. wipe the system clean and start over. If you have windows 10, this will be quickly done.

PC: AMD Ryzen 5 3600 @4.2HGhz 1.25V || Noctua NH-U12S SE2 || 16GB (2×8GB) Aegis 3000Mhz CL16 @3200Mhz || 
|| Sapphire Pulse RX 6700 10G || MSI B450i Gaming PLUS MAX Wifi
  || Kingston NV1 2TB m.2 ||  Corsair SF600 || Intertech IM 1 |||
Peripherals: Sennheiser PC  360 G4ME || AOC CQ27G2U || Viewsonic PX701HD || Keychron V1 || Logitech G303 Shroud Edition||| Laptop: XPS 13 2in1 7390 || Steam Deck 256 GB (64GB Version) ||| Cameras: Fujifilm XH-1 || Fujifilm X100T

 

 

Elite 110 build log (update:05/15/2018)

Link to comment
Share on other sites

Link to post
Share on other sites

Holy crap how does one get such a bad infection?

I would just reinstall, no other way to get 100% clean

Link to comment
Share on other sites

Link to post
Share on other sites

I would run ADWCleaner and see if it detect the same thing. 
Then run System File Checker.

Of course a OS reinstall is better if you have the time to do that but i prefer to seek & destroy those things myself.

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

when you have a clean install then download avast or something that will atleast try keeping it clean

Main build
CPU: i7 5820k  MotherBoard: Gigabyte x99 UD4  RAM: corsair ballistix 2400mhz 4x4gb  GPU: Asus GTX 970  PSU: corsair rm1000  SSD 1: Samsung 840evo 500gb  SSD 2: Samsung 850evo 500gb  HDD: Western Digital red 3tb  Case: Phanteks Enthoo pro M  CPU cooler: corsair h80i

 

Second build
CPU: i7 5820k  MotherBoard: Gigabyte x99 UD5 WIFI  RAM: G.skill 2666mhz 4x4gb  GPU: Nvidia GTS 450 (soon to be upgraded)  PSU: corsair HX650  SSD: Samsung 850evo 250gb  Case: Cooler Master 430 elite  CPU cooler: Cooler Master hyper 212 evo

 

Third build

CPU: xeon x5690  MotherBoard: Evga x58 classified 4way-sli  Ram: Patriot 1600mhz 4x3gb  GPU: Asus HD6970  PSU: fractal newton r2 1000w  SSD: crucial m500 240gb  Case: Cooler Master Haf X  CPU cooler: Mega Shadow

Link to comment
Share on other sites

Link to post
Share on other sites

I have an ISO of the software geeksquad uses to remove viruses and such.  You can give that a try if you don't want to reformat

download here: https://drive.google.com/open?id=0B6RdaXFnwpG5Ui1oV29TdGF3RTg

CPU: AMD FX-6100 3.3GHz 6-Core OEM/Tray Processor + Antec Kuhler H2O 620 Liquid CPU Cooler
Motherboard: Asus Sabertooth 990FX ATX AM3+ Motherboard Memory: G.Skill Ripjaws X Series 16GB (4 x 4GB) DDR3-1866 Memory
Storage: Kingston HyperX 3K 120GB 2.5" Solid State Drive + Western Digital Caviar Green 500GB 3.5" 5400RPM Internal Hard Drive & Seagate Barracuda 750GB 3.5" 7200RPM Internal Hard Drive
Video Card: MSI GeForce GTX 960 2GB Video Card Case: Rosewill THOR V2 ATX Full Tower Case + Thermaltake TR2 750W 80+ Bronze Certified Semi-Modular ATX Power Supply
Wireless Network Adapter: TP-Link TL-WDN4800 802.11a/b/g/n PCI-Express x1 Wi-Fi Adapter Monitor: Asus VK278Q 27.0" Monitor

Peripherals: Razer DeathStalker Wired Gaming Keyboard + Razer Abyssus Wired Optical Mouse Headphones: Bose SIE2i Orange Earbud Headphones + Mic: Kaxidy Stereo MIC

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, xAcid9 said:

I would run ADWCleaner and see if it detect the same thing. 
Then run System File Checker.

Of course a OS reinstall is better if you have the time to do that but i prefer to seek & destroy those things myself.

 

Doesn't nuking the entire OS count as a form of seek & destroy?

Link to comment
Share on other sites

Link to post
Share on other sites

Holy smokes, what did you browse to get all that malware o.O

PC - NZXT H510 Elite, Ryzen 5600, 16GB DDR3200 2x8GB, EVGA 3070 FTW3 Ultra, Asus VG278HQ 165hz,

 

Mac - 1.4ghz i5, 4GB DDR3 1600mhz, Intel HD 5000.  x2

 

Endlessly wishing for a BBQ in space.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, itsmyjobtoknow said:

 

Doesn't nuking the entire OS count as a form of seek & destroy?

that only destroy, no seek and no fun.

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, itsmyjobtoknow said:
1 hour ago, itsmyjobtoknow said:

You have, in my eyes at least, two options...either get a stronger anti-virus software installed and to get rid of it....or format the machine and install a fresh copy of Windows

I have eset smart security alreadi installed but it detected nothing!

1 hour ago, HydraGaming said:

Holy crap how does one get such a bad infection?

I would just reinstall, no other way to get 100% clean

I downloaded a file from a private tracker that was supposed to give direct links to all windows versions iso.

1 hour ago, Arokhantos said:

Doing scan in windows safe mode usually can fix things, even couple of them if does't become less infected after 2e or 3e scan then wipe it, make sure whatever you install or use ain't infected either, you might be reinstalling it without realising its the source of the infection.

Done it already in safe mode

1 hour ago, xAcid9 said:

I would run ADWCleaner and see if it detect the same thing. 
Then run System File Checker.

Of course a OS reinstall is better if you have the time to do that but i prefer to seek & destroy those things myself.

Done it already

1 hour ago, ShaunC said:

I have an ISO of the software geeksquad uses to remove viruses and such.  You can give that a try if you don't want to reformat

download here: https://drive.google.com/open?id=0B6RdaXFnwpG5Ui1oV29TdGF3RTg

I ll give a try

 

Link to comment
Share on other sites

Link to post
Share on other sites

I believe that the task scheduler service triggers the infection!!!!

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, ganja7 said:

I believe that the task scheduler service triggers the infection!!!!

Which? Mind taking screenshot of the Action tab?

| Intel i7-3770@4.2Ghz | Asus Z77-V | Zotac 980 Ti Amp! Omega | DDR3 1800mhz 4GB x4 | 300GB Intel DC S3500 SSD | 512GB Plextor M5 Pro | 2x 1TB WD Blue HDD |
 | Enermax NAXN82+ 650W 80Plus Bronze | Fiio E07K | Grado SR80i | Cooler Master XB HAF EVO | Logitech G27 | Logitech G600 | CM Storm Quickfire TK | DualShock 4 |

Link to comment
Share on other sites

Link to post
Share on other sites

15 minutes ago, xAcid9 said:

Which? Mind taking screenshot of the Action tab?

The windows task scheduler service. I ll send a photo later.

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Arokhantos said:

Their probably a task scheduled that needs to be removed, if you still trying to remove it then i suggest doing this while having the machine disconnected from the internet and use another system to post etc, backdoor cannot function if it has no internet acces.

I believe that it is not functional right now because I have removed it with mbam and not run task scheduler which is what triggers it.

I ve been scanning and removing for many hours but whenever I change task schdl status to auto it regenarates. I dont believe that I can remove it completely. I will dual boot to linux now as you suggested not to use windows online and make a fresh install the next days.

Link to comment
Share on other sites

Link to post
Share on other sites

I tried to boot kaspersy rescue disk but when it is loading(graphics mode) it stops with kernel panic error.

Link to comment
Share on other sites

Link to post
Share on other sites

Have you tried navigating to the location of the malicious files and manually deleting them? Also try pressing (Windows Key)+R and typing in msconfig, Windows 10 has this in task manager.  Look at start up, is there anything you don't recognize? If so disable it (This will require a reboot). But before you reboot, set up your AV to run a scan on boot this could help us kill the malware prior to it locking the processes. Look up malware analysis pieces online e.g. http://vms.drweb-av.de/virus/?i=3764676

Link to comment
Share on other sites

Link to post
Share on other sites

23 hours ago, target51 said:

Have you tried navigating to the location of the malicious files and manually deleting them? Also try pressing (Windows Key)+R and typing in msconfig, Windows 10 has this in task manager.  Look at start up, is there anything you don't recognize? If so disable it (This will require a reboot). But before you reboot, set up your AV to run a scan on boot this could help us kill the malware prior to it locking the processes. Look up malware analysis pieces online e.g. http://vms.drweb-av.de/virus/?i=3764676

You are the man!!! I manually deleted 3 rar files in program files/common files/microsoft system/serviceprofiles. Probably antimalware didnt have access to compressed files and could not detect them as threats. I also deleted the associated keys in registry.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, ganja7 said:

You are the man!!! I manually deleted 3 rar files in program files/common files/microsoft system/serviceprofiles. Probably antimalware didnt have access to compressed files and could not detect them as threats. I also deleted the associated keys in registry.

No problems bud. Now i highly recommend that you keep running a full scan daily for 90 days to ensure that it definitely has not persisted. In addition to this make sure that you reset all of your login creds and enable dual factor authentication on them (if you can). Finally, learn from your mistake, most malware makes it onto a machine due to social engineering, be skeptical and above all if it looks dodgy then research! 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×