Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Posible rootkit and who knows what else. [Solved]

win10 rootkit crypto help cryptominer

  • This topic is locked This topic is locked
37 replies to this topic

#31 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 15 May 2020 - 03:15 AM

Thanks but that was not the full log. Please post the complete log.

 

Satchfan


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

    Advertisements

Register to Remove


#32 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 15 May 2020 - 04:12 AM

Wow didn't noticed the upper part was cut, sorry about that.

 

Farbar Service Scanner Version: 14-12-2019
Ran by noise (administrator) on 14-05-2020 at 19:58:55
Running from "C:\Users\noise\Desktop"
Microsoft Windows 10 Home Single Language  (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


System Restore:
============

System Restore Policy:
========================


Security Center:
============


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv: "%systemroot%\system32\svchost.exe -k netsvcs -p".
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => File is digitally signed
C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
C:\Windows\System32\drivers\afd.sys => File is digitally signed
C:\Windows\System32\drivers\tdx.sys => File is digitally signed
C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
C:\Windows\System32\dnsrslvr.dll => File is digitally signed
C:\Windows\System32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\System32\SDRSVC.dll => File is digitally signed
C:\Windows\System32\vssvc.exe => File is digitally signed
C:\Windows\System32\wscsvc.dll => File is digitally signed
C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
C:\Windows\System32\wuaueng.dll => File is digitally signed
C:\Windows\System32\qmgr.dll => File is digitally signed
C:\Windows\System32\es.dll => File is digitally signed
C:\Windows\System32\cryptsvc.dll => File is digitally signed
C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
C:\Windows\System32\ipnathlp.dll => File is digitally signed
C:\Windows\System32\iphlpsvc.dll => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed


**** End of log ****



#33 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 15 May 2020 - 05:06 AM

That all seems to be fine and shows no connection problems.

 

If you're happy that all else is well, I''ll send instructions to tidy up here and you can start a topic in our Networing forum.


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#34 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 15 May 2020 - 05:13 PM

Hello and yes, I am more than grateful for everything you have done.

Anything I should know/look up for?



#35 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 15 May 2020 - 05:38 PM

I am more than grateful for everything you have done.

You're welcome.

 

Your computer appears to be clean. Now that it seems to be running well, please follow these steps to tidy up and decrease the likelihood of getting infected again:

Uninstall FRST

  • right-click on FRST.exe/FRST64.exe and select Rename
  • rename the file to Uninstall.exe
  • double-click on Uninstall.exe – this will uninstall FRST

===================================================

Uninstall AdwCleaner

  • open adwcleaner.exe
  • click on Settings
  • click on the Application tab and scroll down to the bottom
  • click on Remove.

===================================================

Uninstall remaining programmes

To check for any leftover installed tools press the Windows Key + R at the same time, then type appwiz.cpl then Enter.

You can uninstall any programmes we used that still remain:

You can also delete all other logs and programmes we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Recommended

Download the current version of Malwarebytes from here. This really is an excellent program that you should update and run on a regular basis, probably weekly.

===================================================

I also recommend that you read the following:

Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams

Answers to Common Security Questions - Best Practices by quietman7

How Malware Spreads - How Did I Get Infected by quietman7

I will keep this open for 24 hours in case you have any problems, after which I’ll close the topic.

Safe computing

Satchfan

 

 


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#36 GatoTuerto

GatoTuerto

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 15 May 2020 - 06:31 PM

Everything has been done and cleaned.

I thank you a lot for your assistance and patience, god bless you.



#37 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 15 May 2020 - 06:45 PM

god bless you.

And you. Stay safe.

 

Regards

 

Nina (Satchfan)


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#38 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,813 posts
  • Interests:LFC, music, more LFC, more music

Posted 18 May 2020 - 02:37 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatth...ed_t106388.html
and start a New Topic.


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

Related Topics




Also tagged with one or more of these keywords: win10, rootkit, crypto, help, cryptominer

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users