Problems posible trojan

Page 1 of 2 12 LastLast

  1. Posts : 39
    Win 10
       #1

    Problems posible trojan


    Having problems..I couldn't open sites on FF..I can't recall exactly what it said but was something like the site was not set up properly & wasn't safe. FF could not connect. I ran Unhack-me & can move around but there are many problems shown on Rkill. I would be thankful for help.
      My Computer


  2. Posts : 39
    Win 10
    Thread Starter
       #2

    here are the two Rkill files...Rkill 1 is before I ran unhackme..Rkill 2 is after..it looks messed up.. please help!
    Problems posible trojan Attached Files
      My Computer


  3. Posts : 16,325
    W10Prox64
       #3

    Hi.
    Couple things:
    First of all, you answered your own thread, so it's not sitting in the "unanswered queue" anymore.
    Secondly, you marked it as solved, which tells everyone you no longer need help.

    Here is what I would recommend. Run these programs in the order I give them:

    RKILL (free)
    Download RKill

    ADWCleaner (free)
    (Post the logs. It will have you reboot first)
    Downloads - AdwCleaner - ToolsLib

    RKILL again
    (because everything RKILL does is undone by a reboot)

    Malwarebytes Antimalware (free) FULL SCAN
    (be sure to tick the box in settings to scan for rootkits!)
    (post the log)
    Free Anti-Malware & Malware Removal | Malwarebytes

    Ccleaner (free)
    Download CCleaner | Clean, optimize tune up your PC, free!
    Run this cleaner on all your browsers and clear everything out. If you save passwords in your browsers, back them up first.
    Then RESET ALL Browsers on the system (not just the ones you use, but all of them, especially Internet Explorer).
    Reset Microsoft Edge to Default in Windows 10 | Windows 10 Tutorials

    How to Reset Your Web Browser To Its Default Settings

    Then, back in Ccleaner, go into Tools>Uninstall and remove any toolbars or rogue apps you find.
    Then run it on your registry, ticking all boxes except Help Files.

    Open an Admin Command Prompt and clear your DNS
    Code:
    ipconfig /flushdns
    You have 728 entries in your HOSTS file. Can you please explain?
    If there is any illegal software on the system, please uninstall it now.
    Check that Windows Update is now running, and your AV also (whatever you use).

    Open an Admin Command Prompt and run the System File Checker, by entering
    Code:
    sfc /scannow
    Once it is finished, you should see "No integrity violations found". If it says found and fixed, or found and couldn't fix, reboot and run it again, up to 3 times.

    Report back here and we'll see how things are going.
      My Computer


  4. Posts : 39
    Win 10
    Thread Starter
       #4

    Thanks Simrick for the reply...I'll try to explain the confusion later...here are the first set of logs. I'll make sure these send then reboot.
    Problems posible trojan Attached Files
      My Computer


  5. Posts : 39
    Win 10
    Thread Starter
       #5

    Here is the last rkill & mbytes..I think I've completed all items...on the first post, it was all my confusion...I was your reply & was so thankful because I was getting ready to format. I don't know why all the hosts were on rkill ..they hadn't shown up before...please let me know if there is anything else I need to do...
    Problems posible trojan Attached Files
      My Computer


  6. Posts : 39
    Win 10
    Thread Starter
       #6

    Thank you once again Simrick..you save me a lot of trouble..kudos to you & 10forums
      My Computer


  7. Posts : 16,325
    W10Prox64
       #7

    Thank you for the logs.
    Nothing looking to terribly bad in there (except slim cleaner, which is considered a PUP).
    I'd like to see a FULL SCAN though, and not just a threat scan from MBAM, with Rootkits box checked.

    1. Have you confirmed Windows Update is working?
    2. What Anti-Virus program do you use, and have you confirmed that it is functioning correctly (Windows Defender is disabled).
    3. What were the results of the system file checker scan?

    If you have completed all the steps and are no longer having any issues with FF, I think you are good to go. But, if you are still having issues, we'll need to take a deeper look.
      My Computer


  8. Posts : 16,325
    W10Prox64
       #8

    One more thing:
    Unless you or your legitimate apps have specifically made those changes to your HOSTS file, I would reset it. MS have instructions here:
    https://support.microsoft.com/en-us/...to-the-default

    Or you can use this tool
    Downloads - RstHosts - ToolsLib

    Here you can read a little more on the subject, if you like:
    How can I reset the Hosts file back to the default in Windows 10? - Windows 10 Support

    .
      My Computer


  9. Posts : 39
    Win 10
    Thread Starter
       #9

    Thank you simrick..on mbam I did have rootkits checked..I didn't see any way to run a scan...I'm using a version I just upgraded from mbytes, so i'm installing the one you sent just in case.
    1. I went to windows update & clicked on update ...it began looking...not sure how to check any other way.
    2. I use Avast...it opens & I don't notice anything amiss...When I go to update/security there is no windows defender listed so I didn't know how to turn on or off realtime protection
    3. The SFC indicated no integrity violations found.
    4. Hit Man finds the file SVC host...listed as suspicious.
    I will take care of the host as you have directed
    I have also attatched an mbam txt from the mbam that you sent.
    I think that covers it all.
    Problems posible trojan Attached Files
      My Computer


  10. Posts : 16,325
    W10Prox64
       #10

    10beers said:
    Thank you simrick..on mbam I did have rootkits checked..I didn't see any way to run a scan...I'm using a version I just upgraded from mbytes, so i'm installing the one you sent just in case.
    1. I went to windows update & clicked on update ...it began looking...not sure how to check any other way.
    Okay good - that's fine.

    10beers said:
    2. I use Avast...it opens & I don't notice anything amiss...When I go to update/security there is no windows defender listed so I didn't know how to turn on or off realtime protection
    Defender will be disabled by Avast to prevent conflicts. Turning off Avast shields will turn off real-time protection.

    10beers said:
    3. The SFC indicated no integrity violations found.
    Great.

    10beers said:
    4. Hit Man finds the file SVC host...listed as suspicious.
    Hmmm....Please provide the logs for this?

    10beers said:
    I will take care of the host as you have directed
    Good.

    10beers said:
    I have also attatched an mbam txt from the mbam that you sent.
    I think that covers it all.
    Thanks - looks good, but still only a Threat Scan. Still, since you're on the trial, you have active protection from MBAM for about 2 weeks, so that makes me feel better, while we determine what Hitman has flagged.

    One thing: please run winver from the search box and post a screenshot of what version Windows you have running on there. Hopefully you're already on v1803...

    For a Full MBAM scan:

    Problems posible trojan-image.png


    Problems posible trojan-image.png
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:14.
Find Us




Windows 10 Forums