Windows 10: Weird behavior, possible Trojan

  1.    08 Feb 2017 #1

    Weird behavior, possible Trojan


    Symptoms:
    1. Volume icon appears with a red cross even though all sound devices are working.
    2. With UAC set to default, a notification pops up at startup asking my permission to run explorer.exe
    3. I can't run some programs.
    4. Malwarebytes web protection suddenly disabled and can't be re-enabled. I'm using the latest one.
    5. System restore fails all the time, so can't go that path either.

    I suspect it is malware that targets/makes a fake explorer.exe, but not entirely convinced since there is only one instance and the CPU load is not constantly high. but I want to know if anyone has encountered this before and might point me int the right direction, like the name of the malware, perhaps.

    Thanks, everyone!
      My System SpecsSystem Spec

  2. Bree's Avatar
    Posts : 1,731
    10 Home x64 (1607), Pro x86 (1511 & 1607)
       08 Feb 2017 #2

    frankmanguiob said: View Post
    4. Malwarebytes web protection suddenly disabled and can't be re-enabled. I'm using the latest one.
    Welcome to TenForums @frankmanguiob

    Have you tried a scan with Malwarebyte Chameleon? If you are using 3, see:
    Malwarebytes | Chameleon - Free Malware Removal Tool

    There's also Defender Offline.
    Windows Defender Offline Scan in Windows 10
      My System SpecsSystem Spec

  3.    08 Feb 2017 #3

    frankmanguiob,

    Welcome to TenForums!

    You can give this tool a try to see what it finds...

    Please use the Farbar Recovery Scan Tool Download
    Save FRST to your Desktop.
    [Note: You need to run the version compatible with your system: 32 bit or 64 bit]

    Double-click FRST to run it.
    When the tool opens click Yes to the disclaimer.
    Next, press the Scan button.

    When done, the tool makes a log (FRST.txt) on the Desktop.
    Also, the first time the tool is run, it makes another log: (Addition.txt).

    Please attach both reports in your reply.


    Note: FYI, MBAM v3 has experienced problems lately.
      My System SpecsSystem Spec

  4.    09 Feb 2017 #4

    @Bree

    Thanks! Chameleon ran but it didn't detect anything. Defender offline doesn't work for some reason. I can't even view event logs.
      My System SpecsSystem Spec

  5.    09 Feb 2017 #5

    -duplicate-
      My System SpecsSystem Spec

  6.    09 Feb 2017 #6

    -duplicate-
      My System SpecsSystem Spec

  7.    09 Feb 2017 #7

    Hi cottonball,

    Thanks!

    Please see the attached.

    Cheers,
    Frank
    Weird behavior, possible Trojan Attached Files
      My System SpecsSystem Spec

  8.    11 Feb 2017 #8

    frankmanguiob,

    My apology for the delay. Can't remember getting a notification of your reply.

    Looked at the reports provided, and did not see malware.

    You may want to run a System File Check on the OS:
    SFC Command - Run in Windows 10

    Use: Option Three

    If you see: Windows Resource Protection found integrity violations

    Then, please reboot, and run the sfc /scannow command again.

    Sometimes it takes running the sfc /scannow command up to 3 times before all is fixed.

    If no luck, and still looking at integrity violation, please use Option Five: To View Only the "SFC" Scan Results from the CBS.LOG

    Next, attach the sfcdetails.txt in you reply for someone to look at.
      My System SpecsSystem Spec


 

Related Threads
Solved Trojan or not ? in AntiVirus, Firewalls and System Security
Hi all, Not quite sure when this started but roughly somewhere around July I noticed a file called NTUSER.rhk that resides in "Users\My username". Googling for the .rhk file extension gave me a bit of a scare as most sites suggest this is...
The only reason I'm using Windows at all, (and not using Linux), is Windows is the only OS that's "handicap accessible" for people with my type of eye problems. I have very poor eyesight... and without the magnifier, I can't use the computer at...
Weird behavior after update in General Support
I had a recent update of win10. After that everything is ok except when I launch applications a small window with an html file open with the buttons save and open. If I open they open in the browser but nothing happen if I save them the same because...
Solved Do I Have A Trojan? in AntiVirus, Firewalls and System Security
Hello, First post here :) Lately my Windows Defender is finding a Trojan in the Recovery D (Trojan:Win32/Dynamer!ac) It only shows up after a full 3 hour search and not in the fast search A full search with Malwarebytes, Adware and Hitman...
Weird windows 10 behavior in General Support
Just wonder if anyone has encountered these behaviors? It happens to me every time without exception: If I do a restart, the computer restarts but makes the windows 7-start sound. Upon getting to the desktop, the laptop battery meter is missing...
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd
All times are GMT -5. The time now is 17:01.
Find Us
Twitter Facebook Google+ Ten Forums iOS App Ten Forums Android App



Windows 10 Forums