Password reset and notification emails are now sending correctly.
If you recently requested a password reset, please check your inbox (and spam folder just in case).
You can now reset your password and log in as normal.
Welcome back to PCHF, and thank you for your patience during our migration process!
— The PCHF Team
Welcome to PC Help Forum!
You’re viewing our community as a guest.
That means you can browse posts, but can’t yet reply or start new topics.
Join us today — it's completely free!
As a member, you'll be able to:
✅ Get personalized tech support from trusted volunteers
🦠 Work one-on-one with our Malware Removal Specialists
Hi my computer is infected with RAT (remote access trojan).
It survives after OS re-installation.
And i think it’s active before Windows loads.
What to do guys?
Thanks.
Avira Security with Geek Uninstaller, you can reinstall after this process is complete but the built in windows defender should be adequate.
Also, run the Mcafee removal tool.
Download AV block remover .
Unzip to your desktop, Right click run as admin and follow the instructions. If it does not start, rename the AVbr.exe file to, for example, AV_br.exe
Click yes to reset hosts file.
After the machine reboots then there will be a logfile in the new folder created, post that please.
Download Autologger to your desktop.
Disable your Anitivirus/Defender prior to running.
[ul]
[li]Unzip it there. – If you are unsure how to unzip a program, then use ---- http://www.7-zip.org/ ----[/li][li]Right click Autologger and run as admin. (Xp user double click)[/li][li]AVZ4 will open and scan your machine, allow this to complete.[/li][li]Upload Collectionlog.zip to your next reply.[/li][/ul]
Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
Once you have started the program, you will need to click the scanner button.
[COLOR=rgb(184, 49, 47)]The program will close all open browsers!
Once the scan is completed, the you will want to click the Repair button.
At the end of the process you may be asked to reboot your machine.
After you reboot a report will open on your desktop.
Attach the report here in your next reply.
@puki
Download ClearLNK
Save to your desktop.
Drag and drop the attached text log onto ClearLNK program.
[IMG alt=" move.gif"]http://dragokas.com/tools/move.gif
Navigate to [COLOR=rgb(184, 49, 47)]C:\Users\TeaTang\Desktop\AutoLogger\AV\av_z.exe and right click and run as Admin the AVZ program. (Inside of Autologger folder)
Go To File.
Then to troubleshooting wizard.
Under Issue type select system issues.
Under dangerousness level select All issues.
Click start.
Once complete.
Then tick each box.
Then click the fix selected issues button, then reboot your machine.
In AVZ after fixing the issues you will see…
[ATTACH type=“full”]10628[/ATTACH]
Click that to reboot, if it is not seen then close out AVZ and reboot manually.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\44323732.sys => removed successfully
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\network\44323732.sys => removed successfully
C:\Windows\system32\tasks\Microsoft\Windows\Remote Assistance\RemoteAssistanceTask => moved successfully
C:\Windows\system32\tasks\Microsoft\Windows\HelloF ace\FODCleanupTask => moved successfully
C:\Windows\system32\tasks\KpRm-quarantines\KpRm-quarantines-20220826161858 => moved successfully
C:\Program Files (x86)\Avira => moved successfully
C:\ProgramData\Comodo => moved successfully
C:\Program Files (x86)\Comodo => moved successfully
C:\ProgramData\ByteFence => moved successfully
C:\Program Files\ByteFence => moved successfully
C:\Windows\system32\drivers\trufos.sys => moved successfully
C:\Windows\SYSWOW64\eEmpty.exe => moved successfully
C:\ProgramData\MicroWorld => moved successfully
C:\Program Files\stinger => moved successfully
C:\ProgramData\HitmanPro => moved successfully
C:\ProgramData\Avast Software => moved successfully
HKLM\Software\Classes*\ShellEx\ContextMenuHandlers \SystemSpeedupFilesMenu => not found
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHan dlers\ContextMenu => removed successfully
HKLM\Software\Classes\CLSID{ee10d625-cc60-30a4-b3df-4b349785be6b} => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx \ContextMenuHandlers\ContextMenu => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMen uHandlers\SystemSpeedupFoldersMenu => not found
HKLM\Software\Classes\Directory\Background\ShellEx \ContextMenuHandlers\SystemSpeedupDesktopMenu => not found
HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mfehidk => not found
HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mfehidk.sys => not found
HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mfetdi2k => not found
HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mfetdi2k.sys => not found
HKLM\System\CurrentControlSet\Control\SafeBoot\Net work\mfevtp => not found
“HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run\qBittorrent” => removed successfully
“HKU\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \qBittorrent” => not found
HKLM\SOFTWARE\Microsoft\Windows Defender\DisableAntiSpyware => Error setting value.
HKLM\SOFTWARE\Microsoft\Windows Defender\DisableAntiVirus => Error setting value.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\ProgramData\NTUSER.pol => moved successfully
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{38CE31F 4-1C2B-4679-A63F-83DB4B5E7BC8}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Maintena nce” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Maintenance” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{38CE31F 4-1C2B-4679-A63F-83DB4B5E7BC8}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Maintena nce” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Maintenance” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{38CE31F 4-1C2B-4679-A63F-83DB4B5E7BC8}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Maintena nce” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Maintenance” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{47A1447 9-1D83-45CA-A720-9E25A27BE9DA}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Systray” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Systray” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain{A3D9335 C-AA7E-4742-B013-61183002822F}” => removed successfully
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{A3D9335 C-AA7E-4742-B013-61183002822F}” => removed successfully
“C:\Windows\System32\Tasks\KpRm-quarantines\KpRm-quarantines-20220826161858” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KpRm-quarantines\KpRm-quarantines-20220826161858” => removed successfully
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{B95F1A9 C-D91F-4AD1-B562-BE401F428A20}” => not found
“C:\Windows\System32\Tasks\AviraSystemSpeedupVerif y” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AviraSys temSpeedupVerify” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{E2D7DD7 2-64F2-4883-AA07-0917F7B231CC}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Update” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Update” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks{F348475 9-1416-4EEC-A319-56BADEAEBC5A}” => not found
“C:\Windows\System32\Tasks\Avira_Security_Service_ SCM_Watchdog” => not found
“HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avira_Se curity_Service_SCM_Watchdog” => not found
“C:\Program Files (x86)\Avira” => not found
“C:\Windows\system32\mfevtps.exe” => not found
“C:\Windows\System32\DRIVERS\BdSentry.sys” => not found
“C:\Windows\System32\drivers\mfehidk.sys” => not found
“C:\Windows\System32\drivers\mferkdet.sys” => not found
“C:\Windows\System32\drivers\netprotection_network _filter.sys” => not found
“C:\Windows\System32\DRIVERS\rtp_filesystem_filter .sys” => not found
“C:\Windows\system32\DRIVERS\rtp_process_monitor.s ys” => not found
“C:\Windows\system32\DRIVERS\rtp_traverse.sys” => not found
“C:\Windows\System32\drivers\trufos.sys” => not found
HKLM\System\CurrentControlSet\Services\aswbdisk => removed successfully
aswbdisk => service removed successfully
netprotection_network_filter2 => service not found.
VirusTotal: C:\Windows\QIII.INI => VirusTotal
VirusTotal: C:\Windows\system32\drivers\6247C596.sys => VirusTotal
“HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curre ntVersion\Uninstall\Avira Phantom VPN” => not found
“HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curre ntVersion\Uninstall\Avira Security_is1” => not found
“HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\Curre ntVersion\Uninstall\Avira System Speedup_is1” => not found
========= net stop bits =========
The Background Intelligent Transfer Service service is stopping..
The Background Intelligent Transfer Service service was stopped successfully.
========= End of CMD: =========
“C:\ProgramData\Microsoft\Network\Downloader\qmgr* .db” moved successfully to C:\ProgramData\Microsoft\Network\Downloader\qmgr*. db.old
========= net start bits =========
The Background Intelligent Transfer Service service is starting.
The Background Intelligent Transfer Service service was started successfully.
========= End of CMD: =========
========= bitsadmin /list /allusers =========
BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.
C:\Windows\Temp\HighPerformancePlan.log => moved successfully
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\PowerPlan.log => moved successfully
C:\Windows\Temp\Uninstall Log 2022-10-01 #001.txt => moved successfully
C:\Windows\Temp\Uninstall Log 2022-10-01 N001 DLL.txt => moved successfully
C:\Windows\Temp\UsoStoreFile.xml => moved successfully
========= End → “C:\Windows\Temp*.*” ========
=========== “C:\WINDOWS\system32*.tmp” ==========
not found
========= End → “C:\WINDOWS\system32*.tmp” ========
=========== “C:\WINDOWS\syswow64*.tmp” ==========
not found
========= End → “C:\WINDOWS\syswow64*.tmp” ========
=========== EmptyTemp: ==========
FlushDNS => completed
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8617636 B
Java, Discord, Steam htmlcache => 224791196 B
Windows/system/drivers => 83790184 B
Edge => 3608978 B
Firefox => 0 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 603126000 B
systemprofile32 => 603126000 B
LocalService => 603158754 B
NetworkService => 603175278 B
TeaTang => 615281296 B
RecycleBin => 0 B
EmptyTemp: => 3.1 GB temporary data Removed.
About Zhp Cleaner i pressed the ‘‘scanner’’ button.
After the scan was completed i clicked on the ‘‘repair’’.
But when the program finished i wasn’t asked to restart the machine.
And got only those reports :
~ ZHPCleaner v2022.9.27.78 by Nicolas Coolman (2022/09/27)
~ Run by TeaTang (Administrator) (02/10/2022 21:31:10)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : ZHP
~ State version : Version OK
~ Type : Scan
~ Report : C:\Users\TeaTang\Desktop\ZHPCleaner (S).txt
~ Quarantine : C:\Users\TeaTang\AppData\Roaming\ZHP\ZHPCleaner_Re g.txt
~ System Restore Point :
~ UAC : Activate
~ Boot Mode : Normal (Normal boot)
Windows 10 Pro, 64-bit (Build 17134)
—\ Alternate Data Stream (ADS). (0)
~ No malicious or unnecessary items found.
—\ Services (0)
~ No malicious or unnecessary items found.
—\ Browser internet (0)
~ No malicious or unnecessary items found.
—\ Hosts file (1)
~ The hosts file is legitimate (21)
—\ Scheduled automatic tasks. (0)
~ No malicious or unnecessary items found.
—\ Explorer ( File, Folder) (6)
FOUND file: C:\Users\TeaTang\Downloads\DiscordSetup.exe [Discord Inc. - Discord - https://discord.com/ ] =>.SUP.Discord
FOUND file: C:\Documents and Settings\TeaTang\Downloads\DiscordSetup.exe [Discord Inc. - Discord - https://discord.com/ ] =>.SUP.Discord
FOUND folder: C:\Users\TeaTang\AppData\Roaming\Microsoft\Windows \Start Menu\Programs\Discord Inc =>.SUP.Discord
FOUND folder: C:\Users\TeaTang\AppData\Local\Popcorn-Time\node_modules =>.SUP.PopcornTime
FOUND folder: C:\Users\TeaTang\AppData\Local\Popcorn-Time =>.SUP.PopcornTime
FOUND folder: C:\Documents and Settings\TeaTang\Application Data\Microsoft\Windows\Start Menu\Programs\Discord Inc =>.SUP.Discord
—\ Registry ( Key, Value, Data) (9)
FOUND value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run \Discord [C:\Users\TeaTang\AppData\Local\Discord\Update.exe ] =>.SUP.Discord
FOUND key: HKLM\SOFTWARE\POLICIES\Mozilla\Firefox [AdditionalScan 573] =>.SUP.FirefoxRestriction
FOUND key: HKLM\System\CurrentControlSet\Services\EventLog\Re ason\ReasonByteFence [AdditionalScan 579] =>SUP.Optional.ByteFence
FOUND key: HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Discord =>.SUP.Discord
FOUND key: HKEY_USERS\S-1-5-21-3407470762-2713599730-1590247004-1001\SOFTWARE\Classes\Discord [URLiscord Protocol] =>.SUP.Discord
FOUND key: HKCU\Software\Discord =>.SUP.Discord
FOUND key: HKCU\Software\Microsoft\Windows\CurrentVersion\Uni nstall\Discord [Discord Inc.] =>.SUP.Discord
FOUND key: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASAPI32 =>SUP.Optional.ByteFence
FOUND key: [X64] HKLM\SOFTWARE\Microsoft\Tracing\ByteFence_RASMANCS =>SUP.Optional.ByteFence
@puki
Download ClearLNK
Save to your desktop.
Drag and drop the attached text log onto ClearLNK program.
[IMG alt=" move.gif"]http://dragokas.com/tools/move.gif
Navigate to [COLOR=rgb(184, 49, 47)]C:\Users\TeaTang\Desktop\AutoLogger\AV\av_z.exe and right click and run as Admin the AVZ program. (Inside of Autologger folder)
Go To File.
Then to troubleshooting wizard.
Under Issue type select system issues.
Under dangerousness level select All issues.
Click start.
Once complete.
Then tick each box.
Then click the fix selected issues button, then reboot your machine.
In AVZ after fixing the issues you will see…
[ATTACH type=“full” alt=“1664652932814.png”]10628[/ATTACH]
Click that to reboot, if it is not seen then close out AVZ and reboot manually.
What issues are you experiencing? I am not seeing any malware on your machine, but post a new FRST log so that I can double check. Also, reset your router to factory settings.
We process personal data about users of our site, through the use of cookies and other technologies, to deliver our services, personalize advertising, and to analyze site activity. We may share certain information about our users with our advertising and analytics partners. For additional details, refer to our Privacy Policy.
By clicking "I AGREE" below, you agree to our Privacy Policy and our personal data processing and cookie practices as described therein. You also acknowledge that this forum may be hosted outside your country and you consent to the collection, storage, and processing of your data in the country where this forum is hosted.
Comment