A virus disguising as RAR

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Berry_Marchs
    PCHF Member
    • Dec 2022
    • 9

    #1

    A virus disguising as RAR

    I have virus that is disguising itself as winRAR, and it can be viewed in Task Manager.
    [ATTACH type=“full”]11021[/ATTACH]

    If show in details, it will show up as this (properties included)
    [ATTACH type=“full”]11022[/ATTACH]
    [ATTACH type=“full”]11023[/ATTACH]
    Ending the task does nothing. It will simply run again on its own. Access to the file’s location is also inaccessible, even with Administrator.
    [ATTACH type=“full”]11025[/ATTACH]
    Is there a way to get rid of this? Thank you.

    Some specs if necessary:
    i7-9thgen
    GTX 1050 4GB
    1TB HDD
    no SSD
    8GB RAM
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #2
    Download Autologger to your desktop.
    Disable your Anitivirus/Defender prior to running.
    [ul]
    [li]Unzip it there. – If you are unsure how to unzip a program, then use ---- http://www.7-zip.org/ ----[/li][li]Right click Autologger and run as admin. (Xp user double click)[/li][li]AVZ4 will open and scan your machine, allow this to complete.[/li][li]Upload Collectionlog.zip to your next reply.[/li][/ul]

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #3
      If you have trouble with running AVZ let me know, and we can use other tools.

      Comment

      • Berry_Marchs
        PCHF Member
        • Dec 2022
        • 9

        #4
        here it is, apologies for the delayed reply

        .exe found in log
        [ATTACH type=“full”]11027[/ATTACH]

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #5
          Ok, give me a few to look this over.

          Comment

          • Berry_Marchs
            PCHF Member
            • Dec 2022
            • 9

            #6
            Alrighty. Sorry for putting this thread on the wrong forum. Newbie here :cry:

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #7
              Look in the Autologger folder and drag out the CheckBrowsersLNK file.
              To your desktop.
              AutoLogger\CheckBrowserLnk

              Drag and drop onto the ClearLNK utility .
              After saving ClearLNK to desktop.
              [IMG alt=“move.gif”]https://dragokas.com/tools/move.gif


              Disable your antivirus prior to running AVZ!
              Run AVZ as admin! (located in the folder …Autologger\AVZ) click File => Customs Scripts.
              Copy the content of the text file I uploaded. (AVZFix.txt)
              Click edit select all copy.
              Paste into AVZ window.
              Make sure the word begin is in the absolute top left of the window as per picture below.
              [ATTACH type=“full” alt=“1671241631764.png”]11029[/ATTACH]
              Hit Run Fix.

              The computer will reboot.





              Then collect FRST logs for me and let me know if the issue is still present.

              Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
              If you are unsure if your operating system is 32 or 64 Bit please go HERE.
              Once downloaded right click the FRST desktop icon and select “Run as administrator” from the menu
              If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
              FRST will open with two dialogue boxes, accept the disclaimer.
              [ol]
              [li]Accept the default whitelist options,[/li][li]If the additions.txt options box is not checked please select it.[/li][li]Then select Scan[/li][li]Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.[/li][/ol]
              Code:
                  [IMG alt="2016-08-12_152002.jpg"]https://pchelpforum.net/attachments/2016-08-12_152002-jpg.797/
              Please Attach the contents of these logs in your next post for review by our Security Team


              Code:
              begin
               ExecuteFile('net.exe', 'stop tcpip /y', 0, 15000, true);
               QuarantineFile('c:\programdata\msibooster\windowspaint-ver4.7.0.7.exe','');
               DeleteFile('c:\programdata\msibooster\windowspaint-ver4.7.0.7.exe','32');
               DeleteFileMask('C:\ProgramData\MsiBooster', '*', true);
               DeleteDirectory('C:\ProgramData\MsiBooster');
               CreateQurantineArchive(GetAVZDirectory + 'quarantine.zip');
              ExecuteSysClean;
               ExecuteWizard('SCU', 2, 3, true);
              RebootWindows(true);
              end.
              [/IMG]

              Comment

              • Berry_Marchs
                PCHF Member
                • Dec 2022
                • 9

                #8
                Doing it now. Is this ok?

                [ATTACH type=“full”]11031[/ATTACH]

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7041

                  #9
                  Perfect. This is going to reboot your computer, so save anything your are working on!

                  Comment

                  • Berry_Marchs
                    PCHF Member
                    • Dec 2022
                    • 9

                    #10
                    [ATTACH type=“full”]11032[/ATTACH]
                    should i leave it be

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #11
                      It takes a while, so let it run. Did the main issue disappear?

                      Comment

                      • Berry_Marchs
                        PCHF Member
                        • Dec 2022
                        • 9

                        #12
                        It did! Wow, you are a life saver! Here are the 2 logs:

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7041

                          #13
                          OK, we will clean the remnants of the virus, give me a few to look this over.

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #14
                            FRST Fix.
                            Download attached fixlist.txt file and save it to the Desktop. NOTE. It’s important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


                            Download RogueKiller and install the program.
                            Once downloaded and installed, right click and run as admin.
                            Click the check for updates button.
                            Go to scan setting then slide the MalPE option right to activate.
                            Then go to scan, then start a full scan on your machine.
                            Then click report when the scan completes.
                            Under Share my report click on open then select text file.
                            Copy it and paste the results here.
                            Make sure you do not remove anything detected until I see the log please.

                            Comment

                            • Berry_Marchs
                              PCHF Member
                              • Dec 2022
                              • 9

                              #15
                              scanning now. sorry that i am taking too long
                              [ATTACH type=“full”]11036[/ATTACH]

                              Comment

                              Working...