Backdoor on my pc (Solved)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #76
    Post the latest fixlog from FRST as well.

    Open elevated command prompt and copy and paste each command below, hitting enter after each.
    RD /S /Q “%WinDir%\System32\GroupPolicyUsers” && RD /S /Q “%WinDir%\System32\GroupPolicy”
    gpupdate /force
    Download KPRM then save to desktop.
    Right click run as admin.
    Check mark, restore system settings.
    Click the run button.

    Then reboot your computer. Check that the issue is gone with the clipboard.

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #77
      May need to use these commands and do them one at a time hitting enter after each. Then reboot the computer after.
      RMDIR /S /Q “%WinDir%\System32\GroupPolicyUsers”
      RMDIR /S /Q “%WinDir%\System32\GroupPolicy”
      gpupdate /force







      RD /S /Q “%WinDir%\System32\GroupPolicy”
      RD /S /Q “%WinDir%\System32\GroupPolicyUsers”
      gpuрdаte /force

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #78
        If the above does not help, then create and run a batch file.

        Open a notepad and copy the content of the code box below, paste into open notepad and save it to your desktop as clean.bat then right click on clean.bat and run as admin. It is very important to run the batch file as admin!!

        Note: You should allow the n batch file to complete, Once it reboots your machine that is when it is done.

        [COLOR=rgb(184, 49, 47)]Do not copy the word Code:
        Code:
        wmic /Namespace:\\root\default Path SystemRestore Call Enable "%SystemDrive%"
        WMIC /Namespace:\\root\default Path SystemRestore Call CreateRestorePoint "BatchRestorePoint", 100, 10
        SC config trustedinstaller start=auto
        reg delete "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies" /f
        reg delete "HKCU\Software\Microsoft\WindowsSelfHost" /f
        reg delete "HKCU\Software\Policies" /f
        reg delete "HKLM\Software\Microsoft\Policies" /f
        reg delete "HKLM\Software\Microsoft\Windows\CurrentVersion\Policies" /f
        reg delete "HKLM\Software\Microsoft\WindowsSelfHost" /f
        reg delete "HKLM\Software\Policies" /f
        reg delete "HKLM\Software\WOW6432Node\Microsoft\Policies" /f
        reg delete "HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies" /f
        gpuрdаte /force      
        shutdown -r
        Exit /B
        If you are unable to copy and paste, I have uploaded the batch file for you. Unzip it to your desktop, right click run as admin.[COLOR=rgb(184, 49, 47)] Must be ran from the desktop[/COLOR][/COLOR]

        Comment

        • Ichigo
          PCHF Member
          • Dec 2022
          • 61

          #79
          Here’s the latest fix log

          Comment

          • Ichigo
            PCHF Member
            • Dec 2022
            • 61

            #80
            [ATTACH type=“full”]11111[/ATTACH]
            It has been 10 minutes that it is updating

            Comment

            • Ichigo
              PCHF Member
              • Dec 2022
              • 61

              #81
              It updated but the clipboard is still disabled, im going to try the other commands you’ve sent

              Comment

              • Ichigo
                PCHF Member
                • Dec 2022
                • 61

                #82
                [ATTACH type=“full” alt=“1671797732362.png”]11112[/ATTACH]
                The file doesnt exist

                Comment

                • Ichigo
                  PCHF Member
                  • Dec 2022
                  • 61

                  #83
                  the batch file isnt restarting my computer

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #84
                    @Ichigo

                    Ok, reboot manually.

                    If that fails to repair the issue, then we will use AVZ to correct it.

                    Disable your antivirus prior to running AVZ!
                    Run AVZ as admin! (located in the folder …Autologger\AVZ) click File => Customs Scripts.
                    Copy the content of the text file I uploaded. (AVZFix.txt)
                    Click edit select all copy.
                    Paste into AVZ window.
                    Make sure the word begin is in the absolute top left of the window as per picture below.

                    You can either type the words in and make sure the spacing is correct.
                    Save the avzfix i uploaded to your documents folder.
                    Hit File.
                    Customs Scripts.
                    Hit the Load Button.
                    In the bottom right select text document.
                    type avzfix.txt hit enter or click the open button.
                    Now click on run.
                    [ATTACH type=“full” alt=“1671835870873.png”]11123[/ATTACH]

                    Hit Run Fix.

                    The computer will reboot.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #85
                      If none of the above helps it may be due to a setting in O&O shutup ten, you should run this and revert everything back to default.

                      Comment

                      • Ichigo
                        PCHF Member
                        • Dec 2022
                        • 61

                        #86
                        I just ran AVZ and now I am able to activate it but whenever I activate and then I do Windows+V to use it it opens a transparent window like on this picture[ATTACH type=“full”]11122[/ATTACH]
                        and when I close and launch again the clipboard settings it shows up as disabled while I had enabled it

                        Comment

                        • Ichigo
                          PCHF Member
                          • Dec 2022
                          • 61

                          #87
                          Im going to try to revert O&O shutup ten settings

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #88
                            Originally posted by Ichigo
                            Im going to try to revert O&O shutup ten settings
                            Yep, I think that is the issue… Make sure and reboot after.

                            Comment

                            • Ichigo
                              PCHF Member
                              • Dec 2022
                              • 61

                              #89
                              I pressed “Undo all changes (“factory settings”)” but it is still not working, should I reboot my computer

                              Comment

                              • Malnutrition
                                PCHF Moderator
                                • Jul 2016
                                • 7041

                                #90
                                yes

                                Comment

                                Working...