"Redline Stealer" infection

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Bohauo
    PCHF Member
    • Nov 2016
    • 79

    #31
    well, i couldn’t tell, i didn’t even know i had a problem before, it was the CISO (IT Security) that notified me of my problem.
    both MBAM and Windows Defender only discover issues with some of the apps you wanted me to download.

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7045

      #32
      There were some questionable files that I removed, and also a couple of open ports on your firewall.

      These.

      C:\Users\bohau\AppData\Local\9305404043
      C:\WINDOWS\system32\Drivers\yvkurxwa.sys
      FirewallRules: [{D7117FA5-FDC3-42CB-8879-AA0FB29EF7FF}] => (Allow) LPort=32976
      FirewallRules: [{7440A2B4-816E-4193-8B25-FE149001ACA1}] => (Allow) LPort=17771

      So yes there was something active which was removed. But no active malware, seems to be pieces of left over infection. Or at the time of these scans not active. But everything that needed to be removed was.

      As far as the anti keylogging softwware that is up to you, would not hurt to have an extra layer of protection, but that is up to you.

      Update your older programs with Patch My PC home Edition.



      We will clean all the tools we used…

      Download KpRM
      Save to Desktop
      Check Delete Tools’
      Check Delete Restore points.
      Create Restore point.
      Click delete quarantines.
      Then click run.


      I suggest:
      Ublock Origin
      O&O Shutup Ten
      O&O App Buster

      Comment

      • Bohauo
        PCHF Member
        • Nov 2016
        • 79

        #33
        hey.
        So i downloaded and “installed” those O&O thingies, can you explain what they do and how to use them?

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7045

          #34
          The intent is to block telemetry, and uninstall useless to you apps. You can be the judge of what you want or do not want blocked.

          Comment

          • Bohauo
            PCHF Member
            • Nov 2016
            • 79

            #35
            so what anti logger do you suggest???
            Zemana didn’t work since both MBAM and Windows Defender reacted on some .sys files, and they did also interferer with the installation of zemana

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7045

              #36


              Any other questions or issues?

              Comment

              • Bohauo
                PCHF Member
                • Nov 2016
                • 79

                #37
                not right now…
                Thank you for your help!

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7045

                  #38
                  Marked as solved. Thanks for following thru.

                  Comment

                  Working...