Solved Backdoor on my pc (Solved)

  • Hi there and welcome to PC Help Forum (PCHF), a more effective way to get the Tech Support you need!
    We have Experts in all areas of Tech, including Malware Removal, Crash Fixing and BSOD's , Microsoft Windows, Computer DIY and PC Hardware, Networking, Gaming, Tablets and iPads, General and Specific Software Support and so much more.

    Why not Click Here To Sign Up and start enjoying great FREE Tech Support.

    This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Status
Not open for further replies.
Hit file in the top left. Then custom scripts paste the fix I uploaded
 
Since I am at work, and unable to properly check the fix log. Please run these tools to clean up any remaining trash from the machine.

And when I return home from work, I will have a proper detailed response for you.



Adware Cleaner

  • Download AdwCleaner and save it to your Desktop
  • Right-click on AdwCleaner.exeand select, Run as Administrator
  • Accept the EULA (I accept), then click on Scan Now
  • Let the scan complete
  • Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button
  • Subsequently you may be asked to Run Basic Repair. This is optional. I would suggest holding off on this for now.
  • Once the cleaning process is complete, AdwCleaner will ask you to restart your computer
  • Close all other open windows and allow it to restart
  • After the restart, Notepad will open with the AdwCleaner cleaning log
  • Please Attach the contents of that log into your next reply to me




Download Malwarebytes v.4 . Install and run.
  • Once the MBAM dashboard opens, click on Settings (gear icon).
  • Click on Security tab and make sure that all four Scan options are enabled.
  • Close Settings and click on the Scan button on the dashboard.
  • Once the scan is completed make sure you have it quarantine any detections it finds.
  • If no detections were found click on the Save results drop-down, then the Export to TXT button and save the file as a Text file to your desktop.
  • If there were detections then once the quarantine has completed click on the View report button, then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.
  • If the computer restarted to quarantine you can access the logs from the Detection History, then the History tab. Highlight the most recent scan and double-click to open it. Then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and include that log on your next reply.



ZHP cleaner Scan.


Please download Zhp Cleaner to your desktop. Right Click the icon and select run as administrator.
Once you have started the program, you will need to click the scanner button.
The program will close all open browsers!
Once the scan is completed, the you will want to click the Repair button.
At the end of the process you may be asked to reboot your machine.
After you reboot a report will open on your desktop.
Attach the report here in your next reply.
 
Screenshot_19.png

I don't see "Clean & Repair" on AdwCleaner, I only got the "Quarantine" button.
 
Adware Cleaner
I didn't get "Clean & Repair" option, the only option I had was "Quarantine" which I did and then deleted them and it didn't ask me to restart my computer. However, here are the logs:
 

Attachments

Ok, now updated Frst and addition.txt logs please .

Along with this. And I’ll check them when I get home.

Download ZHP Suite to your desktop.
Right Click Run as admin.
Hit the scanner button.
Once it is complete a file name ZHPdiag.txt will be on your desktop.
Attach it here.
 
No problem. Did you create and are you aware of this user?

hermi (S-1-5-21-13960046-46231223-1468497707-1002 - Administrator - Enabled) => C:\Users\hermi
 
It will be a couple hours... just so you know. Around same time as yesterday.
 
Right click ZHP Suite
Run as admin.
Click on Repair.
Copy the content of the quote box below.
In the top right click on paste a report.
It will be the second down from the top right.
Then click on start script at the top left.


1671502521969.png


Start::
CreateRestorePoint
EmptyCLSID
EmptyFlash
EmptyTemp
EmptyTracing
EmptyPrefetch
EmptyProxy
EmptyRecycle
O4 - HKLM\..\Wow6432Node\Run: [Lightshot] . (. - .) -- C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe (.Not File.) =>.SUP.Orphan
HKLM\SOFTWARE\RAVAntivirus
HKLM\SOFTWARE\Symantec =>.Symantec
HKLM\SOFTWARE\TeamViewer =>.TeamViewer GmbH
HKLM\SOFTWARE\WOW6432Node\McAfee =>.McAfee Inc.
HKLM\SOFTWARE\WOW6432Node\mcafeeupdater =>.McAfee Inc.
HKLM\SOFTWARE\WOW6432Node\Symantec =>.Symantec
HKLM\SOFTWARE\WOW6432Node\WiseCleaner =>.wisecleaner
HKCU\SOFTWARE\0046085e-ca7d-5ae0-84da-edb50a69f027 =>Adware.CrossRider
HKCU\SOFTWARE\22789c4f-79c4-5364-9ee1-c5a09f5035b1 =>Adware.CrossRider
HKCU\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKCU\SOFTWARE\d294c24a-fad9-5048-ad38-b25b1ab733a1 =>Adware.CrossRider
HKCU\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8 =>Adware.CrossRider
HKCU\SOFTWARE\f844a100-2ca0-51d4-8013-d11548b01669 =>Adware.CrossRider
HKCU\SOFTWARE\Opera Software =>.Opera Software
HKCU\SOFTWARE\Opera Stable Offer =>.Opera Software
HKCU\SOFTWARE\TeamViewer =>.TeamViewer GmbH
HKCU\SOFTWARE\AppDataLow\Software\Norton =>.Symantec Corporation
HKU\.DEFAULT\SOFTWARE\Norton =>.Symantec Corporation
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\0046085e-ca7d-5ae0-84da-edb50a69f027 =>Adware.CrossRider
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\22789c4f-79c4-5364-9ee1-c5a09f5035b1 =>Adware.CrossRider
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\AvastAdSDK =>.Avast Software s.r.o
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\d294c24a-fad9-5048-ad38-b25b1ab733a1 =>Adware.CrossRider
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\da60f423-202e-5908-a438-cd6fbbc819c8 =>Adware.CrossRider
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\f844a100-2ca0-51d4-8013-d11548b01669 =>Adware.CrossRider
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\Norton =>.Symantec Corporation
O43 - CFD: 12/02/2021 - [] D -- C:\ProgramData\McAfee
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\McAfee\WebAdvisor\uihost.exe.FriendlyAppName
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\McAfee\WebAdvisor\uihost.exe.ApplicationCompany
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\McAfee\WebAdvisor\uihost.exe.FriendlyAppName
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\McAfee\WebAdvisor\uihost.exe.ApplicationCompany
O43 - CFD: 30/04/2021 - [] D -- C:\ProgramData\Norton
O43 - CFD: 07/12/2019 - [] D -- C:\ProgramData\NortonInstaller
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.17.1.50\NortonSecurity.exe
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.2.57\uiStub.exe.FriendlyAppName
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.2.57\uiStub.exe.ApplicationCompany
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.4.57\uiStub.exe.FriendlyAppName
[HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.4.57\uiStub.exe.ApplicationCompany
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.17.1.50\NortonSecurity.exe
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.2.57\uiStub.exe.FriendlyAppName
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.2.57\uiStub.exe.ApplicationCompany
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.4.57\uiStub.exe.FriendlyAppName
[HKU\S-1-5-21-13960046-46231223-1468497707-1001\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]:C:\Program Files\Norton Security\Engine\22.20.4.57\uiStub.exe.ApplicationCompany
HKU\S-1-5-21-13960046-46231223-1468497707-1001\SOFTWARE\TeamViewer
O43 - CFD: 06/07/2021 - [0] D -- C:\Program Files\RAVAntivirus
O43 - CFD: 18/03/2021 - [0] D -- C:\Program Files (x86)\360
O43 - CFD: 18/03/2021 - [] SHD -- C:\ProgramData\360Quarant
O43 - CFD: 18/03/2021 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Roaming\360safe
O43 - CFD: 04/12/2020 - [0] D -- C:\ProgramData\{1BD627EA-33FE-5F92-6BA6-77BA834EAF62}
O43 - CFD: 27/02/2021 - [] D -- C:\Users\PCGAMER\AppData\Local\jILhSZuRqThbQPTW9VU
O43 - CFD: 09/10/2021 - [] D -- C:\Users\PCGAMER\AppData\Local\UTW008
O43 - CFD: 18/05/2022 - [] D -- C:\Users\PCGAMER\AppData\Local\_
O43 - CFD: 29/10/2020 - [] D -- C:\Users\PCGAMER\AppData\LocalLow\n9h9r91h8fna789q
O43 - CFD: 27/06/2022 - [] D -- C:\Users\PCGAMER\AppData\LocalLow\nb98wqnehe8bw89hb
End::



FRST Fix.
Download attached fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.







After running the two fixes above, I am confident that you will be 100 percent malware free .

We will check with one more tool to make sure.

Download RogueKiller and install the program.
Once downloaded and installed, right click and run as admin.
Click the check for updates button.
Go to scan setting then slide the MalPE option right to activate.
Then go to scan, then start a full scan on your machine.
Then click report when the scan completes.
Under Share my report click on open then select text file.
Copy it and paste the results here.
Make sure you do not remove anything detected until I see the log please.
 

Attachments

Last edited:
Status
Not open for further replies.