I think the hacker is back ....Someone is controlling my pc :
-closing apps
-hide tray icons
-change my passwords
-delete files
-my internet is so slow at moments (i never shared my Wifi password with anyone)
Also i have already tried to reset the router to default settings. (i'm sure i don't have malware in the router).
I also tryed to flash my BIOS (without success of course).
And have have checked my HDD firmware for viruses(none there).
I even paid for virus removal and when back at home the virus just wasn't removed.
I have read a lot about those viruses,but don't know how it's remain.
What information maybe useful for you?
I will post fresh FRST log in the next post.
@echo off
WMIC /Namespace:\\root\default Path SystemRestore Call CreateRestorePoint "BatchRestorePoint", 100, 10
sc stop RasAuto
sc stop RasMan
sc stop SessionEnv
sc stop TermService
sc stop UmRdpService
sc stop RemoteAccess
sc config RasAuto start= disabled
sc config RasMan start= disabled
sc config SessionEnv start= disabled
sc config TermService start= disabled
sc config UmRdpService start= disabled
sc config RemoteAccess start= disabled
pause
shutdown -r
Exit /B
Program : RogueKiller Anti-Malware
Version : 15.6.2.0
x64 : Yes
Program Date : Oct 10 2022
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19044) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : TeaTang
User is Admin : Yes
Date : 2022/10/26 13:47:21
Type : Scan
Aborted : No
Scan Mode : Standard
Duration : 1129
Found items : 1
Total scanned : 49754
Signatures Version : 20221024_084649
Truesight Driver : Yes
Updates Count : 0
************************* Warnings *************************
************************* Updates *************************
************************* Processes *************************
************************* Modules *************************
************************* Services *************************
************************* Scheduled Tasks *************************
************************* Registry *************************
>>>>>> XX - System Policies
└── [PUM.Policies (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -- 0 -> Found
************************* WMI *************************
************************* Hosts File *************************
is_too_big : No
hosts_file_path : C:\Windows\System32\drivers\etc\hosts
************************* Filesystem *************************
************************* Web Browsers *************************
************************* Antirootkit *************************
DoneRun the batch file, if indeed it’s being controlled, that is the only avenue. Otherwise we would have seen it.
We use essential cookies to make this site work, and optional cookies to enhance your experience.