bigfunnyguy
-
Posts
8 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by bigfunnyguy
-
-
That was it, thank you very much.
-
Yes, I have not had any problems yet.
-
I don't have the link anymore. but it was just same fake link starting with imgcross. I did look it up and it was connected to russia somehow. So could I use lastpass now and just start from there to reset these passwords?
-
I believe that was the only one. It was just a link I clicked that i shouldn't have. It ended in scr. so I knew something was wrong. I looked it up and it was malware.
I downloaded malwarebytes and thats what it deleted. It was named trojan password stealer steam in malwarebytes. The link was from the twitch streaming site so I assume it was meant to steal passwords from steam. Do you think I still need to change all my passwords if i didn't enter any after that happened. I was logged into things, but i never entered any new information. I deleted cookies and things like that to log me out of everything. I only have entered a login to this website after i fixed it with that program. I have 2 step on most websites that I use. -
Fix result of Farbar Recovery Scan Tool (x64) Version: 27-07-2017
Ran by Matt (28-07-2017 08:02:38) Run:1
Running from C:\Users\Matt\Desktop
Loaded Profiles: defaultuser0 & Matt (Available Profiles: defaultuser0 & Matt)
Boot Mode: Normal
==============================================fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:C:\ProgramData\mntemp
C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
C:\ProgramData\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}.log
C:\ProgramData\{6BADCD73-E925-46F7-A295-FF2448632728}.log
C:\ProgramData\{CEF5334F-B91A-4327-ACAE-AA50DCE3F995}.log
C:\Users\Matt\AppData\Roaming\x64sys
C:\Users\Matt\AppData\Roaming\rtv.binEmptyTemp:
*****************Processes closed successfully.
Restore point was successfully created.
C:\ProgramData\mntemp => moved successfully
C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log => moved successfully
C:\ProgramData\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}.log => moved successfully
C:\ProgramData\{6BADCD73-E925-46F7-A295-FF2448632728}.log => moved successfully
C:\ProgramData\{CEF5334F-B91A-4327-ACAE-AA50DCE3F995}.log => moved successfully
C:\Users\Matt\AppData\Roaming\x64sys => moved successfully
C:\Users\Matt\AppData\Roaming\rtv.bin => moved successfully=========== EmptyTemp: ==========
BITS transfer queue => 4746363 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 151202604 B
Java, Flash, Steam htmlcache => 241341189 B
Windows/system/drivers => 125063318 B
Edge => 3661514 B
Chrome => 589170939 B
Firefox => 0 B
Opera => 0 BTemp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 8260 B
NetworkService => 373918 B
defaultuser0 => 128 B
Matt => 1045041561 BRecycleBin => 0 B
EmptyTemp: => 2 GB temporary data Removed.================================
The system needed a reboot.==== End of Fixlog 08:03:19 ====
Is my computer fine to use now? Thanks for the help by the way <3
-
These were found and deleted after a scan. I downloaded the program once I realized I clicked something I shouldn't have. Scanned and then deleted
-
Clicked on a link which downloaded a .scr file. I ran the malwarebytes anti virus and it removed this. https://gyazo.com/bf8a21b6bae12d97d7b34ee42fbb6cca
trojan password stealer steam and PUP.optional
I'm not sure if everything is removed or if the PC is safe to run/login into with these removed, since it took a couple of scans/programs to remove these.
Infected with .scr
in Resolved Malware Removal Logs
Posted
# DelFix v1.013 - Logfile created 31/07/2017 at 10:52:34
# Updated 17/04/2016 by Xplode
# Username : Matt - DESKTOP-I8TEP6J
# Operating System : Windows 10 Home (64 bits)
~ Activating UAC ... OK
~ Removing disinfection tools ...
~ Creating registry backup ... OK
~ Cleaning system restore ...
Deleted : RP #34 [Scheduled Checkpoint | 07/30/2017 11:03:55]
New restore point created !
~ Resetting system settings ... OK
########## - EOF - ##########