Jump to content

LocalThreats

Members
  • Posts

    11
  • Joined

  • Last visited

Posts posted by LocalThreats

  1. Thanks, I'll update with the logs when they're done. I've found these System overrides in my Windows Exploit Protection settings and I don't remember ever setting these, are they suspicious? Thanks so much for the help

     

    <?xml version="1.0" encoding="UTF-8"?>
    <MitigationPolicy>
      <AppConfig Executable="ExtExport.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="ie4uinit.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="ieinstal.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="ielowutil.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="ieUnatt.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="iexplore.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="mscorsvw.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
      <AppConfig Executable="msfeedssync.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="mshta.exe">
        <ASLR ForceRelocateImages="true" RequireInfo="false" />
      </AppConfig>
      <AppConfig Executable="MsSense.exe">
        <StrictHandle Enable="true" />
        <SEHOP Enable="true" TelemetryOnly="false" />
      </AppConfig>
      <AppConfig Executable="ngen.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
      <AppConfig Executable="ngentask.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
      <AppConfig Executable="PresentationHost.exe">
        <DEP Enable="true" EmulateAtlThunks="false" />
        <ASLR ForceRelocateImages="true" RequireInfo="false" BottomUp="true" HighEntropy="true" />
        <SEHOP Enable="true" TelemetryOnly="false" />
        <Heap TerminateOnError="true" />
      </AppConfig>
      <AppConfig Executable="PrintDialog.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
      <AppConfig Executable="runtimebroker.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
      <AppConfig Executable="SystemSettings.exe">
        <ExtensionPoints DisableExtensionPoints="true" />
      </AppConfig>
    </MitigationPolicy>



    Capture.thumb.PNG.7caa4b58571a69a8070c5e7c9f1a7e59.PNG

  2. Hello,

    I'm fairly sure I've been infected by a RAT, and I have some questions - is there anyway to see if this was installed by a family member on the same network with physical access to the computer? I dread to think it was my brother but I'm fairly certain. Is this system still infected? 

    I have also found Malwarebytes antivirus scans with no action taken and things added to my exception list. I have added those logs alongside the log this advice - Thanks in advance.

    Addition.txt FRST.txt AdwCleaner[C00].txt MostRecentPostADW.txt Previous1.txt Previous2.txt Previous3.txt Previous4.txt

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.