Jump to content

Task Manager opens then immediatly closes - Pilotman111


Recommended Posts

  • Replies 87
  • Created
  • Last Reply

Top Posters In This Topic

Thank you. My colleagues and I are currently investigating this Task Manager issue. It seems that users that were infected with SmartService (the infection you had) recently are now stuck with this issue. We were able to reproduce it and we're working on seeing why it is occurring and how to fix it.

In the meantime, may I ask you to not download any illegal/pirated/cracked software (or illegal loaders/activators)? I wouldn't want you to get infected again before the clean-up is over :) Keep in mind that downloading this kind of things is a sure way to end up infected.

2017-08-09 04:10 - 2017-08-09 04:10 - 000000000 ____D C:\Users\epicb\Downloads\CyberGhost VPN 6.0.6.2540 + Crack [CracksNow]
2017-08-06 17:22 - 2017-08-06 17:23 - 000000000 ____D C:\Users\epicb\Downloads\FL STUDIO 12 Producer Edition v12.2 [build3]  32Bit & 64Bit + Crack
2017-08-06 15:31 - 2017-08-06 15:41 - 835027707 _____ C:\Users\epicb\Downloads\CLS 747 V2_inkl_all_liveries_SP integrated + Crack.rar

 

Link to post
Share on other sites

All good :)

Can you open Malwarebytes, update the database (click on Current by the Update line in the right tab), then run a new scan and provide me the log afterwards? New detection for the newest variant of SmartService you were hit with were added.

hlOb1pt.png

Link to post
Share on other sites

Good, that's one of the new definition that was added. I forgot to instruct you to turn on rootkit scanning before running the scan. Can you do so and run a new one? It should detect more stuff.

nCTiu7D.png

Link to post
Share on other sites

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 8/12/17
Scan Time: 1:05 PM
Log File: 
Administrator: Yes

-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.160
Update Package Version: 1.0.2569
License: Free

-System Information-
OS: Windows 10 (Build 15063.540)
CPU: x64
File System: NTFS
User: CAMERONS-PC\epicb

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 438491
Threats Detected: 0
Threats Quarantined: 0
Time Elapsed: 25 min, 4 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 0

Physical Sector: 0
(No malicious items detected)


(end)

Link to post
Share on other sites

Let's see if it works in Safe Mode with Networking. However, we need to re-enable the ability to boot into that mode first. Run the following FRST fix and attach the fixlog.txt after.

fixlist.txt

Link to post
Share on other sites

No still not able to open it sadly.

 

Zemana AntiMalware 2.74.2.76 (Portable)

-------------------------------------------------------
Scan Result            : Completed
Scan Date              : 2017/8/14
Operating System       : Windows 10 64-bit
Processor              : 4X Intel(R) Core(TM) i5-2450M CPU @ 2.50GHz
BIOS Mode              : Legacy
CUID                   : 12F59921BE2541210FCF42
Scan Type              : System Scan
Duration               : 52m 13s
Scanned Objects        : 137630
Detected Objects       : 2
Excluded Objects       : 0
Read Level             : SCSI
Auto Upload            : Enabled
Detect All Extensions  : Disabled
Scan Documents         : Disabled
Domain Info            : WORKGROUP,0,2

Detected Objects
-------------------------------------------------------
once
Status             : Scanned
Object             : NE->c:\users\epicb\appdata\roaming\microsoft\protect\once
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Trojan:Win32/Blocrypt.D!Neng
Cleaning Action    : Quarantine
Related Objects    :
                (null) - (null)

winrescheck.wrc
Status             : Scanned
Object             : NE->c:\users\epicb\appdata\roaming\microsoft\protect\winrescheck.wrc
MD5                : -
Publisher          : -
Size               : -
Version            : -
Detection          : Trojan:Win32/Blocrypt.C!Neng
Cleaning Action    : Quarantine
Related Objects    :
                (null) - (null)


Cleaning Result
-------------------------------------------------------
Cleaned               : 2
Reported as safe      : 0
Failed                : 0
 

Edited by Pilotman111
Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.


Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.