Jump to content

G program in shutdown screen


Recommended Posts

Hello forum staff I would like to request assistance in the removal of a possible malware threat that has recently appeared. First on startup 2 cmd boxs pop up and go away. 2, a program named G was found on the shutdown screen. plz help. Attached are the files FRST, Addition and Malwarebytes threat log

 

 

FRST.txt

Addition.txt

Threat log.txt

Link to post
Share on other sites

  • Root Admin

Hello @Prince-Ali2 and :welcome:

Sorry for the delay. I'm not seeing any obvious infection on the computer. It may be part of one of your applications that is spawning that window on purpose. Let me have you run a couple other things though and we'll see what else we can find.

 

Please run the following steps and post back the logs as an attachment when ready.

 

Please download AdwCleaner by Malwarebytes and save the file to your Desktop.

  • Right-click on the program and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Accept the Terms of use.
  • Wait until the database is updated.
  • Click Scan.
  • When finished, please click Clean.
  • Your PC should reboot now if any items were found.
  • After reboot, a log file will be opened. Copy its content into your next reply.

 

 

Create an Autoruns Log:

  • Please download Sysinternals Autoruns from here.
  • Save Autoruns.exe to your desktop and double-click it to run it.
  • Once it starts, please press the Esc key on your keyboard.
  • Now that scanning is stopped, click on the Options button at the top of the program and select Verify Code Signatures
  • Once that's done press the F5 key on your keyboard, this will start the scan again, this time let it finish.
  • When it's finished, please click on the File button at the top of the program and select Save and save the Autoruns.arn file to your desktop and close Autoruns.
  • Right click on the Autoruns.arn file on your desktop and hover your mouse over Send To and select Compressed (zipped) Folder
  • Attach the Autoruns.zip folder you just created to your next reply

Thanks

Ron

 

 

Link to post
Share on other sites

  • Root Admin

Not seeing anything out of the ordinary. In fact, cleaner than most systems I see.
 

Can you take a screenshot of it with your phone when you see it? I'd have to believe it has something to do with a launch or process spawn from another valid application on your system. That's pretty difficult to track down without a lot of work.

Thanks

Ron

 

Link to post
Share on other sites

  • Root Admin

That is a signed driver from Tech Titan. It has a brick and mortar physical address too. Extremely unlikely that it is an infected file. The file is signed too which is also difficult for real malware to provide.

None of the bigger antivirus names like Kaspersky, Norton, Microsoft detect it. I am pretty confident there is nothing wrong with that file.

 

Link to post
Share on other sites

  • Root Admin

I don't see anything, but let's go ahead and scan with Kaspersky antivirus as well just to make sure.

Disable your current security software and run the following Kaspersky antivirus scan.

 

Please download and run the following Kaspersky antivirus removal tool to scan and to remove any found threats

Kaspersky Virus Removal Tool

Let me know if it finds anything or not @Prince-Ali2

Thanks

Ron

 

Link to post
Share on other sites

  • 3 weeks later...
  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.