Jump to content

Recommended Posts

When I log into a clients server using Teamviewer, I get a Malwarebytes message pop up that says "Website blocked due to trojan". It lets me log into my client anyway, so I logged in and ran Malwarebytes and found several malware programs and a couple of trojan softrwares. I cleaned up the server, rebooted it and ran Malwarebytes again. This time it came up clean. However, I continue to get a message that says "Website blocked due to trojan". The IP address of the "Website" is the static IP of the client. I ran Malwarebytes after logging in a second time and everything was still clean. The ports that are showing vary. One time it is port 59007, then 54886 and then 56150. This does not happen on any of my other clients.

Q - Is this malware still on my clients computer and trying to send out a trojan every time I try to connect to them? OR - is this a "Website" that got added to a list of problem sites on my side. Why is it still reporting a possible Trojan if Malwarebytes is showing the  client as being clean? Do you have a utility to tell me what type of trojan it is detecting on my side?

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Let see what we can find that is malware.

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.
Click Attach this file.
Click the Add reply button.
===

Please post the logs  for my review.

Wait for further instructions

Link to post
Share on other sites

Hi.

Windows Firewall is disabled.
Turn ON your Firewall Windows.
https://support.microsoft.com/en-us/instantanswers/c9955ad9-1239-4cb2-988c-982f851617ed/turn-windows-firewall-on-or-off

===

Please download the attached Fixlist.txt file to  the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please post the Fixlog.txt and let me know what problem persists.

fixlist.txt

Link to post
Share on other sites

  • 2 weeks later...
  • Root Admin

Due to the lack of feedback, this topic is closed to prevent others from posting here.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this topic. Other members who need assistance please start your own topic in a new thread.

Thanks

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.