Jump to content

Recommended Posts

so after wiping all my drives (2 hdd and 1 nvme ssd) I decided to install win10 on my ssd only (hdd aren't connected at the moment) just in case something happens again. upon first boot I connected tdsskiller and hitman pro and they found a couple traces in chrome cookies. so all good I hope 

 

did a scan with FRST and noticed something very strange, files are attached. 

 

should I just get knew drives at this point? 

 

and yes I did name the main account that lol

 

Shortcut.txt

FRST.txt Addition.txt

Link to post
Share on other sites

Hello, Welcome to Malwarebytes.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Your logs are clean of malware.

If you are referring to these entries
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\59730511.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\59730511.sys => ""="Driver"

They may have been created by a 3rd party programs you installed.
I suspect it was TdssKiller or Hitman Pro.

If the computer is running well I would forget about them.

Link to post
Share on other sites

  • 1 month later...

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following for Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.