Izanai Posted September 20, 2022 ID:1533661 Share Posted September 20, 2022 Hi, I'm removing the account, but after reboot the Windows, the account appear again. I've been running Malwarebytes but is not detecting any threat. Looking in the Addition.txt, the account named "Alex" is the one that is appearing. Addition.txt FRST.txt Scan Report MB.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 22, 2022 Root Admin ID:1534932 Share Posted September 22, 2022 Hello and @Izanai My screen name is AdvancedSetup and I will assist you with your system issues. Let's keep these principles as we proceed. Make sure to read the entire post below first. Please follow all steps in the provided order and post back all requested logs Please attach all log files to your post, unless otherwise requested Temporarily disable your antivirus or other security software first. Make sure to turn it back on once the scans have been completed. Temporarily disable Microsoft SmartScreen to download the software below if needed. Make sure to turn it back on once the scans are completed. Searching, detecting, and removing malware isn't instantaneous and there is no guarantee to repair every system. Before we start, please make sure that you have an external backup, not connected to this system, of all private data. Do not run online games while the case is ongoing. Do not do any free-wheeling or risky web-surfing. Only run the tools I guide you to use. Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Cracked, Hacked, or Pirated programs are not only illegal but also can make a computer a malware victim. Having such programs installed is the easiest way to get infected. It is the leading cause of ransomware encryption. It is at times also a big source of current Trojan infections. If there are any on the system you should uninstall them before we proceed. Please be patient and stick with me until I give you the "all clear". We don't want to waste your time, please don't waste ours. If your system is running Discord, please be sure to Exit it while this case is ongoing. I see that you have ESET antivirus. Did it detect anything? Please temporarily disable ESET and Malwarebytes real-time protection and run the following. Please download and run the following Kaspersky Virus Removal Tool 2020 and save it to your Desktop. (Kaspersky Virus Removal Tool version 20.0.10.0 was released on November 9, 2021) Download: Kaspersky Virus Removal Tool How to run a scan with Kaspersky Virus Removal Tool 2020https://support.kaspersky.com/15674 How to run Kaspersky Virus Removal Tool 2020 in the advanced modehttps://support.kaspersky.com/15680 How to restore a file removed during Kaspersky Virus Removal Tool 2020 scanhttps://support.kaspersky.com/15681 Select the Windows Key and R Key together, the "Run" box should open. Drag and Drop KVRT.exe into the Run Box. C:\Users\{your user name}\DESKTOP\KVRT.exe will now show in the run box. add -dontencrypt Note the space between KVRT.exe and -dontencryptC:\Users\{your user name}\DESKTOP\KVRT.exe -dontencrypt should now show in the Run box. That addendum to the run command is very important, when the scan does eventually complete the resultant report is normally encrypted, with the extra command it is saved as a readable file. Reports are saved here C:\KVRT2020_Data\Reports and look similar to this report_20210123_113021.klr Right-click direct onto that report, select > open with > Notepad. Save that file and attach it to your reply. To start the scan select OK in the "Run" box. A EULA window will open, tick all confirmation boxes then select "Accept" In the new window select "Change Parameters" In the new window ensure all selection boxes are ticked, then select "OK" The scan should now start... When complete if entries are found there will be options, if "Cure" is offered leave as is. For any other options change to "Delete" then select "Continue" When complete, or if nothing was found select "Close" Attach the report information as previously instructed... Thank you Link to post Share on other sites More sharing options...
Izanai Posted September 22, 2022 Author ID:1534943 Share Posted September 22, 2022 Even ESET didn't detected anything. About the report, for any reason is not allowing me to upload the .txt, so just copy&paste everything here. Spoiler <Report> <Metadata Version="1" PCID="{89F1262E-754B-7E40-4AC8-B1B14CD3977D}" LastModification="2022.09.22 16:55:19.526" /> <EventBlocks> <Block0 Type="Scan" Processed="1078448" Found="2" Neutralized="2"> <Event0 Action="Scan" Time="133083592572095266" Object="" Info="Started" /> <Event1 Action="Detect" Time="133083602332332823" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="Trojan-Ransom.Win32.Wanna.zae" /> <Event2 Action="Detect" Time="133083603414036749" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="Trojan-Ransom.Win32.Wanna.zae" /> <Event3 Action="Scan" Time="133083607329525294" Object="" Info="Finished" /> <Event4 Action="Select action" Time="133083609192714770" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="Delete" /> <Event5 Action="Select action" Time="133083609192714770" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="Delete" /> <Event6 Action="Disinfection" Time="133083609192724836" Object="" Info="Started" /> <Event7 Action="Quarantined" Time="133083609192734778" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="" /> <Event8 Action="Quarantined" Time="133083609192744779" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="" /> <Event9 Action="Deleted" Time="133083609192744779" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="" /> <Event10 Action="Deleted" Time="133083609192744779" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="" /> <Event11 Action="Disinfection" Time="133083609195254988" Object="" Info="Finished" /> </Block0> </EventBlocks> </Report> About the Event2, Im 100% sure what is that, I donwload it today. About the first one, I don't know. I've been getting multiple notifications from malwarebytes when I open Opera GX. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 22, 2022 Root Admin ID:1534951 Share Posted September 22, 2022 I would recommend that you close ALL your browsers. Then using Windows File Explorer make sure you show hidden files and folders and then go to this folder and delete the files in the folder. C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data Upload this file to https://virustotal.com and have them scan it to see if it's safe or not. asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip Then run the following Create an Autoruns Log: Please download Sysinternals Autoruns from here: https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns Save Autoruns.zip to your computer. Then locate it and extract it to a new folder where you can find and run it. Once it starts you may not be able to easily stop the scan but you can try to press the Escape key on your keyboard. Once scanning is stopped, click on the Options menu at the top of the program and select Scan Options... Then place a check mark on the following items Verify Code Signatures, Check VirusTotal.com, and Submit Unknown Images Then click the Rescan button. Agree to the VirusTotal EULA Once the new scan has been completed, please click on the File button at the top of the program and select Save, or use the Save icon, and save the Autoruns.arn file to your desktop and close Autoruns. Right-click on the Autoruns.arn file (it will typically be the name of your computer) on your desktop or where you save it, and hover your mouse over Send To and select Compressed (zipped) Folder Attach the Autoruns.zip folder (your computer name.zip) you just created to your next reply. Thank you Link to post Share on other sites More sharing options...
Izanai Posted September 23, 2022 Author ID:1534956 Share Posted September 23, 2022 About this .zip: asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip I know what is, are some virus cases, cuz I'm practicing for SOC lvl1, so there is no problem with the file, I mean, the zip content some virus, but is not related with the main problem because I download it today, and the account "Alex" appeared long time ago. Autorun scan.zip Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 23, 2022 Root Admin ID:1534960 Share Posted September 23, 2022 (edited) While I check your log. Have you removed the Account, and Profile properly? https://www.repairwin.com/how-to-delete-user-profile-in-windows-10-11/ DO NOT download anything from this site. Only reference the data Edited September 23, 2022 by AdvancedSetup Updated information Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 23, 2022 Root Admin ID:1534961 Share Posted September 23, 2022 If I may. I would highly suggest not using your physical computer for such learning and testing. Use of a virtual machine would be highly advisable. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 23, 2022 Root Admin ID:1534963 Share Posted September 23, 2022 Please try running AutoRuns again. You closed and saved it before VirusTotal was done. All columns should have an entry. Thanks Link to post Share on other sites More sharing options...
Izanai Posted September 23, 2022 Author ID:1534965 Share Posted September 23, 2022 17 minutes ago, AdvancedSetup said: Please try running AutoRuns again. You closed and saved it before VirusTotal was done. All columns should have an entry. Thanks I've been trying to run it, but its appearing "Error" now on each entry. Also, yes, I deleted the account multiple times, but appear after each reboot. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 23, 2022 Root Admin ID:1534980 Share Posted September 23, 2022 Okay, let me get this new set of logs, please. @Izanai To begin, please do the following so that we may take a closer look at your installation for troubleshooting: NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system. Download the Malwarebytes Support Tool In your Downloads folder, open the mb-support-x.x.x.xxx.exe file In the User Account Control pop-up window, click Yes to continue the installation Run the MBST Support Tool In the left navigation pane of the Malwarebytes Support Tool, click Advanced In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine A zip file named mbst-grab-results.zip will be saved to your desktop, please upload that file on your next reply Thank you Link to post Share on other sites More sharing options...
Izanai Posted September 23, 2022 Author ID:1535090 Share Posted September 23, 2022 Ok you can close the topic. @AdvancedSetup Looks like ESET Anti-Theft was doing some weird stuff and created everytime a ghost account. Anyway thanks for all the tips, tools and your time. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted September 23, 2022 Root Admin ID:1535109 Share Posted September 23, 2022 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Please review the following to help you better protect your computer and privacy Tips to help protect from infection Thank you Link to post Share on other sites More sharing options...
Recommended Posts