Jump to content

Account create everytime after reboot


Izanai

Recommended Posts

  • Root Admin

Hello  and  :welcome:      @Izanai

 

My screen name is AdvancedSetup and I will assist you with your system issues.
 

Let's keep these principles as we proceed. Make sure to read the entire post below first.

  • Please follow all steps in the provided order and post back all requested logs
  • Please attach all log files to your post, unless otherwise requested
  • Temporarily disable your antivirus or other security software first. Make sure to turn it back on once the scans have been completed.
  • Temporarily disable Microsoft SmartScreen to download the software below if needed. Make sure to turn it back on once the scans are completed.
  • Searching, detecting, and removing malware isn't instantaneous and there is no guarantee to repair every system.
  • Before we start, please make sure that you have an external backup, not connected to this system, of all private data.
  • Do not run online games while the case is ongoing. Do not do any free-wheeling or risky web-surfing.
  • Only run the tools I guide you to use. Please don't run any other scans, download, install or uninstall any programs while I'm working with you.
  • Cracked, Hacked, or Pirated programs are not only illegal but also can make a computer a malware victim. Having such programs installed is the easiest way to get infected. It is the leading cause of ransomware encryption. It is at times also a big source of current Trojan infections. If there are any on the system you should uninstall them before we proceed.
  • Please be patient and stick with me until I give you the "all clear". We don't want to waste your time, please don't waste ours.
  • If your system is running Discord, please be sure to Exit it while this case is ongoing.

 

I see that you have ESET antivirus. Did it detect anything?

 

Please temporarily disable ESET and Malwarebytes real-time protection and run the following.

 

 

 

Please download and run the following Kaspersky Virus Removal Tool 2020 and save it to your Desktop.

(Kaspersky Virus Removal Tool version 20.0.10.0 was released on November 9, 2021)

Download: Kaspersky Virus Removal Tool

How to run a scan with Kaspersky Virus Removal Tool 2020
https://support.kaspersky.com/15674

How to run Kaspersky Virus Removal Tool 2020 in the advanced mode
https://support.kaspersky.com/15680

How to restore a file removed during Kaspersky Virus Removal Tool 2020 scan
https://support.kaspersky.com/15681

 


Select the  image.png  Windows Key and R Key together, the "Run" box should open.

user posted image

Drag and Drop KVRT.exe into the Run Box.

user posted image

C:\Users\{your user name}\DESKTOP\KVRT.exe will now show in the run box.

image.png

add -dontencrypt   Note the space between KVRT.exe and -dontencrypt

C:\Users\{your user name}\DESKTOP\KVRT.exe -dontencrypt should now show in the Run box.
 
image.png


That addendum to the run command is very important, when the scan does eventually complete the resultant report is normally encrypted, with the extra command it is saved as a readable file.

Reports are saved here C:\KVRT2020_Data\Reports and look similar to this report_20210123_113021.klr
Right-click direct onto that report, select > open with > Notepad. Save that file and attach it to your reply.

To start the scan select OK in the "Run" box.

A EULA window will open, tick all confirmation boxes then select "Accept"

image.png

In the new window select "Change Parameters"

image.png

In the new window ensure all selection boxes are ticked, then select "OK" The scan should now start...

user posted image

When complete if entries are found there will be options, if "Cure" is offered leave as is. For any other options change to "Delete" then select "Continue"

user posted image

When complete, or if nothing was found select "Close"

image.png

Attach the report information as previously instructed...
 
Thank you
 
 

 

 

Link to post
Share on other sites

Even ESET didn't detected anything.

About the report, for any reason is not allowing me to upload the .txt, so just copy&paste everything here.

Spoiler

<Report>
    <Metadata Version="1" PCID="{89F1262E-754B-7E40-4AC8-B1B14CD3977D}" LastModification="2022.09.22 16:55:19.526" />
    <EventBlocks>
        <Block0 Type="Scan" Processed="1078448" Found="2" Neutralized="2">
            <Event0 Action="Scan" Time="133083592572095266" Object="" Info="Started" />
            <Event1 Action="Detect" Time="133083602332332823" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="Trojan-Ransom.Win32.Wanna.zae" />
            <Event2 Action="Detect" Time="133083603414036749" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="Trojan-Ransom.Win32.Wanna.zae" />
            <Event3 Action="Scan" Time="133083607329525294" Object="" Info="Finished" />
            <Event4 Action="Select action" Time="133083609192714770" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="Delete" />
            <Event5 Action="Select action" Time="133083609192714770" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="Delete" />
            <Event6 Action="Disinfection" Time="133083609192724836" Object="" Info="Started" />
            <Event7 Action="Quarantined" Time="133083609192734778" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="" />
            <Event8 Action="Quarantined" Time="133083609192744779" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="" />
            <Event9 Action="Deleted" Time="133083609192744779" Object="C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data\f_004c29" Info="" />
            <Event10 Action="Deleted" Time="133083609192744779" Object="C:\Users\nano_\Downloads\asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip" Info="" />
            <Event11 Action="Disinfection" Time="133083609195254988" Object="" Info="Finished" />
        </Block0>
    </EventBlocks>
</Report>
 

 

About the Event2, Im 100% sure what is that, I donwload it today. About the first one, I don't know. I've been getting multiple notifications from malwarebytes when I open Opera GX.

 

Link to post
Share on other sites

  • Root Admin

I would recommend that you close ALL your browsers. Then using Windows File Explorer make sure you show hidden files and folders and then go to this folder and delete the files in the folder.

C:\Users\nano_\AppData\Local\Opera Software\Opera GX Stable\Cache\Cache_Data

 

Upload this file to https://virustotal.com and have them scan it to see if it's safe or not.

asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip

 

Then run the following

 

Create an Autoruns Log:

  • Please download Sysinternals Autoruns from here:   https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns
  • Save Autoruns.zip to your computer. Then locate it and extract it to a new folder where you can find and run it.
  • Once it starts you may not be able to easily stop the scan but you can try to press the Escape key on your keyboard.
  • Once scanning is stopped, click on the Options menu at the top of the program and select Scan Options... 
  • Then place a check mark on the following items Verify Code Signatures, Check VirusTotal.com, and Submit Unknown Images
  • Then click the Rescan button. Agree to the VirusTotal EULA
  • Once the new scan has been completed, please click on the File button at the top of the program and select Save, or use the Save icon, and save the Autoruns.arn file to your desktop and close Autoruns.
  • Right-click on the Autoruns.arn file (it will typically be the name of your computer) on your desktop or where you save it, and hover your mouse over Send To and select Compressed (zipped) Folder
  • Attach the Autoruns.zip folder (your computer name.zip) you just created to your next reply.

 

 

image.png

 

Thank you

 

 

Link to post
Share on other sites

About this .zip:

asset-v1_CyberWarrior+ESPA113+2022_T2+type@asset+block@Cases.zip

I know what is, are some virus cases, cuz I'm practicing for SOC lvl1, so there is no problem with the file, I mean, the zip content some virus, but is not related with the main problem because I download it today, and the account "Alex" appeared long time ago.

 

 

Autorun scan.zip

Link to post
Share on other sites

  • Root Admin

While I check your log. Have you removed the Account, and Profile properly?

https://www.repairwin.com/how-to-delete-user-profile-in-windows-10-11/

DO NOT download anything from this site.  Only reference the data

 

Edited by AdvancedSetup
Updated information
Link to post
Share on other sites

17 minutes ago, AdvancedSetup said:

Please try running AutoRuns again. You closed and saved it before VirusTotal was done.

All columns should have an entry.

image.png

 

Thanks

 

I've been trying to run it, but its appearing "Error" now on each entry.

image.png.5c53a6725a8acbc4fc89bc2d01a1bad0.png

 

 

Also, yes, I deleted the account multiple times, but appear after each reboot.

Link to post
Share on other sites

  • Root Admin

Okay, let me get this new set of logs, please. @Izanai

 

 

To begin, please do the following so that we may take a closer look at your installation for troubleshooting:

NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to your desktop, please upload that file on your next reply

Thank you

 

Link to post
Share on other sites

  • Root Admin

Glad we could help.

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request.

This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread.

Please review the following to help you better protect your computer and privacy Tips to help protect from infection

Thank you

 

 

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.