chronic Posted June 1, 2023 ID:1570240 Share Posted June 1, 2023 Came back from work trip and left my pc with wife in kid. big mistake. I apparently have a clipboard hijacker and noticed when I was copying my eth address to send to someone. Malwarebytes doesn't detect anything with rootkit and all that on it. I did read up in past threads and got adwcleaner. ran that and nothing. went into the settings of adwcleaner. selected everything but the windows host file/installer and then I ran the basic repair. Boom the clipboard was mine again and my copy paste was good. So I restarted to check if it was there after, which it was. Not that good at finding stuff so need help to find this guy, I realllllly don't want to reformat! Thanks! Link to post Share on other sites More sharing options...
Maurice Naggar Posted June 1, 2023 ID:1570244 Share Posted June 1, 2023 Hello I will guide you along on looking for remaining malware. Lets keep these principles as we go along. Removing malware can be unpredictable Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Only run the tools I guide you to. Do not run online games while case is on-going. Do not do any free-wheeling web-surfing. The removal of malware isn't instantaneous, please be patient. Cracked or or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure. Please stick with me until I give you the "all clear". If your system is running Discord, please be sure to Exit out of it while this case is on-going. I would like a report set for review. This is a report only. Please download MALWAREBYTES MBST Support Tool Once you start it click Advanced >>> then Gather Logs Have patience till the run has finished. Upload an archive once it is done. Attach the mbst-grab-results.zip from the Desktop to your reply.. Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570246 Share Posted June 1, 2023 10-4 running it now Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570253 Share Posted June 1, 2023 mbst-grab-results.zip here it is Link to post Share on other sites More sharing options...
Solution Maurice Naggar Posted June 1, 2023 Solution ID:1570265 Share Posted June 1, 2023 Next action step: Start Malwarebytes. Click Settings ( gear ) icon. Next, lets make real sure that Malwarebytes does NOT register with Windows Security Center Click the Security Tab. Scroll down to "Windows Security Center" Click the selection to the left for the line "Always register Malwarebytes in the Windows Security Center". { We want that to be set as Off .... be sure that line's radio-button selection is all the way to the Left. thanks. } This will not affect any real-time protection of the Malwarebytes for Windows 😃. Close Malwarebytes. > Take these actions so that Windows 11 is set to show all hidden files and folders. Open File Explorer from the taskbar. Select View > Show > Hidden items. Select View → Show → File name extensions Please run the following custom script. Read all of this before you start. Please Close all open work. The tool FRSTENGLISH.exe is already on this machine Please download the attached fixlist.txt file and save it to Downloads folder Fixlist.txt<-- - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone. Use File Explorer to go to the Downloads folder RIGHT-Click on FRSTENGLISH and select RUN as Administrator and reply YES to allow it to go forward to start. That is important so that this run has Elevated Administrator rights !! NEXT press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Downloads folder (Fixlog.txt) . Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. NOTE-1: This fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will reset the Winsock & the Hosts file. It will also run scans with MS Defender antivirus. Depending on the speed of your computer this fix may take 50-55 minutes or more. NOTE-2: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications will be automatically closed. The following directories are emptied: Windows Temp Users Temp folders Edge, IE, FF, Chrome, and Opera + Brave caches, HTML5 storages, Cookies and History Recently opened files cache Discord cache Java cache Steam HTML cache Explorer thumbnail and icon cache Recycle Bin Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix. The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply. We will do much more, later. Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570269 Share Posted June 1, 2023 Fixlog.txt here yah go Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570270 Share Posted June 1, 2023 that appears to of done the trick. just copied a eth address from my marketplace and it came out fine Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570274 Share Posted June 1, 2023 Thank you so much for your work & timely fix!!! Link to post Share on other sites More sharing options...
Maurice Naggar Posted June 1, 2023 ID:1570277 Share Posted June 1, 2023 Alright. Just stick around. I need you to run 2 new reports. I also would appreciate this report: Download Farbar's Service Scanner utility and Save to your Desktop. Right-Click on fss.exe and select Run As Administrator. Answer Yes to ok when prompted. If your firewall then puts out a prompt, again, allow it to run. Once FSS is on-screen, be sure the following items are check-marked: Internet Services Windows Firewall System Restore Security Center/Action Center Windows Update Windows Defender Other services Click on "Scan". It will create a log (FSS.txt) in the same directory the tool is run. Please attach that file. ( 2 ) Temporarily disable Microsoft SmartScreen to download the next software below I would recommend getting a readout report as to update status of some key apps. Download SecurityCheck by glax24 from here and save the tool on the desktop. If Windows's SmartScreen block that with a message-window, then Click on the MORE INFO spot and over-ride that and allow it to proceed. This tool is safe. Smartscreen is overly sensitive. Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow to run & go forward Wait for the scan to finish. It will open in a text file named SecurityType.txt. Close the file. Attach it with your next reply. You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt When all done, you may go back to turn ON the EDGE Smartscreen protection. 1 Link to post Share on other sites More sharing options...
chronic Posted June 1, 2023 Author ID:1570279 Share Posted June 1, 2023 FSS.txtSecurityCheck.txt here yah go Link to post Share on other sites More sharing options...
Maurice Naggar Posted June 2, 2023 ID:1570414 Share Posted June 2, 2023 Hello. Thank you for the reports. SecurityCheck report has highlighted these apps as needing to be updated to the latest release. Git v.2.40.0 Warning! Download Update Notepad++ (64-bit x64) v.8.4.9 Warning! Download Update Node.js v.18.15.0 Warning! Download Update Python 3.9.7 (64-bit) v.3.9.7150.0 Uninstall this oldest version. Python 3.11.2 (64-bit) v.3.11.2150.0 Warning! Download Update Discord v.1.0.9010 Warning! Download Update Microsoft Teams v.1.5.00.30767 Warning! Download Update Windscribe v.2.5.18 Warning! Download Update Adobe Acrobat (64-bit) v.22.003.20322 Warning! Download Update^Please run Acrobat Reader DC and go Help - Check for updates...^ 1 Link to post Share on other sites More sharing options...
chronic Posted June 2, 2023 Author ID:1570440 Share Posted June 2, 2023 will do thanks Link to post Share on other sites More sharing options...
Maurice Naggar Posted June 2, 2023 ID:1570451 Share Posted June 2, 2023 Let's go ahead and do some clean-up work and remove the tools and logs we've run. Please download KpRm by kernel-panik and save it to your desktop.right-click kprm_2-14.exe and select Run as Administrator.Read and accept the disclaimer.When the tool opens, ensure all boxes under Actions are checked.Under Delete Quarantines select Delete Now, then click Run.Once complete, click OK.A log will open in Notepad titled kprm-(date).txt.You may attach that file to your next reply. (not compulsory)Delete mb-support-1.8.7.918.exeDelete mbst-grab-results.zip on the Desktop.Sincerely. 1 Link to post Share on other sites More sharing options...
chronic Posted June 2, 2023 Author ID:1570455 Share Posted June 2, 2023 excellent will do tonight! thank you!!! Link to post Share on other sites More sharing options...
Maurice Naggar Posted June 5, 2023 ID:1570767 Share Posted June 5, 2023 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this topic with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Please review the following to help you better protect your computer and privacy Tips to help protect from infection Thank you Link to post Share on other sites More sharing options...
Recommended Posts