DRSaylor Posted October 29, 2023 ID:1597238 Share Posted October 29, 2023 I have been trying for two days to remove this trojan without success. I have used Microsoft Defender (Win 10), Malwarebytes, ComboCleaner, Microsoft Safety Scanner, Farbar Scanner and none have been able to successfully remove this item. I am attaching the Scan Log from Malwarebytes in the hope that you may be able to help me. MBLog.txt Link to post Share on other sites More sharing options...
Porthos Posted October 29, 2023 ID:1597243 Share Posted October 29, 2023 @DRSaylor Let's get the info to get the process started. Please do the following so that we may take a closer look at your system for any possible infections. Do these 2 steps so that ALL folders & Files are set to SHOW, plus also, Turn OFF Windows Fast start. Show-Hidden-Folders-Files-Extensions https://forums.malwarebytes.com/topic/299345-show-hidden-folders-files-extensions/ Disable-Fast-Startup https://forums.malwarebytes.com/topic/299350-disable-fast-startup/ Then please restart the computer and do the following. WARNING: Do Not click the Repair option under Advanced unless requested by a Malwarebytes support agent or authorized helper NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system. Download the Malwarebytes Support Tool In your Downloads folder, open the mb-support-x.x.x.xxx.exe file In the User Account Control pop-up window, click Yes to continue the installation Run the MBST Support Tool In the left navigation pane of the Malwarebytes Support Tool, click Advanced In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine A zip file named mbst-grab-results.zip will be saved to the Desktop or on the hidden Public desktop (usually C:\Users\Public\Desktop), please upload that file on your next reply Thank you Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 29, 2023 ID:1597247 Share Posted October 29, 2023 Hello. My name is Maurice. I will guide you. Kindly run the support-report-tool as outlined above & attach for my review. Removing pesky malware can be an involved set of tasks over separate runs. Have much patience. Follow my directions. Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Only run the tools I guide you to. Do not run online games while case is on-going. Do not do any free-wheeling web-surfing. The removal of malware isn't instantaneous, please be patient. Cracked or or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure. Please stick with me until I give you the "all clear". If your system is running Discord, please be sure to Exit out of it while this case is on-going. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted October 30, 2023 Author ID:1597254 Share Posted October 30, 2023 I did as you suggested above and have attached the zip file below. mbst-grab-results.zip Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 30, 2023 ID:1597402 Share Posted October 30, 2023 Thank you for the reports. Next first housekeeping action: Please do the following actions, so that Microsoft Defender antivirus runs side-by-side along with Malwarebytes. Start Malwarebytes. Click Settings ( gear ) icon. Next, lets make real sure that Malwarebytes does NOT register with Windows Security Center Click the Security Tab. Scroll down to "Windows Security Center" Click the selection to the left for the line "Always register Malwarebytes in the Windows Security Center". { We want that to be set as Off .... be sure that line's radio-button selection is all the way to the Left. thanks. } This will not affect any real-time protection of the Malwarebytes for Windows 😃. Close Malwarebytes. > ( Next action) Be very sure to empty out the Recycle Bin of Windows, which had had a rogue Chrome "updater" rogue executable. Find the Recycle Bin icon on the desktop. Right click (or press and hold) and select Empty Recycle Bin. ( Next action) Do a Quick scan with Microsoft Defender Antivirus Just want to do a visual check in Windows Security to see (visually) that Microsoft Defender is on , and to do a Custom scan. From the Windows Start menu, select Settings, then select Update and Security. Next, look at the left-side menu & select Windows Security Next, In Windows Security section: Click on the grey button Open Windows Security Now, click on the shield Virus and threat protection Look to see that Microsoft Defender is shown & available for use. On the next display, look at all the options. Look down the list and see "Check for Updates" . You should click on that to have the system check for updates for Windows Defender. Watch & wait for that to complete. Please also note that the Scan options (all) can be displayed by clicking on Scan options. Click that & select QUICK scan & have it go forward. Let me know the results. 1 Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 30, 2023 ID:1597414 Share Posted October 30, 2023 this machine has "2miners" pest "coin-miner" classified by Malwarebytes as "Trojan.BitCoinMiner" ( Next action) After you are all caught up with the preceding actions, do this. Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. NOTE-1: This custom fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will attempt to run some scans with Microsoft Defender antivirus. It will attempt to clear Cache files of web browsers. It will attempt to clear temporary file areas. It rebuilds the Winsock. It also is meant to squash the last of the pest "coinminer". Depending on the speed of your computer this fix may take 50-55 minutes or more. Please Close all open work before you actually do begin this run. FRSTENGLISH,exe program location: Downloads folder. The tool is already on system. That is what we will use. Please download the attached fixlist.txt file and save it to Downloads Fixlist.txt <- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. Right-click with your mouse on FRSTENGLISH and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Downloads folder (Fixlog.txt) . Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply. NOTICE: For potential outside readers, This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted October 30, 2023 Author ID:1597445 Share Posted October 30, 2023 Atttached pics below. Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 30, 2023 ID:1597458 Share Posted October 30, 2023 Questions: Have you run my custom fix that I posted above? If not, then do that. link-to-my-post and if you did run the custom fix, then I gotta have the Fixlog.txt report file, so that I can do a review !!! 1 Link to post Share on other sites More sharing options...
DRSaylor Posted October 30, 2023 Author ID:1597460 Share Posted October 30, 2023 I did as suggested above and have attached the fix file below. Fixlog.txt Link to post Share on other sites More sharing options...
DRSaylor Posted October 30, 2023 Author ID:1597462 Share Posted October 30, 2023 I ran a Defender Quick Scan after all this and the trojan is still there. Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 30, 2023 ID:1597463 Share Posted October 30, 2023 The custom-script-fix run is beneficial in several ways. The custom-run is good. The Windows System File Checker has made some corrections. Windows Resource Protection found corrupt files and successfully repaired them. This last run has completed what was originally intended. There had been some corruptions that had excluded certain areas from protection by Microsoft Defender. Specifically, 2 folders had been "excluded" "C:\Windows\system32\config\systemprofile" "C:\Program Files" That has been cured. But before this, essentially all programs launched under Program Files were not monitored. We are making progress. As of the time of the conclusion of the custom-run, the system reports that Microsoft Defender antivirus' protection features are all ON , and that NO folders are excluded from its real-time protection. There is much more work to do. Have LOTS of patience. I also need for you to focus on tasks and procedures I guide you on. For now, just 2 readout reports ( before we resume more actual heavy-duty scanning). I need you to run 2 new reports. Temporarily disable Microsoft SmartScreen to download the next software below ( 1 ) Download Farbar's Service Scanner utility and Save to your Desktop. Right-Click on fss.exe and select Run As Administrator. Answer Yes to ok when prompted. If your firewall then puts out a prompt, again, allow it to run. Once FSS is on-screen, be sure the following items are check-marked: Internet Services Windows Firewall System Restore Security Center/Action Center Windows Update Windows Defender Other services Click on "Scan". It will create a log (FSS.txt) in the same directory the tool is run. Please attach that file. ( 2 ) I would recommend getting a readout report as to update status of some key apps. Download SecurityCheck by glax24 from here and save the tool on the desktop. If Windows's SmartScreen block that with a message-window, then Click on the MORE INFO spot and over-ride that and allow it to proceed. This tool is safe. Smartscreen is overly sensitive. Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow to run & go forward Wait for the scan to finish. It will open in a text file named SecurityType.txt. Close the file. Attach it with your next reply. You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt When all done, you may go back to turn ON the EDGE Smartscreen protection. NOTES: We need to cease looking at old "Protection history" displayed by Microsoft Defender that had been logged before this point. That is old history. The displays in "protection history" are regurgitating the past. In Microsoft geek-speak of Microsoft Defender, as of this afternoon, it has cleared this part ActionSuccess : True AdditionalActionsBitMask : 0 AMProductVersion : 4.18.23090.2008 CleaningActionID : 2 CurrentThreatExecutionStatusID : 1 DetectionID : {5D54496C-2E70-40CE-B572-152553CF2C62} DetectionSourceTypeID : 1 DomainUser : InitialDetectionTime : 10/29/2023 7:02:57 PM LastThreatStatusChangeTime : 10/30/2023 6:27:34 PM ProcessName : Unknown RemediationTime : 10/30/2023 6:27:34 PM Resources : {file:_C:\$Recycle.Bin\S-1-5-21-2911069410-1577389867-1067365367-1000\$R0RFSHQ\Chrome\ updater.exe, file:_C:\$Recycle.Bin\S-1-5-21-2911069410-1577389867-1067365367-1000\$RDO FMHE\Chrome\updater.exe, file:_C:\$Recycle.Bin\S-1-5-21-2911069410-1577389867-1067365367-1000\$RIX76WB.exe, file:_C:\Program Files\Google\Chrome\updater.exe...} ThreatID : 2147891798 That is to say, the Recycle Bin should be empty. and the C:\Program Files\Google\Chrome\updater.exe is no more/ And, as I said before, we will run 2 or 3 independent trusted scanners. Have patience. Keep focus on matter at hand. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted October 31, 2023 Author ID:1597490 Share Posted October 31, 2023 Files are attached below. FSS.txt SecurityCheck.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted October 31, 2023 ID:1597492 Share Posted October 31, 2023 (edited) The FSS report is good. There are 3 applications that need to be updated to latest release. We will address that later. Here I am listing two separate procedures. In the prior runs, we got a list of the old history of Microsoft Defender. Now, we need to trim down on old un-needed history. Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. Please Close all open work before you actually do begin this run. FRSTENGLISH,exe program location: Downloads folder. The tool is already on system. That is what we will use. Please download the attached fixlist.txt file and save it to Downloads <- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. Right-click with your mouse on FRSTENGLISH and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Downloads folder (Fixlog.txt) . Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. NOTICE: For potential outside readers, This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm. ( Next action) This is for a scan with ESET Onlinescanner (free). ESET is a well-respected, well-known entity and tool. ESET Onlinescanner checks for viruses, other malware, adwares, & potentially unwanted applications. This here you can start & once it is under way, you can leave the machine alone & let it run over-night. No need to keep watch once it starts the actual scan run. Go to https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe It will start a download of "esetonlinescanner.exe" Save the file to your system, such as the Downloads folder, or else to the Desktop. Go to the saved file, and double click it to get it started. When presented with the initial ESET options, click on "Computer Scan". Next, when prompted by Windows, allow it to start by clicking Yes When prompted for scan type, Click on CUSTOM scan and select C drive to be scanned Look at & tick ( select ) the radio selection "Enable ESET to detect and quarantine potentially unwanted applications" and click on Start scan button. Have patience. The entire process may take an hour or more. There is an initial update download. There is a progress window display. You may step away from machine &. Let it be. That is, once it is under way, you should leave it running. It will run for several hours. At screen "Detections occurred and resolved" click on blue button "View detected results" On next screen, at lower left, click on blue "Save scan log" View where file is to be saved. Provide a meaningful name for the "File name:" On last screen, set to Off (left) the option for Periodic scanning Click "save and continue" Please attach the report file so I can review Attach FIXLOG.txt with next reply. located on Downloads folder. Edited November 4, 2023 by Maurice Naggar 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 2, 2023 Author ID:1597896 Share Posted November 2, 2023 Find Eset log file below. EsetScanlog.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted November 2, 2023 ID:1597978 Share Posted November 2, 2023 Now a different scan with another security scanner. You should first Close as many of your open-user app-screens as possible. That is to say, Exit all that you do not need to have open. This with Kaspersky KVRT tool. Download Kaspersky Virus Removal Tool (KVRT) from here: https://www.kaspersky.com/downloads/thank-you/free-virus-removal-tool and save to your Desktop. Next, Select the Windows Key and R Key together, the "Run" box should open. Drag and Drop KVRT.exe into the Run Box. C:\Users\User\DESKTOP\KVRT.exe will now show in the run box. add -dontencrypt Note the space between KVRT.exe and -dontencrypt C:\Users\User\DESKTOP\KVRT.exe -dontencrypt should now show in the Run box. That addendum to the run command is very important. To start the scan select OK in the "Run" box. The Windows Protected your PC window "may" open, IF SO then select "More Info" A new Window will open, select "Run anyway" A EULA window will open, tick both confirmation boxes then select "Accept" Go slow & careful on this part. In the new window select "Change Parameters" In the new window ensure the following boxes are ticked: System memory Startup objects Boot sectors System drive Then select "OK" and "Start scan“. The Kaspersky tool is very thorough so will take a considerable time to complete, please allow it to finish. Also while Kaspersky runs do not use your PC for anything else.. completed: If entries are found, there will be options to choose. If "Cure" is offered, leave as it is. For any other options change to "Delete", then select "Continue". Usually, your system needs a reboot to finish the removal process. Logfiles can be found on your systemdrive (usually C: ), similar like this: Reports are saved here C:\KVRT2020_Data\Reports and look similar to this report_20231103_203000.klr Right click direct onto those reports, select > open with > Notepad. Save the files and attach them with your next reply Have lots of patience, as this will most likely run for many hours. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 2, 2023 Author ID:1598058 Share Posted November 2, 2023 Kaspersky report below. Kaspersky Report.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted November 3, 2023 ID:1598114 Share Posted November 3, 2023 First some housekeeping, and then one Scan. There will be more later after all this. Start Malwarebytes. Click Settings ( gear ) icon. Next, let us make real sure that Malwarebytes does NOT register with Windows Security Center Click the Security Tab. Scroll down to "Windows Security Center" Click the selection to the left for the line "Always register Malwarebytes in the Windows Security Center". { We want that to be set as Off .... be sure that line's radio-button selection is all the way to the Left. thanks. } This will not affect any real-time protection of the Malwarebytes for Windows 😃. now Click the General tab. Under Application updates, click the Check for updates button. When it shows a new version available, Accept it and let it proceed forward. Be sure it succeeds. If prompted to do a Restart, just please follow all directions. Let me know how that goes. Next, the Malwarebytes scan Next, click the small x on the Settings line to go to the main Malwarebytes Window. Next click the blue button marked Scan. When the scan phase is done, be real sure you Review and have all detected lines items check-marked on each line on the left. That too is very critical. >>>>>> 👉 You can actually click the topmost left check-box on the very top line to get ALL lines ticked ( all selected). <<<< 💢 Please double verify you have that TOP check-box tick marked. and that then, all lines have a tick-mark Then click on Quarantine button. Then, locate the Scan run report; export out a copy; & then attach in with your reply. See https://support.malwarebytes.com/hc/en-us/articles/360038479194-View-Reports-and-History-in-Malwarebytes-for-Windows-v 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 4, 2023 Author ID:1598217 Share Posted November 4, 2023 I have repeated all of the steps with my external drives turned off and they all come back clean. I have then reformatted all my drives so no traces of the infection remain. I only have one remaining problem, I can not clear the protection history of windows defender. I have used the three most common methods listed on several websites but it continues to report several days past scan results showing infections regardless of clean scans done today. I could use some help to eliminate this issue. Link to post Share on other sites More sharing options...
Maurice Naggar Posted November 4, 2023 ID:1598260 Share Posted November 4, 2023 Hello. Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. Please Close all open work before you actually do begin this run. FRSTENGLISH,exe program location: Downloads folder. The tool is already on system. That is what we will use. Please download the attached fixlist.txt file and save it to Downloads Fixlist.txt <- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. Right-click with your mouse on FRSTENGLISH and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Downloads folder (Fixlog.txt) . Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. NOTICE: For potential outside readers, This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 4, 2023 Author ID:1598286 Share Posted November 4, 2023 If this was intended to clear the Defender protection history, unfortunately, it did not. Please let me know what to do next. Fixlog.txt Link to post Share on other sites More sharing options...
Solution Maurice Naggar Posted November 4, 2023 Solution ID:1598295 Share Posted November 4, 2023 Hello. Your machine just has a stubborn case where old scan history of Microsoft Defender refuses to go away. It is only the "history" that is at the base of the "visual" issue. On this pass here, I am asking that the run only be done in SAFE mode of Windows. ! Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. Please Close all open work before you actually do begin this run. FRSTENGLISH,exe program location: Downloads folder. The tool is already on system. That is what we will use. Please download the attached fixlist.txt file and save it to Downloads Fixlist.txt <- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. Now at this point here, Put Windows into SAFE mode. To plan for that, get a hold of and study this Microsoft Support how-to You do a Windows Logoff and follow the directions on the article. Only when in Safe mode , then do the procedure here. Right-click with your mouse on FRSTENGLISH and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Downloads folder (Fixlog.txt) . Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. NOTICE: For potential outside readers, This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm. 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 5, 2023 Author ID:1598351 Share Posted November 5, 2023 The history is now gone. Thank you so much for all your assistance in clearing my computer. Link to post Share on other sites More sharing options...
Maurice Naggar Posted November 5, 2023 ID:1598353 Share Posted November 5, 2023 Please stick with me. I need a report, the Fixlog.txt 1 Link to post Share on other sites More sharing options...
Maurice Naggar Posted November 5, 2023 ID:1598354 Share Posted November 5, 2023 I am very pleased to hear the good news. 😁 👍 Please stick around with me for a bit. I truly need to get from you the log file named Fixlog.txt. I would like to get a new diagnostic readout report. I would recommend getting a readout report as to update status of some key apps. Temporarily disable Microsoft SmartScreen to download the next software below Download SecurityCheck by glax24 from here and save the tool on the desktop. If Windows's SmartScreen block that with a message-window, then Click on the MORE INFO spot and over-ride that and allow it to proceed. This tool is safe. Smartscreen is overly sensitive. Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow to run & go forward Wait for the scan to finish. It will open in a text file named SecurityType.txt. Close the file. Attach it with your next reply. You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt 1 Link to post Share on other sites More sharing options...
DRSaylor Posted November 5, 2023 Author ID:1598355 Share Posted November 5, 2023 Here are the files you asked for. Fixlog.txt SecurityCheck.txt Link to post Share on other sites More sharing options...
Recommended Posts