Jump to content

Atruic Service


Go to solution Solved by Maurice Naggar,

Recommended Posts

@egg4

Let's get the info to get the process started.

Please do the following so that we may take a closer look at your system for any possible infections.

Do these 2 steps FIRST so that files and folders are set to SHOW, plus also, Turn OFF Windows Fast Start.
Show-Hidden-Folders-Files-Extensions
https://forums.malwarebytes.com/topic/299345-show-hidden-folders-files-extensions/

Disable-Fast-Startup
https://forums.malwarebytes.com/topic/299350-disable-fast-startup/

Then please restart the computer and do the following.

WARNING: Do Not click the Repair option under Advanced unless requested by a Malwarebytes support agent or authorized helper

NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system.

  • Download the Malwarebytes Support Tool
  • In your Downloads folder, open the mb-support-x.x.x.xxx.exe file
  • In the User Account Control pop-up window, click Yes to continue the installation
  • Run the MBST Support Tool
  • In the left navigation pane of the Malwarebytes Support Tool, click Advanced
  • In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine
  • A zip file named mbst-grab-results.zip will be saved to the Desktop or on the hidden Public desktop (usually C:\Users\Public\Desktop), please upload that file on your next reply

    Then be patient for the next expert to take your case.

Thank you

  • Thanks 1
Link to post
Share on other sites

Hello. :welcome: My name is Maurice. I will guide you.

  • Removing pesky malware can be an involved set of tasks over separate runs. Have much patience. Follow my directions. 
  • Please don't run any other scans, download, install or uninstall any programs while I'm working with you.
  • Only run the tools I guide you to.
  • Do not run online games while case is on-going. Do not do any free-wheeling web-surfing.
  • The removal of malware isn't instantaneous, please be patient.
  • Cracked or or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure.
  • Please stick with me until I give you the "all clear".
  • If your system is running Discord, please be sure to Exit out of it while this case is on-going.

    Please do the steps listed before by Porthos.  and then

  • Let's do one special run  with Malwarebytes Adwcleaner. 
     
    It will not take much time, Read over all lines before starting so that you have a good understanding of the whole method. Take your time and go careful. I ant to make sure you select all of what I list below - before- pressing the "scan" button.
     
    First download & save it
     
    Then go to where the EXE file is saved. Start Adwcleaner.  Do not rush. There are a few first choices to set as I have listed below.
     
    Reply YES at the Windows prompt to allow the program to proceed and make changes. That is the usual Windows security prompt.
     
    When AdwCleaner starts, on the left side of the window, click on “Settings” and then enable these repair actions on that tab-window
    by clicking their button to the far-right for ON status
    Delete IFEO keys
    Delete tracing keys
    Delete Prefetch files
    Reset Proxy
    Reset IE Policies
    Reset Chrome policies
    Reset Winsock
    Reset HOSTS file
     
    ADW-s-1.png.c32838f45f840beb2b835ad51f0a1b7c.png
     
     
    ONLY after you have set the selections above ....only after that .....
    Now On the left side of the AdwCleaner window, click on “Dashboard” and then click “Scan” to perform a computer scan.
     
     
    This can take several minutes.
    When the AdwCleaner scan is completed it will display all of the items it has found. Click on the “Quarantine” button To remove what it found.
     
    AdwCleaner will now prompt you to save any open files or data as the program will need to close any open programs before it starts to clean.
    Click on the “Continue” button to finish the removal process.
     
Link to post
Share on other sites

Save the next download to either the Desktop, or else, to the Downloads folder. download & save a new copy of the tool FRST64.exe from this link

Go to where FRST64 was saved. RIGHT-click on FRST64.exe and select 

Run as Administrator

and tap ENTER. And reply YES to allow to proceed.  

  •  When the tool opens click Yes to the disclaimer.  And be very sure to TICK the box for Addition.txt
  • Press the Scan button.

_frst_scan.jpg

  • It will make a log (FRST.txt & Addition.txt) in the same directory the tool is run
  • Have patience since the run may take something like 10 or so minutes  (less depending on your hardware speed)
  • Close Notepad IF those show up on Notepad.
  • Just please Attach the 2 files FRST.txt +Addition.txt  with your next reply.
Link to post
Share on other sites

Yes, get around that message.. Temporarily disable Microsoft SmartScreen  to  prevent the block by the Smartscreen..

If the download is still blocked...... If Windows's  SmartScreen block that with a message-window, then
                         Click on the MORE INFO spot and over-ride that and allow it to proceed.

FRST64 is safe, and is widely used in the security community.



Examples of Smart Screen preventing the download

02_win7_smart_screen_block_01.jpg.eb05b2   


Click the three... dots and select Keep

03_win7_smart_screen_block_02.jpg.6f4f22


04_win7_smart_screen_block_03.jpg.c483c1

05_win7_smart_screen_block_04.jpg.3f1d4a

 

When the User Account Control window appears, click Yes.

06_uac_block.jpg.1a36bb28a620520d806aa98
 

To accept the Disclaimer of warranty, click Yes.

07_eula_farbar.jpg.c1966a4842ef445bf5cff

Edited by Maurice Naggar
  • Thanks 1
Link to post
Share on other sites

ENGLISHFRST.zip  <<--save this zip file to your Desktop

Extract the content to the Desktop. ENGLISHFRST is another name for FRST. Use that to run the reports I requested.

IF you still get block / rejection message, It is most likely due to the presence of Reason Cybersecurity. If so, you must TURN OFF Reason Cybersecurity antivirus !!!

Link to post
Share on other sites

  • Solution

For the next procedure, we must disable RAV ( Reason) antivirus. But if you do not have a paid license for RAV you need to Uninstall it.
To Uninstall see https://malwaretips.com/blogs/remove-rav-antivirus/

If you do have a paid license for RAV, then TURN OFF RAV before we do the procedure below.
For Turning off, see this Youtube video https://www.youtube.com/watch?v=fM2viCCOUTk    ( disregard ads at the beginning)
 

Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine.

NOTE-1:  This will remove the "Atruic" malware. "Atruic" is the display name it shows on Task Manager. But internally this one here  is a brand new variant of the malware. This custom fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files.  It will attempt to run some scans with Microsoft Defender antivirus. It will attempt to clear Cache files of web browsers.  It will attempt to clear temporary file areas. It rebuilds the Winsock. Depending on the speed of your computer this fix may take 50-55 minutes or more.

Please Close all open work before you actually do begin this run.

ENGLISHFRST.exe program location:   C:\Users\jacqu\Desktop\ENGLISHFRST folder. .

Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder.

Fixlist.txt<- < - - - -

NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work.

With File Explorer, go to C:\Users\jacqu\Desktop\ENGLISHFRST folder

Right-click with your mouse on  ENGLISHFRST.exe and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important.

next, press the Fix button just once and wait.

You will see a green-color scroll display while FRST is running.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop\ENGLISHFRST folder (Fixlog.txt) . Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.

The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply.

NOTICE: For potential outside readers,  This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm.

Edited by Maurice Naggar
  • Thanks 1
Link to post
Share on other sites

Yes, stick with me. I definitely need the Fixlog report      from  Desktop\ENGLISHFRST folder (Fixlog.txt)  , plus,

 

SecurityCheck by glax24              

I would like you to run a tool named SecurityCheck to inquire about the current security update status of some applications.

  • Download SecurityCheck by glax24: https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe
  • If Microsoft SmartScreen blocks the download, click through to save the file
  • This tool is safe.   Smartscreen is overly sensitive.
  • If SmartScreen blocks the file from running click on More info and Run anyway
  • Right-click  with your mouse on the Securitycheck.exe  and select "Run as administrator"  and reply YES to allow to run & go forward
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file.  Attach it with your next reply.
  • You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt

 

image.png

image.png

image.png

 

Thank you

Link to post
Share on other sites

Hello. Thanks for the reports. The custom-fix run result is very good. The rogue-malware service has been squashed. I am going to list a few things to do.

A request please 

I would like to get a copy of what we placed in Quarantine, from the runs I had you do. Please. 

  • Using Windows File Explorer, Navigate to C:\FRST folder on your system. Expand the folder so you see all contents.
  • Right click on Quarantine > Send to > Compressed (zipped) folder
  • Upload the archive in your next reply
  • If archive is too big you can upload here > https://wetransfer.com/

(  2  )

Using File Explorer, Go to C:\Users\jacqu\Desktop\ENGLISHFRST. RIGHT-click on ENGLISHFRST.exe and select 

Run as Administrator

and tap ENTER. And reply YES to allow to proceed.  

  •  When the tool opens click Yes to the disclaimer.  And be very sure to TICK the box for Addition.txt
  • Press the Scan button.

_frst_scan.jpg

  • It will make a log (FRST.txt & Addition.txt) in the same directory the tool is run
  • Have patience since the run may take something like 10 or so minutes  (less depending on your hardware speed)
  • Close Notepad IF those show up on Notepad.
  • Just please Attach the 2 files FRST.txt +Addition.txt  with your next reply.

(   3  ) 

Download   Farbar's Service Scanner utility

and Save to your Desktop.

Right-Click on fss.exe and select Run As Administrator.

Answer Yes to ok when prompted.

If your firewall then puts out a prompt, again, allow it to run.

Once FSS is on-screen, be sure the following items are check-marked:

  • Internet Services
    Windows Firewall
    System Restore
    Security Center/Action Center
    Windows Update
    Windows Defender
    Other services

  

Click on "Scan".

It will create a log (FSS.txt) in the same directory the tool is run.   Please attach that file.  

(  4  )

When you get some quiet time, these applications need your attentio,
Notepad++ (64-bit x64) v.8.4.8  Warning! Download Update

NVIDIA GeForce Experience 3.27.0.112 v.3.27.0.112  Warning! Download Update

Microsoft 365 v.1.0  Warning! Download Update
How Install Office updates?

Google Drive v.1.0  Warning! Download Update
Microsoft OneDrive v.23.174.0820.0003 Warning! Download Update

Zoom v.5.12.0 (8964)  Warning! Download Update

VLC media player v.3.0.18  Warning! Download Update

---------------------------- [ UnwantedApps ] -----------------------------
SpyHunter 5 v.5.15.13.318  Warning! Suspected demo version of anti-spyware, driver updater or optimizer.  Computer experts no longer recommend this program.

Wondershare Helper Compact 2.5.3 v.2.5.3  Warning! Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended.

Link to post
Share on other sites

Thank you very much. I appreciate getting the Quarantine collection, and the reports. The reports look quite good. The pest "Atruic service / atructsoft" is gone. We just need to remove some leftover traces ( now inert),

Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine.

This will run very fast.

Please Close all open work before you actually do begin this run.

ENGLISHFRST.exe program location:   C:\Users\jacqu\Desktop\ENGLISHFRST folder. .

Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder.

Fixlist.txt<- < - - - -

NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work.

With File Explorer, go to C:\Users\jacqu\Desktop\ENGLISHFRST folder

Right-click with your mouse on  ENGLISHFRST.exe and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important.

next, press the Fix button just once and wait.

You will see a green-color scroll display while FRST is running.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop\ENGLISHFRST folder (Fixlog.txt) . Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.

The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply.

Edited by Maurice Naggar
Link to post
Share on other sites

If FRSTENGLISH has a current open window, Close it.  Look very very close on the Folder. I must have you to Delete "Fixlist (1) - Copy.txt

You must also Delete Fixlist (1).txt

Be extremely careful on this next save. The name of the file has to stay Fixlist.txt

Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder.

Fixlist.txt

Re-verify it was saved properly !!!

Once that is taken care of,  do the Fix run like I had listed before.

 

Link to post
Share on other sites

Very very beneficial run. It cleaned up the containers where the malware was stored.

As a next step, I suggest the following:
This is for a scan with ESET Onlinescanner (free). ESET is a well-respected, well-known entity and tool. ESET Onlinescanner checks for viruses, other malware, adwares, & potentially unwanted applications.
This here you can start & once it is under way, you can leave the machine alone & let it run over-night. No need to keep watch once it starts the actual scan run.

Go to https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe

It will start a download of "esetonlinescanner.exe"

  • Save the file to your system, such as the Downloads folder, or else to the Desktop.
  • Go to the saved file, and double click it to get it started.

If upon launching the Esetonlinescanner, there is a windows-message box displaying

A driver cannot load on this device. Driver ehdrv.sys

then, please, TICK the check-box

"Don't show this message again"

and then, click the Close button on that window-box. The ESET scan will proceed forward.

  • When presented with the initial ESET options, click on "Computer Scan".
  • Next, when prompted by Windows, allow it to start by clicking Yes
  • When prompted for scan type, Click on CUSTOM scan  and select C drive to be scanned
  • Look at & tick ( select ) the radio selection "Enable ESET to detect and quarantine potentially unwanted applications"
  • and click on Start scan button.

Have patience. The entire process may take an hour or more. There is an initial update download.
There is a progress window display. You may step away from machine &. Let it be. That is, once it is under way, you should leave it running. It will run for several hours.

  • At screen "Detections occurred and resolved" click on blue button "View detected results"
  • On next screen, at lower left, click on blue "Save scan log"
  • View where file is to be saved. Provide a meaningful name for the "File name:"
  • On last screen, set to Off (left) the option for Periodic scanning
  • Click "save and continue"
  • Please attach the report file so I can review
Link to post
Share on other sites

Threats were found & removed by ESET Onlinescanner. We should run a different scanner just to see if any other threats are around.

The Microsoft Safety Scanner is a free Microsoft stand-alone virus scanner that can be used to scan for & remove malware or potentially unwanted items from a system. This tool does not install. It is run on-demand.

This link is for the 64-bit version of MSERT.exe . Be sure you save the file first

Upon completion of the save, Please make sure you Exit out of any other program you might have open so that the sole task is to run the following scan.
That goes especially for web browsers, make sure all are fully exited out of and messenger programs are exited and closed as well

Launch MSERT.exe
Accept the agreement terms of Microsoft
Select CUSTOM scan
Look on Scan Options & select CUSTOM scan & then select the C drive to be scanned.

Then start the scan. Have lots of patience. Once you start the scan & you see it started, then leave it be.

Once you see it has started, take a long long break; walk away. Do not pay credence if you see some intermediate early flash messages on screen display. The only things that count are the End result at the end of the run.
Again, any on-screen display about repeat 'infection' is not to be relied on. Ignore those.
We only rely on the end result that is on the log-report-file.


This is likely to run for many hours ( depending on number of files on your machine & the speed of hardware.)

The log is named MSERT.log

the log will be at

Windows\debug\msert.log
Please attach that log with your reply

It is normal for the Microsoft Safety Scanner to show 'detections' during the scan process on the screen itself.

It is scanning for basically all bread crumbs or traces of files and registry entries that "might" be or have been part of some infection or previous infection.

That DOES NOT mean the computer is infected. Once the scan has been completed it uploads the log to their Cloud service which then uses Artificial Intelligence to determine if in fact any of the traces are an infection or not.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.