egg4 Posted December 5, 2023 ID:1603522 Share Posted December 5, 2023 Hello! I found the Atruic Service in task manager, and i want to remove it permently. when i scan using Malwarebytes it is not dected. how can i remove this virus permently. Link to post Share on other sites More sharing options...
Porthos Posted December 5, 2023 ID:1603524 Share Posted December 5, 2023 @egg4 Let's get the info to get the process started. Please do the following so that we may take a closer look at your system for any possible infections. Do these 2 steps FIRST so that files and folders are set to SHOW, plus also, Turn OFF Windows Fast Start. Show-Hidden-Folders-Files-Extensions https://forums.malwarebytes.com/topic/299345-show-hidden-folders-files-extensions/ Disable-Fast-Startup https://forums.malwarebytes.com/topic/299350-disable-fast-startup/ Then please restart the computer and do the following. WARNING: Do Not click the Repair option under Advanced unless requested by a Malwarebytes support agent or authorized helper NOTE: The tools and the information obtained are safe and not harmful to your privacy or your computer, please allow the programs to run if blocked by your system. Download the Malwarebytes Support Tool In your Downloads folder, open the mb-support-x.x.x.xxx.exe file In the User Account Control pop-up window, click Yes to continue the installation Run the MBST Support Tool In the left navigation pane of the Malwarebytes Support Tool, click Advanced In the Advanced Options, click Gather Logs. A status diagram displays the tool is Getting logs from your machine A zip file named mbst-grab-results.zip will be saved to the Desktop or on the hidden Public desktop (usually C:\Users\Public\Desktop), please upload that file on your next reply Then be patient for the next expert to take your case. Thank you 1 Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 5, 2023 ID:1603526 Share Posted December 5, 2023 Hello. My name is Maurice. I will guide you. Removing pesky malware can be an involved set of tasks over separate runs. Have much patience. Follow my directions. Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Only run the tools I guide you to. Do not run online games while case is on-going. Do not do any free-wheeling web-surfing. The removal of malware isn't instantaneous, please be patient. Cracked or or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure. Please stick with me until I give you the "all clear". If your system is running Discord, please be sure to Exit out of it while this case is on-going. Please do the steps listed before by Porthos. and then Let's do one special run with Malwarebytes Adwcleaner. It will not take much time, Read over all lines before starting so that you have a good understanding of the whole method. Take your time and go careful. I ant to make sure you select all of what I list below - before- pressing the "scan" button. First download & save it download link Then go to where the EXE file is saved. Start Adwcleaner. Do not rush. There are a few first choices to set as I have listed below. Reply YES at the Windows prompt to allow the program to proceed and make changes. That is the usual Windows security prompt. When AdwCleaner starts, on the left side of the window, click on “Settings” and then enable these repair actions on that tab-window by clicking their button to the far-right for ON status Delete IFEO keys Delete tracing keys Delete Prefetch files Reset Proxy Reset IE Policies Reset Chrome policies Reset Winsock Reset HOSTS file ONLY after you have set the selections above ....only after that ..... Now On the left side of the AdwCleaner window, click on “Dashboard” and then click “Scan” to perform a computer scan. This can take several minutes. When the AdwCleaner scan is completed it will display all of the items it has found. Click on the “Quarantine” button To remove what it found. AdwCleaner will now prompt you to save any open files or data as the program will need to close any open programs before it starts to clean. Click on the “Continue” button to finish the removal process. Guide article Link to post Share on other sites More sharing options...
egg4 Posted December 6, 2023 Author ID:1603736 Share Posted December 6, 2023 Here's the file, I appreciate your help, what should I do next? mbst-grab-results.zip Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 6, 2023 ID:1603757 Share Posted December 6, 2023 Save the next download to either the Desktop, or else, to the Downloads folder. download & save a new copy of the tool FRST64.exe from this link Go to where FRST64 was saved. RIGHT-click on FRST64.exe and select Run as Administrator and tap ENTER. And reply YES to allow to proceed. When the tool opens click Yes to the disclaimer. And be very sure to TICK the box for Addition.txt Press the Scan button. It will make a log (FRST.txt & Addition.txt) in the same directory the tool is run Have patience since the run may take something like 10 or so minutes (less depending on your hardware speed) Close Notepad IF those show up on Notepad. Just please Attach the 2 files FRST.txt +Addition.txt with your next reply. Link to post Share on other sites More sharing options...
egg4 Posted December 6, 2023 Author ID:1603777 Share Posted December 6, 2023 hello when i try to download FRST64.exe i get multiple warnings that it is a virus should i still download it? Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 7, 2023 ID:1603789 Share Posted December 7, 2023 (edited) Yes, get around that message.. Temporarily disable Microsoft SmartScreen to prevent the block by the Smartscreen.. If the download is still blocked...... If Windows's SmartScreen block that with a message-window, then Click on the MORE INFO spot and over-ride that and allow it to proceed. FRST64 is safe, and is widely used in the security community. Examples of Smart Screen preventing the download Click the three... dots and select Keep When the User Account Control window appears, click Yes. To accept the Disclaimer of warranty, click Yes. Edited December 7, 2023 by Maurice Naggar 1 Link to post Share on other sites More sharing options...
egg4 Posted December 7, 2023 Author ID:1603792 Share Posted December 7, 2023 i disabled Microsoft SmartScreen how this message keeps on stopping me. Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 7, 2023 ID:1603802 Share Posted December 7, 2023 ENGLISHFRST.zip <<--save this zip file to your Desktop Extract the content to the Desktop. ENGLISHFRST is another name for FRST. Use that to run the reports I requested. IF you still get block / rejection message, It is most likely due to the presence of Reason Cybersecurity. If so, you must TURN OFF Reason Cybersecurity antivirus !!! Link to post Share on other sites More sharing options...
egg4 Posted December 7, 2023 Author ID:1603810 Share Posted December 7, 2023 here are the files FRST.txt +Addition.txt. what are the next steps? FRST.txt Addition.txt Link to post Share on other sites More sharing options...
Solution Maurice Naggar Posted December 7, 2023 Solution ID:1603811 Share Posted December 7, 2023 (edited) For the next procedure, we must disable RAV ( Reason) antivirus. But if you do not have a paid license for RAV you need to Uninstall it. To Uninstall see https://malwaretips.com/blogs/remove-rav-antivirus/ If you do have a paid license for RAV, then TURN OFF RAV before we do the procedure below. For Turning off, see this Youtube video https://www.youtube.com/watch?v=fM2viCCOUTk ( disregard ads at the beginning) Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. NOTE-1: This will remove the "Atruic" malware. "Atruic" is the display name it shows on Task Manager. But internally this one here is a brand new variant of the malware. This custom fix will run a scan to check that all Microsoft operating system files are valid and not corrupt and attempt to correct any invalid files. It will attempt to run some scans with Microsoft Defender antivirus. It will attempt to clear Cache files of web browsers. It will attempt to clear temporary file areas. It rebuilds the Winsock. Depending on the speed of your computer this fix may take 50-55 minutes or more. Please Close all open work before you actually do begin this run. ENGLISHFRST.exe program location: C:\Users\jacqu\Desktop\ENGLISHFRST folder. . Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder. Fixlist.txt<- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. With File Explorer, go to C:\Users\jacqu\Desktop\ENGLISHFRST folder Right-click with your mouse on ENGLISHFRST.exe and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop\ENGLISHFRST folder (Fixlog.txt) . Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply. NOTICE: For potential outside readers, This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause harm. Edited December 7, 2023 by Maurice Naggar 1 Link to post Share on other sites More sharing options...
egg4 Posted December 7, 2023 Author ID:1603930 Share Posted December 7, 2023 thank you, it seems like the virus has been removed, is there anything else i need to do at this point? Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 7, 2023 ID:1603937 Share Posted December 7, 2023 Yes, stick with me. I definitely need the Fixlog report from Desktop\ENGLISHFRST folder (Fixlog.txt) , plus, SecurityCheck by glax24 I would like you to run a tool named SecurityCheck to inquire about the current security update status of some applications. Download SecurityCheck by glax24: https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe If Microsoft SmartScreen blocks the download, click through to save the file This tool is safe. Smartscreen is overly sensitive. If SmartScreen blocks the file from running click on More info and Run anyway Right-click with your mouse on the Securitycheck.exe and select "Run as administrator" and reply YES to allow to run & go forward Wait for the scan to finish. It will open a text file named SecurityCheck.txt Close the file. Attach it with your next reply. You can find this file in a folder called SecurityCheck, C:\SecurityCheck\SecurityCheck.txt Thank you Link to post Share on other sites More sharing options...
egg4 Posted December 8, 2023 Author ID:1604113 Share Posted December 8, 2023 hello, here are the files you requested. Fixlog.txt SecurityCheck.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 9, 2023 ID:1604222 Share Posted December 9, 2023 Hello. Thanks for the reports. The custom-fix run result is very good. The rogue-malware service has been squashed. I am going to list a few things to do. A request please I would like to get a copy of what we placed in Quarantine, from the runs I had you do. Please. Using Windows File Explorer, Navigate to C:\FRST folder on your system. Expand the folder so you see all contents. Right click on Quarantine > Send to > Compressed (zipped) folder Upload the archive in your next reply If archive is too big you can upload here > https://wetransfer.com/ ( 2 ) Using File Explorer, Go to C:\Users\jacqu\Desktop\ENGLISHFRST. RIGHT-click on ENGLISHFRST.exe and select Run as Administrator and tap ENTER. And reply YES to allow to proceed. When the tool opens click Yes to the disclaimer. And be very sure to TICK the box for Addition.txt Press the Scan button. It will make a log (FRST.txt & Addition.txt) in the same directory the tool is run Have patience since the run may take something like 10 or so minutes (less depending on your hardware speed) Close Notepad IF those show up on Notepad. Just please Attach the 2 files FRST.txt +Addition.txt with your next reply. ( 3 ) Download Farbar's Service Scanner utility and Save to your Desktop. Right-Click on fss.exe and select Run As Administrator. Answer Yes to ok when prompted. If your firewall then puts out a prompt, again, allow it to run. Once FSS is on-screen, be sure the following items are check-marked: Internet Services Windows Firewall System Restore Security Center/Action Center Windows Update Windows Defender Other services Click on "Scan". It will create a log (FSS.txt) in the same directory the tool is run. Please attach that file. ( 4 ) When you get some quiet time, these applications need your attentio, Notepad++ (64-bit x64) v.8.4.8 Warning! Download Update NVIDIA GeForce Experience 3.27.0.112 v.3.27.0.112 Warning! Download Update Microsoft 365 v.1.0 Warning! Download Update How Install Office updates? Google Drive v.1.0 Warning! Download Update Microsoft OneDrive v.23.174.0820.0003 Warning! Download Update Zoom v.5.12.0 (8964) Warning! Download Update VLC media player v.3.0.18 Warning! Download Update ---------------------------- [ UnwantedApps ] ----------------------------- SpyHunter 5 v.5.15.13.318 Warning! Suspected demo version of anti-spyware, driver updater or optimizer. Computer experts no longer recommend this program. Wondershare Helper Compact 2.5.3 v.2.5.3 Warning! Application is distributed through the partnership programs and bundle assemblies. Uninstallation recommended. Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 11, 2023 ID:1604548 Share Posted December 11, 2023 Hello ((( ping ))) @egg4 How is it going ? Link to post Share on other sites More sharing options...
egg4 Posted December 12, 2023 Author ID:1604707 Share Posted December 12, 2023 hello, here are the files. Quarantine.zip FRST_12-12-2023 00.03.10.txt Addition_12-12-2023 00.03.10.txt FSS.txt Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 12, 2023 ID:1604773 Share Posted December 12, 2023 (edited) Thank you very much. I appreciate getting the Quarantine collection, and the reports. The reports look quite good. The pest "Atruic service / atructsoft" is gone. We just need to remove some leftover traces ( now inert), Please run the following custom script. Read all of this before you start. The meaning of the "Fix button" operation here is just to run a custom script just for this particular machine. This will run very fast. Please Close all open work before you actually do begin this run. ENGLISHFRST.exe program location: C:\Users\jacqu\Desktop\ENGLISHFRST folder. . Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder. Fixlist.txt<- < - - - - NOTE. It's important that both files, FRSTENGLISH, and fixlist.txt are in the same location or the fix will not work. With File Explorer, go to C:\Users\jacqu\Desktop\ENGLISHFRST folder Right-click with your mouse on ENGLISHFRST.exe and select "Run as Administrator" and reply Yes and allow it to proceed when prompted. That is important. next, press the Fix button just once and wait. You will see a green-color scroll display while FRST is running. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop\ENGLISHFRST folder (Fixlog.txt) . Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. The system will be rebooted after the fix has run. Attach FIXLOG.txt with next reply. Edited December 12, 2023 by Maurice Naggar Link to post Share on other sites More sharing options...
egg4 Posted December 13, 2023 Author ID:1605008 Share Posted December 13, 2023 hello it seems like i have run into an issue. As you can see FRSTENGLISH, and fixlist.txt are in the same location, but it says fixlist.txt is not found. Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 13, 2023 ID:1605018 Share Posted December 13, 2023 If FRSTENGLISH has a current open window, Close it. Look very very close on the Folder. I must have you to Delete "Fixlist (1) - Copy.txt You must also Delete Fixlist (1).txt Be extremely careful on this next save. The name of the file has to stay Fixlist.txt Please download the attached fixlist.txt file and save it to C:\Users\jacqu\Desktop\ENGLISHFRST folder. Fixlist.txt Re-verify it was saved properly !!! Once that is taken care of, do the Fix run like I had listed before. Link to post Share on other sites More sharing options...
egg4 Posted December 14, 2023 Author ID:1605067 Share Posted December 14, 2023 Fixlog.txt 1 Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 14, 2023 ID:1605081 Share Posted December 14, 2023 Very very beneficial run. It cleaned up the containers where the malware was stored. As a next step, I suggest the following: This is for a scan with ESET Onlinescanner (free). ESET is a well-respected, well-known entity and tool. ESET Onlinescanner checks for viruses, other malware, adwares, & potentially unwanted applications. This here you can start & once it is under way, you can leave the machine alone & let it run over-night. No need to keep watch once it starts the actual scan run. Go to https://download.eset.com/com/eset/tools/online_scanner/latest/esetonlinescanner.exe It will start a download of "esetonlinescanner.exe" Save the file to your system, such as the Downloads folder, or else to the Desktop. Go to the saved file, and double click it to get it started. If upon launching the Esetonlinescanner, there is a windows-message box displaying A driver cannot load on this device. Driver ehdrv.sys then, please, TICK the check-box "Don't show this message again" and then, click the Close button on that window-box. The ESET scan will proceed forward. When presented with the initial ESET options, click on "Computer Scan". Next, when prompted by Windows, allow it to start by clicking Yes When prompted for scan type, Click on CUSTOM scan and select C drive to be scanned Look at & tick ( select ) the radio selection "Enable ESET to detect and quarantine potentially unwanted applications" and click on Start scan button. Have patience. The entire process may take an hour or more. There is an initial update download. There is a progress window display. You may step away from machine &. Let it be. That is, once it is under way, you should leave it running. It will run for several hours. At screen "Detections occurred and resolved" click on blue button "View detected results" On next screen, at lower left, click on blue "Save scan log" View where file is to be saved. Provide a meaningful name for the "File name:" On last screen, set to Off (left) the option for Periodic scanning Click "save and continue" Please attach the report file so I can review Link to post Share on other sites More sharing options...
egg4 Posted December 16, 2023 Author ID:1605571 Share Posted December 16, 2023 Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 16, 2023 ID:1605575 Share Posted December 16, 2023 Threats were found & removed by ESET Onlinescanner. We should run a different scanner just to see if any other threats are around. The Microsoft Safety Scanner is a free Microsoft stand-alone virus scanner that can be used to scan for & remove malware or potentially unwanted items from a system. This tool does not install. It is run on-demand. This link is for the 64-bit version of MSERT.exe . Be sure you save the file first Upon completion of the save, Please make sure you Exit out of any other program you might have open so that the sole task is to run the following scan. That goes especially for web browsers, make sure all are fully exited out of and messenger programs are exited and closed as well Launch MSERT.exe Accept the agreement terms of Microsoft Select CUSTOM scan Look on Scan Options & select CUSTOM scan & then select the C drive to be scanned. Then start the scan. Have lots of patience. Once you start the scan & you see it started, then leave it be. Once you see it has started, take a long long break; walk away. Do not pay credence if you see some intermediate early flash messages on screen display. The only things that count are the End result at the end of the run. Again, any on-screen display about repeat 'infection' is not to be relied on. Ignore those. We only rely on the end result that is on the log-report-file. This is likely to run for many hours ( depending on number of files on your machine & the speed of hardware.) The log is named MSERT.log the log will be at Windows\debug\msert.log Please attach that log with your reply It is normal for the Microsoft Safety Scanner to show 'detections' during the scan process on the screen itself. It is scanning for basically all bread crumbs or traces of files and registry entries that "might" be or have been part of some infection or previous infection. That DOES NOT mean the computer is infected. Once the scan has been completed it uploads the log to their Cloud service which then uses Artificial Intelligence to determine if in fact any of the traces are an infection or not. Link to post Share on other sites More sharing options...
Maurice Naggar Posted December 18, 2023 ID:1605832 Share Posted December 18, 2023 Hello. Good morning. Kindly advise about the status of the scan. I am also curious if the "Atruic" malware pest is still around ? Link to post Share on other sites More sharing options...
Recommended Posts