Jump to content

Possible UEFI Infection


Go to solution Solved by JSntgRvr,

Recommended Posts

Hi there I did a fresh install of windows after my windows was acting weird and I think the malware is still there after the fresh install.  All my programs seems to be getting copied and replaced.

I`ve tried flashing my bios with a new version but didn`t have any effect.  Nothing seems to show up on Malwarebytes or windows defender but I can actively see new folders and programs being created.

 

 

 

AdwCleaner[S00].txt Addition_03-08-2024 10.35.02.txt FRST_03-08-2024 10.35.02.txt Malwarebytes Scan Report 2024-08-03 093202.txt

Link to post
Share on other sites

FRST64 was saved as C:\Users\ShiUsagi\Downloads\FRST64.exe

  • Download the enclosed file  Fixlist.txt
  • Save it in the same location FRST64 is saved. 
  • Start FRST (FRST64) with Administrator privileges
  • This time around Press the Fix button and wait
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please attach this file in your next reply.

Link to post
Share on other sites

The following Fix will empty these folders:

  • Windows Temp
  • Users Temp folders
  • Edge, IE, FF, Chrome, and Opera caches, HTML5 storages, Cookies and History
  • Recently opened files cache
  • Discord cache
  • Java cache
  • Steam HTML cache
  • Explorer thumbnail and icon cache
  • BITS transfer queue (qmgr*.dat files)
  • Recycle Bin
  • Hosts file will be reset

Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns, please ask before running this fix.

The system will be rebooted after the fix has run.

FRST64 was saved as C:\Users\ShiUsagi\Downloads\FRST64.exe

  • Download the enclosed file  Fixlist.txt
  • Save it in the same location FRST64 is saved.  
  • Start FRST (FRST64) with Administrator privileges
  • This time around Press the Fix button and wait
  • When finished, a log file (Fixlog.txt) will pop up and saved in the same location the tool was ran from.

Please attach this file in your next reply.

Dr.Web CureIt!

Please download the Dr.Web CureIt! anti-virus utility
https://free.drweb.com/

You will need to send them an email to obtain a link to download the scanner, please do so

  • The downloaded file will normally have a unique name such as:  q7a9tr4p.exe
  • Close all open applications and locate the downloaded file and double-click to run it
  • The program will take a moment to launch and bring up the License and Update screen
  • Place a check mark to agree to the terms and then click on the Continue button
  • Click the underlined link Select objects for scanning
  • On the top left click the Scanning objects that should automatically check all objects
  • Click the small wrench and make sure there is a check on Automatically apply actions to threats
  • Then click the large button on bottom right Start scanning
  • Once the scan has completed there will be a link named Open report click that and a log named cureit.log should open in Notepad
  • The log is saved in the folder named Doctor Web in the top of your user profile folders
  • Please attach that log on your next reply
Link to post
Share on other sites

  • Root Admin

No one is allowed to access certain files. That folder and many like it are owned by the TrustedInstaller account.

In the vast majority of cases there is no need for you to be browsing into such folders.

Please RESTART the computer and run the following to get NEW fresh logs

 

Scan with SecurityCheck by glax24
https://forums.malwarebytes.com/topic/307301-scan-with-securitycheck-by-glax24/


Scan with FSS Farbar Service Scanner
https://forums.malwarebytes.com/topic/306736-scan-with-fss-farbar-service-scanner/


Scan with Farbar Recovery Scan Tool
https://forums.malwarebytes.com/topic/306601-scan-with-farbar-recovery-scan-tool/

 

Thank you

 

 

 

 

 

Link to post
Share on other sites

The startup program that appeared seems to be windows defender but when I went to the folder it was supposed to be installed in it wasn`t there.

Edge already update

Is it normal when egde isnt open to have 3 background tasks and I closed skype from task manager but it opened itself back up same with edge

 

no programs run by me.jpg

This appeared in startup.jpg

update.jpg

edge.jpg

Link to post
Share on other sites

  • Solution

I don't know what you a trying to say. There are always processes running in the background, even when the process appears to be closed. Windows will keep the process in memory in case it is needed.

Open a command prompt. Type the following and press Enter.

Tasklist

You will see a list of tasks running even if no application is opened.

In the task manager, Right click on the application running and select "Open File Location". The folder containing the file, will open.

As far as malware, your computer is clean. Lets clean-up.

Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10/11 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools

- Delete Restore Points

- Create Restore Point

- Delete now

  • Click the "Run" button.

automatic.png

  • When the tool has finished, it will create and open a log report and delete itself.

A few final recommendations:
 
The following information will help you to keep your computer and data safer as well as improve your overall privacy

Malwarebytes Browser Guard

uBlock Origin

Cybersecurity basics & protection
 
Everything you need to know about cybercrime
https://www.malwarebytes.com/cybersecurity
 
Further reading if you'd like to keep up on the malware threat scene: Malwarebytes Blog  https://blog.malwarebytes.com/
 
Please review the following to help you better protect your computer and privacy
 
Tips to help protect from infection
 
Hopefully, we've been able to assist you with correcting your system issues.
 
Thank you for using Malwarebytes. Please tell your friends and family if they too need assistance with malware removal.

Regards.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.