Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Windows 10 Trojan message


  • Please log in to reply
67 replies to this topic

#1 husky1954

husky1954

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 02:29 PM

I got a message saying Windows Defender reported my computer has a trojan.

 

The message consisted of 2 popup windows that will not close.   I closed the browser with task manager.

Also told me to call windows support with an 877 number.

This looks like some kind of fake message to me.  

will do a screen print if needed.



BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 58,110 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:02 PM

Posted 20 June 2024 - 03:32 PM

Greetings and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

===================================================

Ground Rules:
  • First, please keep in mind most of us at BleepingComputer volunteer our assistance for your benefit in your time of need. Please try to match our commitment to you with your patience toward us.
  • It is important to not run any tools or take any steps other than those I will provide for you.
  • Please perform all steps in the order they are listed. If things are not clear or you experience problems be sure to stop and let me know.
  • Please copy and paste all logs into your post unless otherwise requested.
  • When your computer is clean I will let you know, provide instructions to remove tools and reports, and offer you information about how you can combat future infections.
  • If you do not reply to your topic after 5 days I will assume it has been abandoned and I will close it.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and let me know.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for 64 bit systems and note where the file is saved (Desktop, Downloads, etc.) <<< Important
  • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
  • Right click on the icon and select Run as administrator
  • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of each report in separate reply windows
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST.txt
  • Addition.txt

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#3 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 04:09 PM

Hi Gary

Ty for your help.

 

Downloaded Farbar.   File is in Downloads.   Clicked on it and it said what do you want to use to open this file.

 

 

Husky/Mike



#4 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 58,110 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:02 PM

Posted 20 June 2024 - 06:48 PM

Please do this. If it is unsuccessful boot into Safe Mode and try to run FRST64.exe.

===================================================

Rkill

-------------------
  • Please download all 3 versions of RKill by Grinler, not including the zip version, and save them to your desktop
  • Disable your anti-malware software. Please refer to this page if you are not sure how.
  • Double click on Rkill to launch the program. If one download version does not launch try a different one.
  • Note: You may have to run Rkill a few times before it is successful
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • Please copy and paste the contents of the Rkill report that will appear on your desktop in your reply (file is also located at c:\rkill.log)
  • Do not reboot your computer after running Rkill. If your computer reboots run Rkill again before continuing on
  • If nothing happens or if the tool does not run, please let me know in your next reply.
  • Attempt to run a FRST scan and post the results
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • FRST reports

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#5 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 08:08 PM

Ok booted in safe mode. Can not down load. Cannot get out of safe mode

#6 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 08:09 PM

Also tried to cilcklink to krill did not work

#7 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 08:13 PM

Also booted up on my tablet to contact you

#8 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 08:35 PM

I have an old computer. Will try to download krill.

#9 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 20 June 2024 - 09:53 PM

Was able to get out of safe mode by using msconfig.
Searched for Rkill and downloaded.
Ran it. It disabled windows defender.
Ran Rkill64. It disabled windows defender

#10 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 21 June 2024 - 07:16 AM

copy was not working last night.

here is the results of Rkill.

Rkill 2.9.1 by Lawrence Abrams (Grinler)
Copyright 2008-2024 BleepingComputer.com
More Information about Rkill can be found at this link:
 
Program started at: 06/20/2024 10:56:28 PM in x64 mode.
Windows Version: Windows 10 Home 
 
Checking for Windows services to stop:
 
 * No malware services found to stop.
 
Checking for processes to terminate:
 
 * No malware processes found to kill.
 
Checking Registry for malware related settings:
 
 * No issues found in the Registry.
 
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
 
Performing miscellaneous checks:
 
 * Windows Defender Disabled
 
   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001


#11 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 58,110 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:02 PM

Posted 21 June 2024 - 09:07 AM

It sounds like you were able to download FRST64.exe but unable to run it. If that is the case, you do not need to download it after booting into Safe Mode, simply try to launch the already downloaded file.

Did you try to run a FRST scan immediately after successfully running Rkill?
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#12 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 21 June 2024 - 09:09 AM

I installed Malwarebytes and ran it. Also I had to run Rkill 3 or 4 times.

I ran Rkill this morning again after booting.


Edited by husky1954, 21 June 2024 - 09:12 AM.


#13 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 58,110 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:02 PM

Posted 21 June 2024 - 09:24 AM

Please don't run any tools unless requested or take independent actions.

Please see my previous post.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#14 husky1954

husky1954
  • Topic Starter

  •  Avatar image
  • Members
  • 83 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Eagle, CO
  • Local time:08:02 PM

Posted 21 June 2024 - 09:29 AM

Should I download FRST64.exe and run it?

 

Sorry for running things.   I had surgery for cataracts Wednesday and I had some problems reading yesterday.

Seeing better today.


Edited by husky1954, 21 June 2024 - 09:37 AM.


#15 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 58,110 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:08:02 PM

Posted 21 June 2024 - 09:50 AM

No problem, we just need to be on the same page. Glad you are doing better.

Yes, here are the instructions again.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for 64 bit systems and note where the file is saved (Desktop, Downloads, etc.) <<< Important
  • If your computer language is other than English right click on the FRST64 icon and rename it to FRST64english
  • Right click on the icon and select Run as administrator
  • Note: If you receive any warning about the download it is a false positive and you can ignore it. Click on More info to get the Run anyway option
  • Click Yes to the disclaimer
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of each report in separate reply windows
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST.txt
  • Addition.txt

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69




4 user(s) are reading this topic

2 members, 2 guests, 0 anonymous users


    husky1954, Oh My!