#Dont know if i successfully removed malware.

1 messages · Page 1 of 1 (latest)

storm brook
#

I have downloaded a program from a user on discord who i knew (he probably got hacked)

I ran it and it started a command prompt with a loading bar and nothing else. When it got close to the end Defender quarantined a program called spooler in the windows folder. I deleted it, the action was succesful. I have deleted the folder that the program came in. I am doing a Kaspersky full scan right now. Sould i be worried that my PC is still infected? Since then i havent noticed anything suspicious, cpu and gpu usage is normal, none of my accounts have login attempts.

Kaspersky and hitmanpro hasnt found anything

tender blade
#

Burn the drive and get a new one 🤣

storm brook
rancid spire
storm brook
#

they said it could maybe inject itself into ther files tho

rancid spire
#

The most simple way to be sure that you got rid of the malware is to re-install Windows completely, or, even safer, get a new disk and destroy/never use the old one again

fluid wyvern
#

Did you do a full virus scan?

#

With all the settings on so it checks everything?

urban whale
#

Literally shows everything that is starting with Windows.

fluid wyvern
#

Or you could do a boot scan

#

That might actually be the same thing that we’re talking about

storm brook
#

and hitmanpro

fluid wyvern
#

Huh. That should have removed the malware

storm brook
#

didnt find nothing

fluid wyvern
#

Yeah, then I doubt the problem is malware

storm brook
#

well i dont have a problem really

#

im just paranoid

urban whale
#

reasonable.

storm brook
#

cus they say once u launch it it spreads

#

all tru the system

fluid wyvern
#

Do you have a computer that you could afford losing?

urban whale
#

it depends on the virus...

fluid wyvern
#

Huh

storm brook
#

i only have one

urban whale
#

well if you have A AntiVirus running you should be fine, consider checking the programs that start with Windows and you should be good for the most part..

storm brook
#

how is cmd.exe not a verified program

#

bruh

urban whale
#

uh

storm brook
#

this was installed before the virus tho

urban whale
#

consider dism /Online /Cleanup-Image /RestoreHealth and sfc /scannow

storm brook
#

now im not good at this what do those do

#

and where do i do those

#

if you mind explaining

urban whale
#

sfc = system file checker

#

so it checks for system files that might be corrected and attempts to fix them

#

dism is uhh... it basically checks for windows image file corruptions and fixes them too..

storm brook
#

i should do these in command prompt right?

urban whale
#

administrator one, yes.

storm brook
#

alright, thanks

#

what is this hlkm thing tho

urban whale
#

well

#

I guess you could navigate to the reg location and check it

#

take a screenshot and I might be able to help.

storm brook
#

has stuff like this too

urban whale
# storm brook

check for unverified first, I would say that's the most important!

storm brook
#

ton of unverified stuff

urban whale
#

dism should fix most

storm brook
#

but my antivirus in there too

#

should i run this (dism /Online /Cleanup-Image /RestoreHealth) whole thng at once or once per slash?

#

im sorry im a noob

urban whale
#

all

#

it's the arguments

#

they have to specified else dism doesn't know what to do.

storm brook
#

ok its doing something its on 3 percent

urban whale
#

ye ye, just let it do its thing!

storm brook
#

when i try to click here

#

i get this

urban whale
#

it's a registry key..

#

open regedit and try to navigate to the key specified...

#

Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers

#

paste this on the regedit path

#

up here

#

and take a screenshot of what keys there are.

storm brook
#

when i do that

#

i just get an error sound

#

and it puts me back where it started

urban whale
#

what about this: Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer

storm brook
#

ooh

#

the delete all

#

didnt delete the computer part

#

from the beginning

urban whale
#

hm

storm brook
#

so it was like this Computer\Computer\

urban whale
#

Unlucky

storm brook
urban whale
#

weird

#

nothin'

#

did dism finish yet?

storm brook
#

ok now ihave a windows thats activated by "MAS" this is just that right?

#

also i think it matches the activation date

urban whale
#

uh

storm brook
#

so i didnt buy a real key

#

i didnt do the process

urban whale
#

well

storm brook
#

a friend of mine did

urban whale
#

sus

storm brook
#

well ur pc has legit windows right?

urban whale
#

yes

storm brook
#

then i thnk its just that

urban whale
#

oh well

storm brook
#

cus he said its somehow cracked

#

cus we didnt pay

urban whale
#

no comment

storm brook
#

this finished

urban whale
#

what about dism?

storm brook
#

55

storm brook
#

weird

#

ok this done too

urban whale
#

alright restart.

storm brook
#

ok then brb

#

k im done

urban whale
#

check autoruns

#

if most of them are ok now!

storm brook
#

def less

#

but still quite a éot

#

lot

#

like all these

urban whale
#

I don't think you're gonna be able to do anything about those..... they most likely have no license..

#

signature*

storm brook
#

yeah

#

when i run law

#

it says unknown publisher

#

what are these

#

and why they not found

urban whale
#

that's not an issue by itself...

storm brook
#

oh ok

#

well defenetely way less unverified stuff that i dont know what they are

urban whale
#

syswow64 is just the compatibility layer between 32-bit applications and the system.

storm brook
#

oh

urban whale
#

just make sure you have antivirus on, and you should be 10/10.

#

always be sus of every application you download.

#

signature is ez verifier of non-virus applications.

storm brook
#

Defenitely wont be launching random exe-s after this

#

thanks for the help i appreciate it🤍

#

gonna go sleep its 4 am here