- Apr 9, 2020
- 667
Are you aware that there is a user named wBzcwBE with administrator permissions on your system?
Not yet. I think your system was infected with a Remote Access Trojan (RAT) which was also used to run the ransomware. Those kinds of malware allow a criminal full control over your system.
It means your system is unsafe and all of your accounts are potentially compromised. After cleaning the system you need to put new passwords in place for all of your accounts (email, online banking, everything that's somewhat important). If you have a clean computer somewhere you can already start doing that. If available, enable 2-Factor-Authentication for accounts.
AVG is still not entirely gone from your system and there is one program that slipped my uninstall list (sorry for that).
1. Uninstall Software
2. Farbar Recovery Scan Tool (FRST) Script
3. Browser Reset
Before proceeding, please refer to the following instructions on how you can backup your Favourites/Bookmarks.
As Internet Explorer is an integral part of Windows, please ensure you reset this browser regardless of whether you use it or not.
Is it safe to use my PC and do my work on it or no?
Not yet. I think your system was infected with a Remote Access Trojan (RAT) which was also used to run the ransomware. Those kinds of malware allow a criminal full control over your system.
It means your system is unsafe and all of your accounts are potentially compromised. After cleaning the system you need to put new passwords in place for all of your accounts (email, online banking, everything that's somewhat important). If you have a clean computer somewhere you can already start doing that. If available, enable 2-Factor-Authentication for accounts.
AVG is still not entirely gone from your system and there is one program that slipped my uninstall list (sorry for that).
1. Uninstall Software
- Press the Windows Key
- Search for the following programs, right-click and click Uninstall.
- WinRAR Free Download Packages
- Follow the prompts.
- Note: If you are offered the choice to install additional software, ensure you decline.
- Reboot if necessary.
2. Farbar Recovery Scan Tool (FRST) Script
- Download the attached fixlist.txt
- Important: The file must be saved in the same location as FRST64.exe.
- Double-click FRST64.exe to run the programme.
- Click Fix.
- A log (Fixlog.txt) will open on your desktop. Attach the log to your next reply.
3. Browser Reset
Before proceeding, please refer to the following instructions on how you can backup your Favourites/Bookmarks.
- Internet Explorer: Backup Internet Explorer Favourites
- Firefox: Backup Firefox Bookmarks
- Chrome: Backup Chrome Bookmarks
As Internet Explorer is an integral part of Windows, please ensure you reset this browser regardless of whether you use it or not.
- Internet Explorer: How to reset Internet Explorer settings
- Firefox: Reset Firefox
- Chrome: 1. Turn off syncing 2. Chrome - Reset browser settings