Help with FRST

Status
Not open for further replies.

gamblinglover23

New Member
Thread author
Oct 2, 2023
5
I have scanned using FRST and the files created are attached, I need help getting a fixlist.txt file
 

Attachments

  • Addition.txt
    88.4 KB · Views: 2
  • FRST.txt
    39.6 KB · Views: 2

gamblinglover23

New Member
Thread author
Oct 2, 2023
5
For context I am unable to access websites such as "malwarebytes.com" or similar domains, scanning with MalwareBytes results in a bitcoin miner being found, even if i quarantine it and delete it itll come back. My computer tries to connect to the website "xml.miners2.com" very frequently. When I don't have task manager open my computer is quite slow but if i open task manager it becomes as normal again. Having performance tab open shows it being at normal rates until considered "idle" when the 3D tab on my GPU spikes to 100% and my cpu goes to 90% activity.
 

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hello, Welcome to MalwareTips.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download the attached Fixlist.txt file to the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the FRST.txt log you have submitted.

Run FRST and click Fix only once and wait.

The Computer will restart when the fix is completed.

It will create a log (Fixlog.txt) please post it to your reply.
===

If any remaining issues please run this scan.

Sophos Virus Removal Tool

Please download Sophos Virus Removal Tool and save it to your computer's Desktop.
  • Right-click the icon and select Run as administrator.[/*]
  • Click Yes to accept any security warnings that may appear.[/*]
  • Click the Next button.[/*]
  • Select 'I accept the terms in the license agreement', then click Next twice.[/*]
  • Click the Install button and wait until the installation is complete.[/*]
  • Click the Finish button. The tool created a shortcut icon on the Desktop of your computer.[/*]
  • Now, double-click the Sophos Virus Removal Tool shortcut icon to run the tool.[/*]
  • Click Yes to accept any security warnings that may appear.[/*]
  • After it updates and a "Start Scanning" button appears in the lower right:
    • Disconnect from the Internet or physically unplug your Internet cable connection.[/*]
    • Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.[/*]
    • Temporarily disable your anti-virus and real-time anti-spyware protection.[/*]
    [/*]
  • Click the "Start Scanning" button in the lower right to start the scan.[/*]
  • After starting the scan, do not use the computer until the scan has completed.[/*]
  • When finished, if it detected anything there will be a "Start Clean-up" button, click it and allow it to finish.[/*]
  • When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.[/*]
  • If any threats are found click Details, then View Log file (bottom left-hand corner).[/*]
  • Copy and paste its contents in your next reply and note any errors encountered.[/*]
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup.[/*]
  • Click Exit to close the program.[/*]
  • If no threats were found, please confirm that result.[/*]
Note: Whenever necessary, the log will be in the following location:

Windows Vista and above:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs\SophosVirusRemovalTool.log

Please post the contents of the log in your next reply and note any errors encountered.
===


Let me know of any remaining issues.
 

Attachments

  • Fixlist.txt
    11.3 KB · Views: 7

gamblinglover23

New Member
Thread author
Oct 2, 2023
5
Hello, Thanks for coming back to me about this. I have used the fixlist and the fixlog is attached. as I mentioned in my own reply the malware has blocked access to certain security websites, "Cybersecurity as a Service Delivered | Sophos" included. Is there a mirror I can use to download it?
Added note, Malwarebytes no longer detects any malware, nor do I get alerts about any malicious connections to websites but I can still not access malwarebytes nor the sophos website.
 

Attachments

  • Fixlog.txt
    25.4 KB · Views: 0

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hi,

Let's see what we can find in the <<< Registry. >>>

Run the Farbar program .exe as an Administrator.

In the Search text area, copy and paste the following:
Sophos;Malwarebytes
Once done, click on the Search Registry button and wait for FRST to finish the search
On completion, a log will open in Notepad. Copy and paste its content in your next reply
====
 

gamblinglover23

New Member
Thread author
Oct 2, 2023
5
Okay, the file generated was quite large and I have instead attached it below.
 

Attachments

  • SearchReg.txt
    336.2 KB · Views: 3

nasdaq

Moderator
Verified
Staff Member
Nov 5, 2019
1,431
Hii,

No policy restrictions were found in your log.


I suggest your contact Sophos and report this problem.


Good luck
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top