By clicking “Accept All”, you agree to the storing of cookies on your device to enhance site navigation, analyse site usage, and assist in our marketing efforts
These cookies enable our website and App to remember things such as your region or country, language, accessibility options and your preferences and settings.
Analytic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
I don’t expect to find any malware or other nasties. It was originally installed on my PC by a person, who was sat in front of the PC and logged in as me. The drive has been wiped three times in the last couple of months, with a fresh install of windows each time. It keeps coming back.
I think it’s my windows admin account installing this ‘thing’.
After you've done a fresh install of Windows, do you keep it separated away from your laptop and cloud storage or do you then share sharing files across all three devices?
Unless this person has some kind of custom code they deployed on your PC, then if it was malware it would be picked up by a decent scanner.
Are you sure you're not installing an application, after your fresh Windows install, which is causing this behaviour?
I’m starting to think along the lines of a remote access Trojan, which can then be used to install or doing anything. I’m seeing strange user accounts on the main pc, which as windows users I assume malware won’t detect as something malicious. At the moment the laptop is behaving itself, but that doesn’t mean there isn’t something there. The main pc was good as gold until yesterday.
If it is a RAT phoning home, you should be able to see its network connections using the 'netstat' command.I’m starting to think along the lines of a remote access Trojan, which can then be used to install or doing anything.
If it is a RAT phoning home, you should be able to see its network connections using the 'netstat' command.
That's a command prompt thing, but plenty of guidance on using it if you Google it.
That might give some clues as to what this is and how to deal with it.
Yes, I meant in the event of reinfection.Wouldn't reinstalling Windows have overwritten any Trojans installed?
Your problem lies most likely with the Microsoft Account as it syncs settings over the different devices.
Next using malwarebytes is already a problem, product for the bin at best and below average detection. Bitdefender or Kaspersky are my weapons of choice you pay them money and they do magic. Any free security tool is performing poor at best. If they dont pick it up I guess a browser extension is being installed using the Microsoft Accounts sync setting. The extension might pass scans but starts downloading code after being installed.
Also if you run any 3rd party updates the update server can be infected. e.g ccleaner had that issue.
make a Kaspersky rescue usb https://www.kaspersky.co.uk/downloads/thank-you/free-rescue-disk boot into it and run a full deep scan this will take hours. If it doesn't show up on there, copy the log file, upload it to onedrive or dropbox and share it here.
My current plan is to remove the SSHD from the pc, take the pc to a man to install a new one and install windows, I suspect my problems are coming from previous ‘IT experts’ who aren’t deleting everything from the drive before reinstalling windows.
I’m reading a lot about macros in ms docs, I don’t use any and plan to switch them off and maybe start using google docs, or something similar. I have to find out how nasty things live in pdfs and AutoCAD, both of which I do use a lot. I use jpegs a lot too, another thing to research.
What I still don’t understand is the need to find out what it is, it would seem almost impossible to find out and even then the end result is the same, can’t trust anything.
make a Kaspersky rescue usb https://www.kaspersky.co.uk/downloads/thank-you/free-rescue-disk boot into it and run a full deep scan this will take hours. If it doesn't show up on there, copy the log file, upload it to onedrive or dropbox and share it here.
This is going well, can’t get out of kaspersky, laptop is a brick!
Why do the autocad files come back to you as attachments that's asking for problems can they not describe the amendments or can you not open them on a offline computer with some good anti virus software setup on it
Because I outsource my cad work to others, I don’t actually do anything much other than yap on the phone and type emails. So my subbies email me cad files, which I print as pdfs or on paper and then send to clients, planning, building control, builders, etc.
You don't have to install the OneDrive client on the local PC. Just open a browser, go to https://onedrive.live.com/, sign in and launch files from there. No Synching, no linking - you stay in control
I'm back, not sure how much use this is to anyone, I thought an update might be nice:
@Financial-Modeller it looks to me that cleans up information - it prevents recovery of deleted data by actually over writting it rather than simply marking it deleted.
A good thing to do, but not the same as removing malware.
@estwig, there has to be a better solution.
Don't feel sorry for me, it's my penchant for hackers in shiny PVC that has got me into this. I am digging myself out.
You have in the time you have had to spend on this.the only saving grace is I don't pay for it!