S.O.S TROJAN Trojan:PDF/Phish.RR!MTB
Solvedbazfile Posted messages 58513 Registration date Status Moderator Last intervention -
Hello,
impossible to get rid of Trojan:PDF/Phish.RR!MTB
This Trojan threat is serious and unfortunately still active on my PC (Asus, running Windows 10).
Analysis done with Microsoft Defender, which still finds it but never deletes it even if I perform offline scan as suggested... Malwarebytes free version 4.5.16, as for it, finds nothing....
I don’t know how to get out of this... And I am very worried to know that this thing IS STILL ACTIVE on my PC !!!!! in light of all the scams you find on the internet, I am anxious.
I'm 70 years old and my computer knowledge is rather "basic". I am reaching out to your know-how and skills to get me out of this pickle....
Many thanks in advance for your help.
7 answers
-
Hello.
Download FRST. Once downloaded, save it to the desktop, then right-click FRST and choose Run as administrator. You will see this:Click on Analyse
Note, wait for the messages indicating that the analysis is finished to appear.

At the end of the analysis you will have two text files on the desktop FRST and Addition.

Then send the FRST and ADDITION reports to PJJOINT and then provide the two links generated by PJJOINT in your reply.
bazfile
Security Moderator/Contributor.
a hello, a reply, and a thank you are always appreciated. -
Good evening,
Thank you for the quick response.
I did as requested, but I don't know how to send the links.
Is this the right place? Hoping that it is...
https://pjjoint.malekal.com/files.php?id=20221031_r6m9u10b10q11
https://pjjoint.malekal.com/files.php?id=FRST_20221031_g11o14l7p10w15 -
Your PC is not infected; what Windows Defender found is a compressed file named Backup files 1.zip. It is located on your D drive; here is its path:
D:\DESKTOP-9B3IHMJ\Backup Set 2022-03-14 112354\Backup Files 2022-05-29 090417\Backup files 1.zipThis file is a backup you created; Backup files 1.zip has been flagged as infected by Windows Defender. To stop the alert, you will need to delete it.
You have a few orphaned or obsolete processes. If you want to delete them, do the following:
Procedure to follow in the given order:
1- Open FRST as administrator. To do this, right-click FRST and choose Run as administrator
2 - Copy the entire script that is in the box below:Start:: CreateRestorePoint: CloseProcesses: ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No file ContextMenuHandlers1_S-1-5-21-236780398-2396492830-1613211555-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => -> No file ContextMenuHandlers4_S-1-5-21-236780398-2396492830-1613211555-1001: [ kwpsshellext] -> {28A80003-18FD-411D-B0A3-3C81F618E22B} => -> No file AlternateDataStreams: C:\ProgramData\TEMP:CB0AACC9 [141] SearchScopes: HKU\S-1-5-21-236780398-2396492830-1613211555-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-236780398-2396492830-1613211555-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = FirewallRules: [TCP Query User{FEAFB78B-EB15-40A9-A051-76D2623482C9}C:\program files\windowsapps\facebook.317180b0bb486_1420.6.106.0_x64__8xx8rvfyw5nnt\app\messenger.exe] => (Block) C:\program files\windowsapps\facebook.317180b0bb486_1420.6.106.0_x64__8xx8rvfyw5nnt\app\messenger.exe => No file FirewallRules: [UDP Query User{EA2E5C5C-6187-4BE3-9528-AE572848F53F}C:\program files\windowsapps\facebook.317180b0bb486_1420.6.106.0_x64__8xx8rvfyw5nnt\app\messenger.exe] => (Block) C:\program files\windowsapps\facebook.317180b0bb486_1420.6.106.0_x64__8xx8rvfyw5nnt\app\messenger.exe => No file FirewallRules: [{CB4D90E6-AD9A-4DE1-8EA6-7615C1CFE011}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS0709\HPDiagnosticCoreUI.exe => No file FirewallRules: [{71B4D694-B5A6-411D-802B-D66B63DFBE7B}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS0709\HPDiagnosticCoreUI.exe => No file FirewallRules: [{24E763B2-BE12-4F06-B4A6-99B569E8BCD0}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS18D6\HP.EasyStart.exe => No file FirewallRules: [{4BD99374-77D2-4F10-ACF6-B65CBB30B929}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS74B1\HPDiagnosticCoreUI.exe => No file FirewallRules: [{8B923854-631E-4A25-9AEC-01D2C9034EAA}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS74B1\HPDiagnosticCoreUI.exe => No file FirewallRules: [{2ABE8D03-10E0-4D73-B0F7-6762FA94C39A}] => (Allow) C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS164A\HP.EasyStart.exe => No file FirewallRules: [{4DC6D09C-6C75-46A8-8055-B49653D297C6}] => (Allow) C:\Users\marly\AppData\Local\Temp\7zS5047\HP.EasyStart.exe => No file FirewallRules: [{17A0F9BD-70EC-4F24-9D1E-AE7D1A1F7633}] => (Allow) C:\Users\marly\AppData\Local\Temp\7zS0A4E\HP.EasyStart.exe => No file HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate: Restriction HKLM\...\RunOnce: [*EmptyTemp] => cmd /c rd /q/s C:\FRST\Temp (No file) HKLM\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\Update\OneDriveSetup.exe" (No file) HKLM\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No file) HKLM-x32\...\RunOnce: [Delete Cached Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files (x86)\Microsoft OneDrive\Update\OneDriveSetup.exe" (No file) HKLM-x32\...\RunOnce: [Delete Cached Standalone Update Binary] => C:\WINDOWS\system32\cmd.exe /q /c del /q "C:\Program Files (x86)\Microsoft OneDrive\StandaloneUpdater\OneDriveSetup.exe" (No file) ShortcutTarget: WinZip Préchargeur.lnk -> C:\Program Files\WinZip\WzPreloader.exe (No file) Task: {08E02FD9-4F53-41E2-8BAC-D6BE4703C80D} - System32\Tasks\AdwCleaner_onReboot => C:\Users\PROPRIETAIRE\Downloads\adwcleaner_7.1.1.exe /r (No file) Task: {4421F816-3914-43AB-B57D-1BE4D8D3C67C} - System32\Tasks\HPPSdr Restart Diagnose => C:\Users\PROPRIETAIRE\AppData\Local\Temp\7zS74B1\HPDiagnosticCoreUI.exe (No file) <==== ATTENTION Task: {4C9EC1B6-8959-4388-AA96-BF97046E70B4} - \Avast Software\Overseer -> No file <==== ATTENTION Task: {6430CC72-EBF8-4F8C-AF87-2CCE1878ED23} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe (No file) Task: {895B41D0-A24E-45F7-84BD-D3DAE13B9974} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe -check (No file) Task: {9AA4A5CE-0D98-4FB4-ABA3-DE9D12F7D163} - \Avast Emergency Update -> No file FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No file] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No file] FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No file] FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.10 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.11 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.7 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [No file] FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No file] EmptyTemp: End::3- Once you have copied the script, click on Fix; FRST will automatically use the script in the clipboard.
Let the correction finish; when it asks you to restart your PC, do so.Then, once your computer has restarted:
4- You will have a Fixlog file on your desktop; please send this report fixlog to PJJOINT and provide the link generated by PJJOINT in your reply.
bazfile
Moderator/Security Contributor.
a greeting, a reply, and a thank you are always appreciated. -
-
Should I conclude that everything is OK?
If that were the case, then a big thank you for your valuable help; Once again, I agree with this old saying that says:
It is better to have one who knows than a hundred who are looking.
Provencal adage.
Many thanks again.
DoraCmoi
-
-

