Windows 10: Fun times with networking malware, please help me remove and prevent.

Discus and support Fun times with networking malware, please help me remove and prevent. in AntiVirus, Firewalls and System Security to solve the problem; So major issues after suspecting malware for awhile ... I finally found it (more on that in a second). The issue is my whole home network must be... Discussion in 'AntiVirus, Firewalls and System Security' started by rickyrickyboby, Jun 6, 2018.

  1. Fun times with networking malware, please help me remove and prevent.


    So major issues after suspecting malware for awhile ... I finally found it (more on that in a second). The issue is my whole home network must be infected (according to the cve that is what this malware does).
    That includes Chromecast, printer, 2 windows desktops, 1 Linux laptop, 2 iPhone, iPad, usb storage, hdds and router. The only way I was able to find this malware is by using a live (Ubuntu) os and scanning the windows drives with av.

    Here are the CVEs:
    win.torojan.rammit-7106
    swf.Exploit.cve_2016_7872-5855317-0
    swf.Exploit.cve_2016_7879-5889229-0
    win.trojan.generic-6563181
    win.trojan.generic-6563205
    win.Dropper.Yeehbar-6567740-0
    This hacker also put malware into my Linux system by taking over a login in client. I was not able to find the any explicit malware but I think they got in through Firefox.

    Also a internal port scan of my router:
    22/tcp filtered ssh
    23/tcp filtered telnet
    53/tcp open domain
    80/tcp open http
    443/tcp open https
    49152/tcp open unknown
    49153/tcp open unknown
    49154/tcp open unknown
    What really concerns me about this is what are the unknown ports, ssh and telnet,
    the router basically default nothing special it is isp cisco router.

    So what I have planned to do:
    -Take all apple devices to apple store have them run diagnostics/ av on them.
    -get a new router
    -reinstall windows/Linux on devices (with trusted usb sticks)
    -put all valuable files on one new storage device go through data and scan device

    Here are my concerns:
    -How do I know the printer is safe and malware free (seams like a great attack vector)?
    -How do I know the Chromecast is safe?
    -Can malware take over laptop/desktop/printer/etc firmware?
    -Would using Linux to erase the storage devices be enough (as such ... )
    bash >> clamscan <> <drive>
    bash >> mv /good/files /trusted/drive
    bash >> shred -vzn 1 <drive>
    bash >> fdisk -u #to make new partition table
    bash >> mkfs.ntfs <part>
    would that handle all types of malware or can it hide from Linux or freedos?

    My passwords are very strong for example: tUrnip55Tr35D0tFY which would be tough to break,
    but my parents won't not use there last name is there anything I do to make their computers/ipads more secure. Thanks in advance this has caused really big problems in my life, like deleting my homework, causing me to drop out of school and I'm scared who ever is doing this is going to steal my identity; leave me with nothing if they haven't already. Please any advice you can give I really can't understand why some
    one has done this to me but at the very least I can try and get rid of it.

    :)
     
    rickyrickyboby, Jun 6, 2018
    #1

  2. removal of sidecubes malware

    Do not get SpyHunter. It's just as bad as the malware you have,

    Follow the steps here.

    https://malwaretips.com/blogs/remove-sidecubes-virus/

    If it is not listed in the Control Panel, or it can't be removed there, move on to step 2. HitmanPro might not be needed.
     
    Bruce Hagen, Jun 7, 2018
    #2
  3. Le Boule Win User
    Get message Defender is removing Malware.

    Sounds like the malware detections may be in a browser.

    Can you give us the complete name/file path of the malware (as it appears under quarantine or on the list of detected items)?

    Have you emptied temporary internet files and rebooted the computer? Then do a manual update of WD followed by a Quick Scan.

    Any new browser extensions that need to be disabled?

    Try this free scanner:
    http://blog.emsisoft.com/2015/06/09/how-to-find-and-clean-malware-infections-with-emsisoft-emergency-kit/


    If the detections continue see the following free removal guide from Malwaretips.com:
    https://malwaretips.com/blogs/malware-removal-guide-for-windows/

    To remove malware from Windows, follow these steps:

    STEP 1: Scan your computer with Kasperskty TDSSkiller

    STEP 2: Scan your computer with Malwarebytes Anti-Malware

    STEP 3: Stop the malicious process with Rkill

    STEP 4: Double-check for malware with HitmanPro

    STEP 5: Scan your computer with AdwCleaner

    (OPTIONAL) STEP 6: Scan your computer with Zemana AntiMalware

    (OPTIONAL) STEP 7: Reset your browser to default settings

    Regards…

    Top 10 Ways PUPs Sneak Onto Your Computer. And How To Avoid Them.
     
    Le Boule, Jun 7, 2018
    #3
Thema:

Fun times with networking malware, please help me remove and prevent.

Loading...
  1. Fun times with networking malware, please help me remove and prevent. - Similar Threads - Fun times networking

  2. Can someone please help me remove this sneaky Malware? nslooksvc64

    in AntiVirus, Firewalls and System Security
    Can someone please help me remove this sneaky Malware? nslooksvc64: Have anyone encountered this exact same issue? IDK where it came from i just noticed that my PC kept on having random stutters, I already did a Quick Scan, Full Scan, Offline Scan in Windows Defender.Already Did installed Malwarebytes and to no avail, this threat kept on...
  3. Help me remove excludeproc.d please!

    in Windows 10 Gaming
    Help me remove excludeproc.d please!: I've had this issue for a while now, where my pc would run very slow unless I had task manager opened. No virus scanner I tried could find anything, until a few days ago when the Windows Security Scanner found "VirTool:Win32/ExcludeProc.D". Every time I delete it through...
  4. Help me remove excludeproc.d please!

    in Windows 10 Software and Apps
    Help me remove excludeproc.d please!: I've had this issue for a while now, where my pc would run very slow unless I had task manager opened. No virus scanner I tried could find anything, until a few days ago when the Windows Security Scanner found "VirTool:Win32/ExcludeProc.D". Every time I delete it through...
  5. Malware Removal Help

    in AntiVirus, Firewalls and System Security
    Malware Removal Help: I need some help from someone whos more techy than me. My issue is that about two weeks ago when ever I clicked on the "Ad" top link for eBay, the top link when ever you just google "ebay", I get redirected to a scam virus page. I have scanned my computer and router for...
  6. Network problems please help me

    in Windows 10 Network and Sharing
    Network problems please help me: So recently I had multiple problems with my pc network,here its all I know: -i have 2 routers one getting netowork from the provider and the other one from the routermy pc is connected to the router connected to the other router -So sometimes almost every day my pc...
  7. Malware Removal Help

    in Windows 10 Network and Sharing
    Malware Removal Help: So I recently had some malware installed on my laptop and I had lots of problems but I was successfully able to remove all malware and viruses and was able to run Norton antivirus and malware bytes and was able to remove all my viruses and malware. Now my system is completely...
  8. Please help - Malware inserted into SCHTASKS - I cannot remove it.

    in AntiVirus, Firewalls and System Security
    Please help - Malware inserted into SCHTASKS - I cannot remove it.: I am not a tech - I am 77 and cannot afford to have my computer repaired. Somehow I picked up this malware amongst a ton of other malware when I visited a sick site !! This is what it says via Defender Report ; admin prompt C:\Windows\System32\schtasks.exe /CREATE /SC...
  9. Malware help please + cryptoprevent

    in AntiVirus, Firewalls and System Security
    Malware help please + cryptoprevent: So I have this in the log of cryptoprevent Event ID=866 Message of: Access to C:\Users\Zman\AppData\Local\atbizdu\cgcstpk.exe has been restricted by your Administrator by location with policy rule {B6AF3C37-6012-4DEC-87BB-5125E94F5BC5} placed on path...
  10. Help me please with removing icons.

    in Windows 10 Support
    Help me please with removing icons.: Are there any regedit settings or a Windows 10 taskbar tweaker like that of Windows 7 that can perform the following as I have searched in vain and found nothing so far. Simply, I would like to remove permanently (not disable) from the far right of the taskbar the "show...