Windows 10: Malware help please + cryptoprevent

Discus and support Malware help please + cryptoprevent in AntiVirus, Firewalls and System Security to solve the problem; So I have this in the log of cryptoprevent Event ID=866 Message of: Access to C:\Users\Zman\AppData\Local\atbizdu\cgcstpk.exe has been restricted by... Discussion in 'AntiVirus, Firewalls and System Security' started by zman3, Mar 18, 2018.

  1. zman3 Win User

    Malware help please + cryptoprevent


    So I have this in the log of cryptoprevent
    Event ID=866 Message of: Access to C:\Users\Zman\AppData\Local\atbizdu\cgcstpk.exe has been restricted by your Administrator by location with policy rule {B6AF3C37-6012-4DEC-87BB-5125E94F5BC5} placed on path C:\Users\AdminZman\AppData\Local\*\*.exe.

    on a constant basis I cannot get into that folder I cannot delete it rename it or anything if I try to take ownership of it I get told I cant even though Im a adminstrator account.
    I booted off a windows 7 disk went to a command prompt and deleted it yet its back again Ive ran malwarebytes hitman pro windows defender. How do I figure out how thats being created and whats trying to access that exe?

    thanks

    :)
     
    zman3, Mar 18, 2018
    #1
  2. Monkey57 Win User

    How crypto ransomware spreads... is it decryptable...should I pay the ransom

    quietman7,

    While this discussion deals mainly on how to deal with the after-effect of ransomware.. Do you have suggestions on what users can do to protect their computer and/or data from these attacks?

    I have liked cryptoprevent, but have seen other market entries (some from suspicious vendors)

    CryptoPrevent Malware Prevention

    use free version only-for personal use

    This tool (cryptoprevent) does not run in the back ground, it automatically changes registry settings (some recommended by Microsoft), but it does update occasionally, so check it for updates.

    And maintaining a rotating backup, with non-attached storage (to much work for many average users)

    Also, with the reports of the more recent attackers using tools and methods previously associated with state sponsored intrusions, would a more hardened OS by Microsoft, that incorporated some of the methods from spiceworks and/or cryptoprevent, be helpful.

    Exclusive: Chinese hackers behind U.S. ransomware attacks -...

    A Top Cybersecurity Firm Says Ransomware Attacks Are Getting Worse
     
    Monkey57, Mar 18, 2018
    #2
  3. Windows 10 failed attempts to use "Backup and Restore (Windows 7)" function

    Repeated backup failures. Running Windows 10, and when the “Backup and Restore (Windows 7) program is run front the Control Panel, I get the messages:



    “Check your backup. The last backup did not complete successfully”.



    “Windows Backup failed to get an exclusive lock on the EFI system partition (ESP). This may happen if another application is using files on the ESP.”



    “Please retry the operation.”



    Each time I retry, I get the same result and messages.

    Windows 10 came installed on my Dell Inspiron 15 (500 Series) laptop. I have successfully used the same Backup and Restore (Windows 7) program to “Create a system image”, as well as to “Create a system repair disc”.

    Please provide me with some insight and suggested actions.
     
    {Please Help}, Mar 18, 2018
    #3
  4. Malware help please + cryptoprevent

    Hi,
    Seems like at bizz is some sort of social media sharing site have you ever joined it ?
    You can try the normal like scanning with malewarebyes and adwcleaner and see what it finds.
     
    ThrashZone, Mar 18, 2018
    #4
  5. zman3 Win User
    nope never joined anything named close to that I have tried malwarebytes thou.
     
    zman3, Mar 18, 2018
    #5
  6. simrick Win User
    Hi. Have you resolved this or are you still looking for help? It sounds to me as if you have some sort of Rootkit (keeps spawning itself over and over).

    Malwarebytes has an option to scan for Rootkits, but you have to check the box for it in Settings> Protection.
    I would first start out with this though:

    Run RKILL
    Download RKill
    This program doesn't install on the system. It just runs, and closes/ends all suspicious running items. Everything it does is temporary and undone by a reboot.

    Run a scan with ADWCleaner
    Downloads - AdwCleaner - ToolsLib
    If the scan finds anything, it will offer you an option to clean - go ahead and do that. After cleaning, it will prompt for a reboot - do that as well.

    Then run RKILL again.

    Now run Malwarebytes with the Rootkit scan box checked and see if anything is found.

    Posting the logs here from RKILL and ADWCleaner will also help.
     
    simrick, Apr 5, 2018
    #6
Thema:

Malware help please + cryptoprevent

Loading...
  1. Malware help please + cryptoprevent - Similar Threads - Malware help please

  2. Trojan Malware possible false positive help please

    in AntiVirus, Firewalls and System Security
    Trojan Malware possible false positive help please: So recently I received a windows threat protection notice for a severe level Trojan:Win32/Malgent. It says it was "blocked", and I removed it the second I got the notification, so the files it said were affected are no longer on my pc windows 10. I did extensive research on...
  3. Trojan Malware possible false positive help please

    in Windows 10 Gaming
    Trojan Malware possible false positive help please: So recently I received a windows threat protection notice for a severe level Trojan:Win32/Malgent. It says it was "blocked", and I removed it the second I got the notification, so the files it said were affected are no longer on my pc windows 10. I did extensive research on...
  4. Trojan Malware possible false positive help please

    in Windows 10 Software and Apps
    Trojan Malware possible false positive help please: So recently I received a windows threat protection notice for a severe level Trojan:Win32/Malgent. It says it was "blocked", and I removed it the second I got the notification, so the files it said were affected are no longer on my pc windows 10. I did extensive research on...
  5. help with malware

    in AntiVirus, Firewalls and System Security
    help with malware: need to speak with an agent to help with a possible scam or breach in my laptop https://answers.microsoft.com/en-us/protect/forum/all/help-with-malware/106abc05-ca31-40db-bace-bbea692ed45f
  6. !HELP! MALWARE

    in Windows 10 Software and Apps
    !HELP! MALWARE: i was looking throu task manager as usual , and i noticed the procces 'BridleBuddlesService' i did some research and found that it is a realy annoying malware , i pretty mutch tried everything to uninstall / delete it but nothing seems to work becouse i dont have permission...
  7. Please help - Malware inserted into SCHTASKS - I cannot remove it.

    in AntiVirus, Firewalls and System Security
    Please help - Malware inserted into SCHTASKS - I cannot remove it.: I am not a tech - I am 77 and cannot afford to have my computer repaired. Somehow I picked up this malware amongst a ton of other malware when I visited a sick site !! This is what it says via Defender Report ; admin prompt C:\Windows\System32\schtasks.exe /CREATE /SC...
  8. Virus / Malware, please help!

    in AntiVirus, Firewalls and System Security
    Virus / Malware, please help!: Hi, Ive got a virus that persists even after formats, I believe I caught it from my roomate and he recently got his identity stolen, so Im pretty scared. We both seem to have it but his files are older, so Im guessing i got it from him over the local network somehow. I was...
  9. Is CryptoPrevent 8 user friendly?

    in AntiVirus, Firewalls and System Security
    Is CryptoPrevent 8 user friendly?: I didn't get around to updating to version 8 as this program is easy to forget you have... Now I have reinstalled Windows I will probably reinstall it. I recall someone saying version 8 was not so user friendly as the old version, is that true? Is it still a good additional...
  10. CryptoPrevent Version 8 is Out

    in AntiVirus, Firewalls and System Security
    CryptoPrevent Version 8 is Out: Another great addition to fighting the criminals CryptoPrevent Malware Prevention CryptoPrevent is a robust anti-virus/anti-malware software supplement, filling a huge gap that exists with traditional security solutions to provide protection against a growing...