Windows 10: Trojan or not ?

Discus and support Trojan or not ? in AntiVirus, Firewalls and System Security to solve the problem; Hi all, Not quite sure when this started but roughly somewhere around July I noticed a file called NTUSER.rhk that resides in "Users\My username".... Discussion in 'AntiVirus, Firewalls and System Security' started by fdegrove, Oct 23, 2016.

  1. fdegrove Win User

    Trojan or not ?


    Hi all,

    Not quite sure when this started but roughly somewhere around July I noticed a file called NTUSER.rhk that resides in
    "Users\My username".

    Googling for the .rhk file extension gave me a bit of a scare as most sites suggest this is associated with Trojan.
    Somehow I doubt it as no anti-virus software I ran seems to flag it.
    I can delete this file all I want but it keeps on cropping up.
    It only resides in my user folder together with NTUSER.DAT.
    Does anyone have a clue what it's for or have it too ?

    TIA, *Wink

    :)
     
    fdegrove, Oct 23, 2016
    #1
  2. Ken Blake Win User

    Trojan virus: Win32/Winexert!rfn

    Click Remove all on that screen.

    And by the way, note that there is no such thing as a "Trojan Virus." It's either a Trojan (full name: Trojan Horse) *or* a virus. They are two different types of malware. What you have is Trojan, not a Virus.
     
    Ken Blake, Oct 23, 2016
    #2
  3. Ken Blake Win User
    How do I remove a Trojan or Virus?

    First, note that there is no such thing as a "Trojan virus." It's either a trojan *or* a virus. Trojans and viruses are two different kinds of malware.

    So assuming you have a trojan, what trojan is it (what is its name?)? How do you know you have it?

    What anti-virus program do you run? And what other anti-malware software? Have you tried to remove it using these?
     
    Ken Blake, Oct 23, 2016
    #3
  4. Neemobeer Win User

    Trojan or not ?

    It's definitely not part of Windows. You should only have a NTUSER.DAT, NTUSER.dat.LOG# and some regtrans-ms and blf files

    I would grab procmon https://technet.microsoft.com/en-us/...ssmonitor.aspx and set a filter for this file. This should tell you what is creating it.
     
    Neemobeer, Oct 23, 2016
    #4
  5. fdegrove,

    Welcome to the forum!

    If you want to be sure NTUSER.rhk is not malware, scan the file with VirusTotal:
    VirusTotal

    It is a free online scanning service.

    Please post the scan results URL address in your next reply.
     
    cottonball, Oct 23, 2016
    #5
  6. fdegrove Win User
    Hi,

    Thanks for the replies so far guys.

    Will do asap. Of course now that I deleted it on this system it seems unwilling to pop up again.... For now that is.*sarc

    I just wonder if anyone else has it. Going by the time stamp I see in images it could be AU related.
    When it's present it updates itself as I notice the time stamp changing but not necessarily on a daily basis.

    Anyhow, I'll keep an eye on it.

    Cheers, *Wink
     
    fdegrove, Oct 23, 2016
    #6
  7. fdegrove,

    If you deleted NTUSER.rhk, there is no point in using VirusTotal, since it has to scan the file.

    The file appears to be an application/octet-stream
     
    cottonball, Oct 23, 2016
    #7
  8. simrick Win User

    Trojan or not ?

    Hi.
    I just checked and I don't have it in my AU system/user folder. I agree, if it pops up again, upload it to virustotal.com and see what the scanners say about it. If it keeps coming back, that could be a sign of a rootkit. Will be interesting to see what the virustotal scan shows. Then again, it could be some malware, and AVs won't pick that up. Have you run ADWCleaner?
     
    simrick, Oct 23, 2016
    #8
  9. fdegrove Win User
    Hi,


    I retrieved a copy of the file from an image created last night.
    Uploaded it to VirusTotal :

    It appears to be benign so I guess it is indeed an application octet-stream as you suggest.
    I'll try to find out which app it is but I suspect either Ccleaner or Wise's Registry Cleaner.

    Yes, I did but nothing suspicious was found.

    Thanks for all the help, guys.

    EDIT: Found the guilty app: It is Wise's Registry Cleaner and more precisely its Registry Defrag part that generates the file.
    A second similar file is created called "UsrClass.rhk" in "C:\Users"UserName"\AppData\Local\Microsoft\Windows".
    Just thought I'd let you know.

    Cheers, *Wink
     
    fdegrove, Oct 23, 2016
    #9
  10. simrick Win User
    Great! Thanks for letting us know.
     
    simrick, Oct 23, 2016
    #10
  11. cottonball, Oct 23, 2016
    #11
  12. simrick Win User
    simrick, Oct 23, 2016
    #12
  13. fdegrove Win User

    Trojan or not ?

    Hi,

    I only have MS Windows Defender installed but have a few stand alone apps that I run whenever I suspect something.

    As for Registry Cleaners and consorts, sure there's a lot of junk out there.
    I have my reasons to keep the registry junk free. It's a database after all, no need to fill it with unnecessary entries.
    Whether or not there's any benefit to it is a matter of opinion.

    Cheers, *Wink
     
    fdegrove, Oct 23, 2016
    #13
  14. MoxieMomma, Oct 23, 2016
    #14
  15. fdegrove Win User
    Hi,

    They used to though. Guess too many people messed up their system because they had no clue what they were doing.

    Anyhow, this has been discussed here a couple of times :

    Registry Cleaning

    Cheers, *Wink
     
    fdegrove, Oct 23, 2016
    #15
Thema:

Trojan or not ?

Loading...
  1. Trojan or not ? - Similar Threads - Trojan

  2. Trojan virus -> hijacked Gmail

    in Windows 10 Gaming
    Trojan virus -> hijacked Gmail: last week, I tried to download a game from a random website, but instead a trogan virus was installed, I immediately had windows security delete the viruses several copies were installed and I kept repeating the quick scan, full scan, and offline scan options, at the...
  3. Trojan virus -> hijacked Gmail

    in Windows 10 Software and Apps
    Trojan virus -> hijacked Gmail: last week, I tried to download a game from a random website, but instead a trogan virus was installed, I immediately had windows security delete the viruses several copies were installed and I kept repeating the quick scan, full scan, and offline scan options, at the...
  4. New Trojan virus scam?

    in Windows 10 Gaming
    New Trojan virus scam?: I got an audible message, not a pop up, stating I have a Trojan virus. It instructed me to call Microsoft. It DID NOT provide a phone number. It DID NOT provide a link. I am fully aware of scams that provide a phone number or link. This was not that. Has anyone experienced...
  5. New Trojan virus scam?

    in Windows 10 Software and Apps
    New Trojan virus scam?: I got an audible message, not a pop up, stating I have a Trojan virus. It instructed me to call Microsoft. It DID NOT provide a phone number. It DID NOT provide a link. I am fully aware of scams that provide a phone number or link. This was not that. Has anyone experienced...
  6. New Trojan virus scam?

    in AntiVirus, Firewalls and System Security
    New Trojan virus scam?: I got an audible message, not a pop up, stating I have a Trojan virus. It instructed me to call Microsoft. It DID NOT provide a phone number. It DID NOT provide a link. I am fully aware of scams that provide a phone number or link. This was not that. Has anyone experienced...
  7. how to remove trojan form win11?

    in Windows 10 Gaming
    how to remove trojan form win11?: i got trojan from some site and after that i cant update my windows https://answers.microsoft.com/en-us/windows/forum/all/how-to-remove-trojan-form-win11/0de7dd4a-44ab-4767-a8c8-b21f3da4494e
  8. how to remove trojan form win11?

    in Windows 10 Software and Apps
    how to remove trojan form win11?: i got trojan from some site and after that i cant update my windows https://answers.microsoft.com/en-us/windows/forum/all/how-to-remove-trojan-form-win11/0de7dd4a-44ab-4767-a8c8-b21f3da4494e
  9. I think that I downloaded a trojan

    in Windows 10 Gaming
    I think that I downloaded a trojan: I have windows 10.I downloaded a zip file of a game from an untrusted source. the link for the site where I got the virus from is: s3.amazonaws.com/pe9/9777129666414113/Starbreed%20v07%20By%20Regulus.html.immediately after downloading I got a message from google that the file...
  10. I think that I downloaded a trojan

    in Windows 10 Software and Apps
    I think that I downloaded a trojan: I have windows 10.I downloaded a zip file of a game from an untrusted source. the link for the site where I got the virus from is: s3.amazonaws.com/pe9/9777129666414113/Starbreed%20v07%20By%20Regulus.html.immediately after downloading I got a message from google that the file...

Users found this page by searching for:

  1. NTUSER.rhk

    ,
  2. usrclass.rhk