Jump to content

Isee The Enemy

Members
  • Posts

    10
  • Joined

  • Last visited

Posts posted by Isee The Enemy

  1. On 4/28/2018 at 8:00 PM, itman said:

    Based on the DNS server IP addresses @Marcos previously posted, I strongly suspect that Counterflix Adware has been modified to include a malicious coin miner component. You can read about Counterflix here: https://www.bleepingcomputer.com/virus-removal/remove-ad-by-counterflix-and-rockettab . Since the article w/removal instructions date to 2/2017, it is debatable if those removal instructions would work against this current variant.

    The most serious problem is it appears this malware has been able to disable ekrn.exe startup. Without ekrn.exe running, Eset is basically non-functional. At this point, I would strongly recommend you not use your PC for e-commerce activities; especially online banking.

    I suggest you contact your in-country Eset customer support for assistance in removing this malware from your PC.

     

    Thank you so much! 

    i did the steps in described in that link and now eset starts up at windows startup!

     

  2. @stackz hxxp://www.mediafire.com/file/2atdah11cpboad3/JOVAN-PC.arn

    @Marcos i already scanned my pc with ESET internet security

    I disabled HIPS cuz i tried setting eset service to automatic.

    i changed router DNS IPV4 1 and ipv4 2 to 8.8.8.8 And 8.8.4.4, third IPV4 is blank (0.0.0.0).also changed my pc dns to same.

    when i scanned with EIS, it found CoinMiner in my Explorer.exe, after it fixed it, i restarted pc and internet explorer wont work. i did an sfc scannow and it fixed it.

     

     

  3. 10 hours ago, itman said:

    As far as I am aware of, the Eset Service needs to be set to Automatic as shown in the below screen shot. I have no clue as to why it would be set to manual.

    Also, you can't change its start up mode using the Win Administrator tool since the reg. key is protected. You will probably have to use regedit.exe and take ownership of the reg. key, if Eset allows that, and set the start up mode to a value of "2." If you don't know what I am talking about by "taking ownership," don't attempt it. If you take ownership, make sure you remove yourself after making the modification.

    Eset_Service.thumb.png.bac7ae3643a1208d4ca70a3bd0851b4f.png

     

    How to do that?

     

    4 hours ago, stackz said:

    Boot the computer into safe mode.

    • Change ESET Service startup type to Automatic.
    • Check the Recovery tab and ensure all failure actions are set to "Restart the Service".
    • Reboot

     

    after i did it, first restart it launched eset,second restart not.

×
×
  • Create New...