-
Posts
4 -
Joined
-
Last visited
Posts posted by Jozef76
-
-
5 hours ago, Marcos said:
Please do not delete any files without keeping a copy of them. Move the file to a new folder, reboot the machine and upload the file here along with logs collected with ESET Log Collector.
Hi!
Thank you for reply!
I moved the file, rebooted machine!
I sent the files to you!
Thanks! -
1 hour ago, itman said:
Have you downloaded and installed any cracked software? The presence of this indicates you are ;
wscript.exe/e:key:przSlksUf6ucMA.
Hi!
Thank you for reply!
Currently not installed cracked software!Thanks!
-
Hi!
I having problem with pop up hxxp://api.backend-app.com:8880
I created new HIPS rule!
Looks like the pop-ups has been stopped.I found:
C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\updatewins.lnkupdatewins.lnk - >Target: C:\WINDOWS\system32\wscript.exe /E:jscript "C:\Users\xxx\AppData\Roaming\updatewins" wscript.exe/e:key:przSlksUf6ucMA
Question.
Can updatewins.lnk file be deleted?Thank you!
ESET I.S. Agressively blocking URL, can't find app
in Malware Finding and Cleaning
Posted · Edited by Jozef76
Thanks!
I didn't find it in the roomaing folder...
Good news, I turned off the rules, there was no pop-up. Nod32 is silent.
Thank you!