Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

Trojan causing duplicatiobn of all data files/folders?


  • This topic is locked This topic is locked
23 replies to this topic

#16 Cumulo

Cumulo
  • Topic Starter

  •  Avatar image
  • Members
  • 92 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 18 April 2024 - 01:09 PM

Thanks - here goes...

 

n.b. not all examples of the serach term are unwanted files. The legitimate ones are the folders ...Documents\Infleunt and ...Documents\Influent 2024.

 

|All the imnstances of folders that comtain the word "Influent", as subfolders within other folders in the Documents library,  are the problem.  

Attached Files


Edited by Cumulo, 18 April 2024 - 01:17 PM.


BC AdBot (Login to Remove)

 


#17 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,486 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:30 AM

Posted 18 April 2024 - 02:51 PM

This is very peculiar as the way the folders are organized.

 

Enclosed please find the list of files and folder related to influent.

 

Attached File  Influent_Folders.txt   26.6KB   1 downloads

 

Please review this list and remove the lines you do not want to remove, then save the rest as Fixlist.txt in the location FRST64 is saved. Run FRST64 and click on Fix.

 

Perform another search:

 

Open FRST64. Type the following on the search box in FRST64.

 

Searchall: Influent 

 

Click on Search files. A search report will be produced. Attach that report in your reply.

 

 


Edited by JSntgRvr, 18 April 2024 - 10:01 PM.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed


#18 Cumulo

Cumulo
  • Topic Starter

  •  Avatar image
  • Members
  • 92 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 19 April 2024 - 04:01 AM

OK, thankyou.

 

Here is the list, atatcched.

 

What is peculair about the way the files are organised? You mean the Dcouments\My Documents thimg?    

Attached Files



#19 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,486 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:30 AM

Posted 19 April 2024 - 08:58 AM

OK, thankyou.

 

Here is the list, atatcched.

 

What is peculair about the way the files are organised? You mean the Dcouments\My Documents thimg?    

Is the way was distributed, such as, teaching, Legal and others. I won't touch the registry as seems to be related to Office.

 

How is it doing?


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed


#20 Cumulo

Cumulo
  • Topic Starter

  •  Avatar image
  • Members
  • 92 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 19 April 2024 - 12:43 PM

It's doing Ok in general.

 

I see there are still cases of /Infleunt and /Influent 2023 enscconced in other folders. And cannot be deleted still as apparent,ly not in tjhs e locations. But AFAIK not doing any harm. Would I be right in thinking we would need to get into the Registry to expunge them?

 

You mention the Hosts file in an earlier post. Is this the name of a virtis and could it have caused this mass duplication of certain folders?   



#21 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,486 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:30 AM

Posted 19 April 2024 - 03:27 PM

They will be cleaned now.

 

Congratulations.

 

Use this application to remove tools used and their quarantined items:
 
Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools

 -Delete Restore Points

- Create Restore Point

- Delete now

  • Click the "Run" button.

automatic.png

  • When the tool has finished, it will create and open a log report and delete itself.

A few final recommendations:
 
The following information will help you to keep your computer and data safer as well as improve your overall privacy

Malwarebytes Browser Guard

uBlock Origin

Cybersecurity basics & protection
 
Everything you need to know about cybercrime
https://www.malwarebytes.com/cybersecurity
 
Further reading if you'd like to keep up on the malware threat scene: Malwarebytes Blog  https://blog.malwarebytes.com/
 
Please review the following to help you better protect your computer and privacy
 
Tips to help protect from infection
 
Hopefully, we've been able to assist you with correcting your system issues.
 
Thank you for using BleepingComputer. Please tell your friends and family if they too need assistance with malware removal.


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed


#22 Cumulo

Cumulo
  • Topic Starter

  •  Avatar image
  • Members
  • 92 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:05:30 AM

Posted 20 April 2024 - 08:26 AM

Thankyou very much.

 

I  have installed some browser extensions.

 

I notice the Infleunt folders still persist in some locations but as they seem to be doing no harm, it does not overly boyther me.  



#23 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,486 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:30 AM

Posted 20 April 2024 - 12:26 PM

You mention the Hosts file in an earlier post. Is this the name of a virtis and could it have caused this mass duplication of certain folders?   

 

No. The Hosts file just helps you to block or allows sites to be reached. It is not a carrier of viruses.

 

Bets regards.


No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed


#24 JSntgRvr

JSntgRvr

    Malware Fighter


  •  Avatar image
  • Malware Response Team
  • 16,486 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto Rico
  • Local time:12:30 AM

Posted 20 April 2024 - 12:26 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

No request for help throughout private messaging will be attended.

Unactive logs for mor more than four (4) days will be closed





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users