Windows 10: How to fully remove a trojan that hides as "cmd.exe"?

Discus and support How to fully remove a trojan that hides as "cmd.exe"? in Windows 10 Gaming to solve the problem; Hello, I am experiencing a issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two... Discussion in 'Windows 10 Gaming' started by Sagar Khatiwada, Dec 11, 2024.

  1. How to fully remove a trojan that hides as "cmd.exe"?


    Hello, I am experiencing a issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two specific programs: "cmd.exe". I have tried using Malwarebytes to scan and remove any suspicious folders bot using malwarebytes and manually but nothing is working. I recently downloaded Farbar Recovery Scan tool and scanned my system. Addition.txt and Frst.txt logs are uploaded to one drive and link is dropped here. Any help will be appreciated.file link - 2 ItemsSystem Information:Operating System: Windows 7 professionalSystem Type: 64-bitAnt

    :)
     
    Sagar Khatiwada, Dec 11, 2024
    #1

  2. How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?

    Hello,



    I am experiencing a persistent issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two specific programs: "cmd.exe" and "SearchProtocolHost.exe". Along with this, it detects the download of a series of suspicious files within my public users' folders, including a "b.bat" file, a "Service.exe" file, and a "b.vbs" file. Additionally, a compressed file (.7z) is downloaded into my Local/Temp folder, which then gets extracted automatically.



    Despite taking steps to address this malware, including installing and running scans with both Malwarebytes and Avast, the issue persists. It seems that these security solutions have not been able to fully remove the trojan from my system.



    Here are some specifics regarding my system and the steps I've already taken:



    System Information:

    • Operating System: Windows 11
    • System Type: 64-bit
    • Antivirus Software: Malwarebytes, Avast

    Actions Taken:

    • Full system scans with Malwarebytes and Avast.
    • Manual deletion of the suspicious files mentioned above, which temporarily resolves the issue until they reappear every hour.

    I am seeking guidance on how to completely remove this trojan from my system and ensure my computer's security. Any advice on tools or methods that could effectively eliminate this threat would be greatly appreciated. If there are specific logs or system information that could help in diagnosing and addressing this issue, please let me know how I can access and share them.



    Thank you in advance for your assistance.

    Here are the screenshots of my antivirus's reports: Question – Google Drive
     
    Tanner Doriano, Dec 11, 2024
    #2
  3. How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?

    Hi Tanner,

    I don't see any active malware at any of the entry points. We need to check one file, which the fixlist.txt will do automatically.

    Also, SearchProtocolHost.exe is not the culprit here. When SearchProtocolHost.exe indexes your files, it triggers the on-demand AV scanning when it attempts to index "c:\users\public\documents\b.bat". If b.bat is repeatedly created, we have to investigate further. There is no reference to Service.exe in the logs.

    For now, please run the fixlist below.

    • Save Fixlist.txt in the same folder where EnglishFRST64.exe is.
    • Close all program windows.
    • Launch the Farbar Scanner tool and click "Fix".
    • Upload the output log file (FixLog.txt) to your OneDrive.
     
    Ramesh Srinivasan, Dec 11, 2024
    #3
  4. How to fully remove a trojan that hides as "cmd.exe"?

    How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?

    Please run the Farbar Scanner and share your logs.




    (How-To: Share OneDrive files and folders - Microsoft Support)



    Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears.
     
    Ramesh Srinivasan, Dec 11, 2024
    #4
Thema:

How to fully remove a trojan that hides as "cmd.exe"?

Loading...
  1. How to fully remove a trojan that hides as "cmd.exe"? - Similar Threads - fully remove trojan

  2. How to fully remove a trojan that hides as "cmd.exe"?

    in Windows 10 Software and Apps
    How to fully remove a trojan that hides as "cmd.exe"?: Hello, I am experiencing a issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two specific programs: "cmd.exe". I have tried using Malwarebytes to scan and remove any suspicious folders bot using malwarebytes...
  3. How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?

    in Windows 10 Gaming
    How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?: Hello, I am experiencing a persistent issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two specific programs: `cmd.exe` and `SearchProtocolHost.exe`. Along with this, it detects the download of a series of...
  4. How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?

    in Windows 10 Software and Apps
    How to fully remove a trojan that hides as "cmd.exe" and "SearchProtocolHost.exe"?: Hello, I am experiencing a persistent issue with my PC that seems to be related to a Trojan infection. My antivirus software has been consistently targeting two specific programs: `cmd.exe` and `SearchProtocolHost.exe`. Along with this, it detects the download of a series of...
  5. How to remove this trojan?

    in Windows 10 Gaming
    How to remove this trojan?: Whenever my computer opens Norton gives me this alert:After looking around online, it seems like it might be a trogan? When you open its file location it displays the program files for Windows. However, no such file was there.I've ran a Farbar Recovery Scan but I am unable to...
  6. How to remove this trojan?

    in Windows 10 Software and Apps
    How to remove this trojan?: Whenever my computer opens Norton gives me this alert:After looking around online, it seems like it might be a trogan? When you open its file location it displays the program files for Windows. However, no such file was there.I've ran a Farbar Recovery Scan but I am unable to...
  7. SIHOST64.exe Mining Trojan

    in AntiVirus, Firewalls and System Security
    SIHOST64.exe Mining Trojan: Hi. I recently found a virus in my computer, sihost64 and sihost32 running on the background. I dont know how to remove it. Please help me, especially @_AW_ who was helped people with the same problem.Here i attached my...
  8. How to remove Trojan?

    in AntiVirus, Firewalls and System Security
    How to remove Trojan?: Hello! There has always been a Trojan at the results whenever I'm done doing a Full Scan in Windows Security. I would like to ask how I can permanently remove this because I just reset my pc and there's already Trojans when I didn't download anything. I would like to request...
  9. How to automatically hide or fully remove taskbar/start menu?

    in Windows 10 Ask Insider
    How to automatically hide or fully remove taskbar/start menu?: [ATTACH] I am making an arcade machine using Windows 10 and a small computer. I would like to be able to streamline the start up process and overall presentation so that the user sees only a few desktop icons as options for games. I want to essentially hide all of the...
  10. How to automatically hide or fully remove taskbar/start menu?

    in Windows 10 Customization
    How to automatically hide or fully remove taskbar/start menu?: I am making an arcade machine using Windows 10 and a small computer. I would like to be able to streamline the start up process and overall presentation so that the user sees only a few desktop icons as options for games. I want to essentially hide all of the other UI....