Hello world!
I work in a digital marketing company and there has been some modifications since a few weeks. Long story short I now work from home and I got a computer from my company. This is really nice but now here's my concern:
I'd like to use it for a more personal use but my boss is a computer engineer and I'm afraid that there might be spy software or rootkits which would allow him to enter/see what I do and have on this computer, or even a keystroke logger.
Do you know how I could use to detect/get rid of them?
- I have the administrator privileges and password
- The computer is running windows 10
- I have uninstalled Teamviewer
- Malwarebytes Anti Malware did'nt find anything
- I have scanned my system with Malwarebytes and have put all the suspected malicious items in the quarantine. Here below's the report.
So, what would be the steps to follow in order to ensure there are not such programs/rootkits/whatever that could've been installed? This isn't a big company with highly modified computer, so I believe we can do something about it.
A box of chocolate for whoever help me with that
Thaaaaaank you!
Sweet_lumberjack
I work in a digital marketing company and there has been some modifications since a few weeks. Long story short I now work from home and I got a computer from my company. This is really nice but now here's my concern:
I'd like to use it for a more personal use but my boss is a computer engineer and I'm afraid that there might be spy software or rootkits which would allow him to enter/see what I do and have on this computer, or even a keystroke logger.
Do you know how I could use to detect/get rid of them?
- I have the administrator privileges and password
- The computer is running windows 10
- I have uninstalled Teamviewer
- Malwarebytes Anti Malware did'nt find anything
- I have scanned my system with Malwarebytes and have put all the suspected malicious items in the quarantine. Here below's the report.
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 11
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{13D15E3A-76E7-4D02-A755-7B668FB103B2}, No Action By User, [117], [337429],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}, No Action By User, [16861], [237958],1.0.1129
PUP.Optional.KeepMySearch, HKU\S-1-5-21-3115390640-629360802-624484214-1001_Classes\keepmysearch, No Action By User, [16994], [239725],1.0.1129
PUP.Optional.YahooSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Search, No Action By User, [17566], [245143],1.0.1129
PUP.Optional.YahooSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Search Updater, No Action By User, [17566], [245143],1.0.1129
PUP.Optional.InstallCore, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\InstallCore, No Action By User, [8], [239563],1.0.1129
Registry Value: 3
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{13D15E3A-76E7-4D02-A755-7B668FB103B2}|PATH, No Action By User, [117], [337429],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}|FAVICONURL, No Action By User, [16861], [237958],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}|URL, No Action By User, [16861], [237958],1.0.1129
Registry Data: 1
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, No Action By User, [16861], [293067],1.0.1129
Data Stream: 0
(No malicious items detected)
Folder: 3
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.PayByAds, C:\USERS\KREM SOFT\APPDATA\LOCAL\Pay-By-Ads, No Action By User, [4053], [178834],1.0.1129
File: 8
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{3BCF4F2C-0BBB-4D4C-BF1F-11BBE6D501EA}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{915CB94B-B4D8-4C0E-83B4-61409471B1C3}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{16A92140-918D-4AFB-9EDB-46F22437BB10}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{641E52B1-3179-43ED-8BCB-F688871E52B0}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{3BCF4F2C-0BBB-4D4C-BF1F-11BBE6D501EA}W64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\app.ini, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.YahooSearch, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Search, No Action By User, [17566], [245141],1.0.1129
PUP.Optional.YahooSearch, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Search Updater, No Action By User, [17566], [245141],1.0.1129
Physical Sector: 0
(No malicious items detected)
(end)
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
-Scan Details-
Process: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registry Key: 11
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{915cb94b-b4d8-4c0e-83b4-61409471b1c3}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{16a92140-918d-4afb-9edb-46f22437bb10}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{641e52b1-3179-43ed-8bcb-f688871e52b0}Gw64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{3bcf4f2c-0bbb-4d4c-bf1f-11bbe6d501ea}w64, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{13D15E3A-76E7-4D02-A755-7B668FB103B2}, No Action By User, [117], [337429],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}, No Action By User, [16861], [237958],1.0.1129
PUP.Optional.KeepMySearch, HKU\S-1-5-21-3115390640-629360802-624484214-1001_Classes\keepmysearch, No Action By User, [16994], [239725],1.0.1129
PUP.Optional.YahooSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Search, No Action By User, [17566], [245143],1.0.1129
PUP.Optional.YahooSearch, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Yahoo! Search Updater, No Action By User, [17566], [245143],1.0.1129
PUP.Optional.InstallCore, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\InstallCore, No Action By User, [8], [239563],1.0.1129
Registry Value: 3
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{13D15E3A-76E7-4D02-A755-7B668FB103B2}|PATH, No Action By User, [117], [337429],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}|FAVICONURL, No Action By User, [16861], [237958],1.0.1129
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{951E15AA-4E3D-4E2C-820C-B9F3C62E682B}|URL, No Action By User, [16861], [237958],1.0.1129
Registry Data: 1
PUP.Optional.Dsrlte, HKU\S-1-5-21-3115390640-629360802-624484214-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|START PAGE, No Action By User, [16861], [293067],1.0.1129
Data Stream: 0
(No malicious items detected)
Folder: 3
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.PayByAds, C:\USERS\KREM SOFT\APPDATA\LOCAL\Pay-By-Ads, No Action By User, [4053], [178834],1.0.1129
File: 8
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{3BCF4F2C-0BBB-4D4C-BF1F-11BBE6D501EA}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{915CB94B-B4D8-4C0E-83B4-61409471B1C3}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{16A92140-918D-4AFB-9EDB-46F22437BB10}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{641E52B1-3179-43ED-8BCB-F688871E52B0}GW64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.BrowseFox, C:\WINDOWS\SYSTEM32\DRIVERS\{3BCF4F2C-0BBB-4D4C-BF1F-11BBE6D501EA}W64.SYS, No Action By User, [2076], [299543],1.0.1129
PUP.Optional.PayByAds, C:\Users\KREM SOFT\AppData\Local\Pay-By-Ads\Yahoo! Search\1.3.19.2\app.ini, No Action By User, [4053], [178834],1.0.1129
PUP.Optional.YahooSearch, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Search, No Action By User, [17566], [245141],1.0.1129
PUP.Optional.YahooSearch, C:\WINDOWS\SYSTEM32\TASKS\Yahoo! Search Updater, No Action By User, [17566], [245141],1.0.1129
Physical Sector: 0
(No malicious items detected)
(end)
So, what would be the steps to follow in order to ensure there are not such programs/rootkits/whatever that could've been installed? This isn't a big company with highly modified computer, so I believe we can do something about it.
A box of chocolate for whoever help me with that
Thaaaaaank you!
Sweet_lumberjack