Pc Locks Up. Mysterious User Account Called Fyk.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Condensermike, Oct 1, 2016.

  1. Condensermike

    Condensermike Private E-2

    Hello,

    I am having issues with my Dell Inspiron desktop. It sometimes freezes up and will not let the mouse move causing me to have to restart. Previous scans with Malwarebytes would get hung up on xml files located in this directory: \Users\fyk\AppData\Local\Temp. Once again, this fyk user is unknown to me and I didn't set it up. I performed the scans but did run into some issues along the way listed below:

    MGTools would not download to the C: drive. I tried the procedures outlined to fix this but the issue was not any of those. Here is the message I got when attempting to download to the c drive:
    ----------------------------------------
    c\:MGtools.exe

    You don’t have permission to save in this location. Contact the administrator to obtain permissions. Would you like to save the fyk folder instead?

    Yes NO

    ----------------------------------------------------

    I ran Malwarebytes with success but no Scan log was generated since it did not find any issues. I instead have attached a scan log from 9/28. I hope this helps.

    Next issue was running RogueKiller. It froze at this point:
    Key: [x64] HKEY_CLASSES_ROOT\CLSID : {2048EEE6-7FA2-11D0-9E6A-00A0C9138C29} and I had to reboot the computer. No log was generated from this as a result. Moved on to the other scans and saved logs.

    Next issue:

    Running MGTools seemed daunting so I decided to wait till the morning. When I turned on the computer I was given a pop up about Avira installing a new Chrome browser extension called:

    ----------------------------------------------
    Avira Browser Safety 1.12.1
    ID: ID: flliilndjeohchalpbbcdekjklbdgfkk
    ----------------------------------------------------

    I found this odd since I did not install it myself. I left it disabled.

    Final issue was when running MGTools from my desktop (only option i had). At the point where I had to accept the TrendMicro Agreement I got the pop up message that I saved a screen grab of which is attached.

    I am not sure if I am having issues still since the computer has not locked up but logs are attached. Still curious about the fyk user issue and the fact some scans freeze at certain points.

    Thanks!
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Uninstall the below software using GeekUninstaller 1.4.0.88, a portable appl.

    Java 8 Update 51 <= outdated​

    Re-run Hitman Pro, activate/enable the free trial and allow it to remove:
    Malware => .exe.exe
    Potential Unwanted Programs​

    Now install the current version of Sun Java from:
    These are the only accounts that I find reference to in your logs and I don't find a malware cause for any changes. Let's run this online scanner. Go here ==> https://www.eset.com/us/online-scanner/ and click on the SCAN NOW radio button > save the esetonlinescanner_enu.exe Binary file to your Desktop > then right-click and choose "Run as Administrator". *Be patient! The scan can take 2hours or more.
     
  3. Condensermike

    Condensermike Private E-2

    Thanks for your help. I performed the tasks you listed and ran the Eset scan. Unfortunately it froze up at the very end. I have attached some screen grabs and the Hitman log.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    The Hitman Pro log is fine. The text in the screenshots are too tiny to read, but I did notice that you had your browser opened while running the scans (HJT log also shows this). It's always preferable to have your system doing nothing else while using malware detection and/or removal software.

    I have no theory regarding the issue of the user account being renamed.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  5. Condensermike

    Condensermike Private E-2

    I went back and reran Eset - this time with out any other applications running. Once again, it did not complete the scan and quit working giving a pop up that basically said Eos stopped working due to encountering a problem. I have attached a larger screen grab.

    Also, do you know why the administrator account is 'disabled', even though this is what I log into when starting Windows; yet the account 'fyk' is what is active? I read the part where you said you didn't understand why the user account was renamed. I am not sure it was renamed. It does not appear in the list of users under User Accounts in Control Panel. the only one listed is me, Mike Administrator. The only way I found it was searching for 'fyk' when Malwarebyte kept freezing up the other night. Only then did I realize this was a user folder called fyk under the c drive. Do you have any suggestions for finding out how this could have happened or how to disable this account?

    Thanks!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Below are other online scanners that you could run. Close ALL un-needed programs and applications (including your AV) before beginning the scan.

    Kaspersky Security Scan
    http://free.kaspersky.com/us?_ga=1.266376776.793029247.1475449675

    Bitdefender Online Scan
    http://www.bitdefender.com/scanner/...dbUQ-XNdUkkyCV1siyZuVM0&bdaffc=global&irgwc=1

    Trend Micro House Call
    http://housecall.trendmicro.com/uk/

    The built-in administrator account is a hidden and disabled account with Windows. Other user accounts can be created and given administrator privileges. According to your logs, there is no user account for "Mike". Malware no longer present may have changed the account's name. I think the proper thing would be to re-name that user account folder back to 'Mike', rather than deleting it. *You can receive further advice with that in our software forum.
     
  7. Condensermike

    Condensermike Private E-2

    I ran Kaspersky and it didn't find anything. I am going to follow your previous comments to finalize this thread. I will rename that folder and call it good. Thanks again!
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :) You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds