Hacked or not, Trojan?

Anonymous
2025-05-08T07:13:38+00:00

I have gotten this exact same "threat" since 24th of april (i figure out how to stop nitifictions) but still, I am not sure what to do I have scaned on my laptop twice with two diffenet antivurs ( malwer byts ( the one in the screen shot) and KVRT) and showe dnothing, my laptop is 100% safe? but this message was poping up, i tryed to delte teh fiel but it is blocked by the microsft coraption. So PLEASE i am DESPERT HELP ME

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

91 answers

Sort by: Newest
  1. Ramesh 181.2K Reputation points Volunteer Moderator
    2025-05-23T06:34:03+00:00

    ok, one other thing evertime i have something open and click alt tab (right now only google is open) i see something called UNCserver, is that normal, its been here fo rlike foreverr

    UNCServer belongs to the Lenovo System Update utility installed on your system.

    UNCServer-window-opens-when-snapping-windows - English Community - LENOVO COMMUNITY:

    https://forums.lenovo.com/t5/Windows-10/UNCServer-window-opens-when-snapping-windows/m-p/4284330

    UNC Server - Microsoft Community: https://answers.microsoft.com/en-us/windows/forum/all/unc-seerver/a48fc9e8-47e0-4a05-85ad-d10fea5724eb

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2025-05-23T06:26:37+00:00

    ok, one other thing evertime i have something open and click alt tab (right now only google is open) i see something called UNCserver, is that normal, its been here fo rlike foreverr

    Was this answer helpful?

    0 comments No comments
  3. Ramesh 181.2K Reputation points Volunteer Moderator
    2025-05-22T05:02:37+00:00

    ok, so do i enable mege sync and cmd, form start up or leave thme off?

    Yes. But even though the rogue module has been removed and the system is clean, consider removing TopazAI and installing it from the vendor's site if you need it. The one you installed used a self-extracting .rar archive (from an unknown source) that bundled the fake jli.dll. The program loaded this DLL at every startup and tried to establish a connection with a remote host.

    The cmd.exe entry in the startup tab can be deleted. To do so, use the Microsoft Autoruns tool and delete the cmd.exe (topazserv.exe) entry in the "Logon" tab.

    Autoruns - Sysinternals | Microsoft Learn: https://learn.microsoft.com/en-us/sysinternals/downloads/autoruns

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2025-05-21T22:40:02+00:00

    ok, so do i enable mege sync and cmd, form start up or leave thme off?

    Was this answer helpful?

    0 comments No comments
  5. Ramesh 181.2K Reputation points Volunteer Moderator
    2025-05-20T01:41:32+00:00

    ok, topaz ai is stll working, I have autheincer app for my out look, and my pssword are saved in keeper extension with complex passwordds.

    Ok, I hope that resolves the issue. Let me know.

    Was this answer helpful?

    0 comments No comments