seems fine now
[SID: 27212] system Infected: Trojan.Malscript Activity Detected.
10 min read
Great.
Let's do a little housekeeping:
Uninstall Combofix
Follow these steps to uninstall Combofix
- click START then RUN
- now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
Click to load external image (CFuninstall.jpg)
- please follow the prompts to uninstall Combofix.
- once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
Download & run Delfix
- download Delfix from here to remove many of the tools we've used during the cleaning process.
- ensure “Remove disinfection tools” is checked.
Also place a checkmark next to:
o Create registry backup
o Purge system restore
- click the Run button.
You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.
Now, some articles to read and think about;
- Answers to common security questions - Best Practices by quietman7, MVP
- How Malware Spreads - How did I get infected? by quietman7, MVP
- Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
- How to Prevent Malware by miekiemoes, MVP
- How to backup and restore your data using Cobian Backup by YourHighness
- Slow Computer/browser? It May Not Be Malware by quietman7, MVP
The following programmes come highly recommended in the security community. - [external image: xKsUqI5A.png.pagespeed.ic.vn1Hlvqi8h.jpg]AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
- [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg.CryptoPrevent), preventing your files from being encrypted.
- [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
- Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
- NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
- [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
- Secuina PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
- SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
- Web of Trust (WOT) is a browser add-on designed to alert you before interacting with a potentially malicious website.
Please respond back one more time to let me know if you have any questions.
Thanks Tomk,
Please let me know the exact source (file that got infected) of malware?
Is it a virus or spyware that I was infected with?
Just to confirm that Symantec Anti-Virus Protection installed on my system was unable to detect this infection?
Also, when I downloaded Delware, Symantec blocked the software but I have to manually allow it…why it blocked delware?
Your winlogon.exe file was infected with Win32:VB-OQE. This is not a virus or spyware… it is a Trojan. It tries to download other nefarious infections, but it appears that it was unsuccessful as we didn't find any others. This variant has been around since about the first of the year. It is most often found in cracked software, but can be found in other patched files (seemingly "good" files that have had the malicious code injected in them) and there have been reports of it being acquired through clicking on pop up ads. In your case, it appears it may have been attached to a movie called "Our Incomplete Story" but I'm not positive.
Based upon the warning from Symantec that you provided in your first post… Symantec did detect it, but was apparently unable to remove it. When you use torrents you open ports that bypass your onboard security and therefore allow them to be installed. Your security then has to remove them, which is a harder job than it would have been to block them in the first place.
Antivirus programs usually block programs like delfix through their hueristics detection. The program makes changes to your system and isn't digitally signed. This appears to be malicious to your security system.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI