Malware W10

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheRealStig, Feb 4, 2023.

  1. TheRealStig

    TheRealStig Private E-2

    Hi,

    Windows Security detected threat
    Trojan:Win32/Vigorf.A
    but was not able to resolve

    Please find logs from
    Malwarebytes, RogueKiller and Hitman.

    I can start MGTools but it never finishes.
    It creates a folder on C:/ but the MGlogs.zip is not created.
    See screendump after many hours running MG.

    Thanks a lot in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
    TheRealStig likes this.
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on the following link and use the below steps to scan a file: Virustotal

    Click the Browse... button.
    Navigate to the file FileToBescanned:Trojan:Win32/Vigorf.A

    Where FileToBeScanned is the actual file to be scanned. Like C:\WINDOWS\System32\vdmt16.sys
    [/LIST]
     
    TheRealStig likes this.
  4. TheRealStig

    TheRealStig Private E-2

    Attached the two Farbar logs.
    Loaded Virustotal, Sorry, not understood where to scan. When I search for Vigorf I find nothing.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    please read the addition text regarding Windows Defender. and th file location. Please update it and scan again. Attach th e new log as well as the ATF cleaner log.​
     
  6. TheRealStig

    TheRealStig Private E-2

    Attached the 3 threats from Windows Security plus the 3 returns from VirusTotal.
    Didn't find option to export log.

    Do you want me to download and run
    https://atf-cleaner.en.softonic.com/
    ?
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And did you click on actions? BTW< Did you install any cracked software? Sorry..please run ADW Cleaner and attach the log.and did you update Defender?
     
  8. TheRealStig

    TheRealStig Private E-2

    Yes, I tried to remove the threat with Windows Security - as it didn't work, I contacted you.
    Attached the print from Windows Security history. Yes updated.
    I suspect the threat appeared on a software file I use occasionally and have on a HD. EaseUS Partition Master. Have used it several times before without problems. Copied from HD to laptop but did not get to install. Deleted it when first threat message appeared.
    ADW log attached.

    Did you want me to run ATF Cleaner as well?
     

    Attached Files:

  9. TheRealStig

    TheRealStig Private E-2

    ADW log
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please download Zemana Malware Removal to your desktop and run it please.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  11. TheRealStig

    TheRealStig Private E-2

    Thanks, ran the default scan (quick, not deep) and got two detections.
    No report is shown (so can't highlight and open), but for each detection there is the option to copy details.
    I copied these into attached .txt
    Also sending you the screenprints.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. TheRealStig

    TheRealStig Private E-2

    Nothing detected
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good....I sugest you uninstall Firefox, run Ccleaner and reinstall From MG's downloads
     
  15. TheRealStig

    TheRealStig Private E-2

    Done, but without reinstalling Firefox yet.
    I ran a Microsoft Defender Offline scan which didn't show anything (also not that nothing was found).
    Attached the prints from Windows Security - after the Offline scan I did a quick scan - same threats found again.
    I noticed the Offline scan does not show up in history?
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is what Zemana found:

    "
    MD5 :
    Status : Scanned
    Object : c:\users\stigk\appdata\roaming\mozilla\firefox\profiles\xxdezdq8.default-release\extensions\jid0-gxjllfbcoax0lcltedfrekqdqpi@jetpack.xpi
    Publisher :
    Size : 0
    Detection : HijackExt:FirefoxPlugin/jid0-GXjLLfbCoAx0LcltEdFrEkQdQPI@jetpack
    Action : Delete

    MD5 :
    Status : Scanned
    Object : c:\users\stigk\appdata\roaming\mozilla\firefox\profiles\xxdezdq8.default-release\extensions\{48f29f44-6ab3-4e1d-99ee-c673520ad414}.xpi
    Publisher :
    Size : 0
    Detection : HijackExt:FirefoxPlugin/{48f29f44-6ab3-4e1d-99ee-c673520ad414}
    Action : Delete

    Foxfire plugins..... extentions. Please. it will proobably not go away until you do that and progressive Zemana scans are clean.
     
  17. TheRealStig

    TheRealStig Private E-2

    Thanks TimW,
    OK, I didn't want to apply any actions without your instruction first :)
    So, Firefox uninstalled, then I ran CCleaner and restarted.
    Windows Secutiry still with warning.
    Ran Zemana, same two detections. Applied DELETE and restarted.
    Ran Windows Security - no threat detected but old not resolved. I'm not able to quarantine, nor delete. Tried Offline scan also.
    Ran Zemana once again, the same two threats that I had applied DELETE come up again.
    Next step?
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It would seem that not all traces of firefox was emoved. try this then reboot and run Ccleaner again.

     
  19. TheRealStig

    TheRealStig Private E-2

    Hi Tim, above was not possible to do as nothing regarding Firefox was found - but by deleting the Service folder from C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service,
    issue was resolved, all good now.
    Thanks a million for your help!
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds