Windows 10: Computer Infection--Emergency!

Discus and support Computer Infection--Emergency! in AntiVirus, Firewalls and System Security to solve the problem; Slow down. It's a trojan downloader. It doesn't spread, it downloads other stuff. JS_NEMUCOD.MV - Threat Encyclopedia - Trend Micro USA I think... Discussion in 'AntiVirus, Firewalls and System Security' started by AMDMan2016, Sep 21, 2016.

  1. simrick Win User

    Computer Infection--Emergency!


    Slow down. It's a trojan downloader. It doesn't spread, it downloads other stuff.
    JS_NEMUCOD.MV - Threat Encyclopedia - Trend Micro USA


    I think you caught things in time. This downloader is noturious for bringing in Locky encryption ransomware, of which you don' t have.
     
    simrick, Sep 22, 2016
    #31

  2. Flew, slows down a bit, so no clean install needed of Windows 10 and all other programs? Think I will still do clean install of Windows 10 Pro, just have to finish backing up all the personal pictures, mp3 files, and documents, I think I will feel safer that way, glad I caught it in time though before it got the Encryption ransomware though, that's a relief
     
    AMDMan2016, Sep 22, 2016
    #32
  3. simrick Win User
    Really, at this point, I don't think it's necessary. Unless you find any ransom notes in any of your data folders:
    Code: _Locky_recover_instructions.txt[/quote] The Locky Ransomware Encrypts Local Files and Unmapped Network Shares
    But if you're up to a clean install, that's always a good thing. *Smile

    I think you caught it in time. Not many people monitor their CPU usage and processes like you and I do. Those who do, see things as soon as they start to happen. Trojan downloaders need time to phone home, to find a site that's not been shutdown, wait for instructions, download the payload, and then execute. Mind you, all this can happen in a flash, but sometimes we get lucky, and we stop them in their tracks. Defender certainly did its job for you this time.

    It's likely this came in as an email attachment from a phishing email. If you use an email client (Outlook/Thunderbird, WindowsLiveMail, etc.), and have it sent to auto-preview messages, simply previewing a message can be enough to trigger the trojan. Other times you actually have to try to open the attachment for it to start downloading junk.

    If you can, I would use best practice for backups, the 3-2-1 method: 3 rotating backups, 2 taking turns being connected to the machine, and one off-site. The best backup method I have found is Macrium Reflect Free. It can be set to run automatically; images can be mounted and single files pulled off if needed. You can even automatically add Macrium to your boot menu. Plus if your hard drive bites the dust, a new drive can be imaged and you're back in business within a short amount of time. No installing of programs necessary.

    I will make a few suggestions for your computer security, if it's okay:

    You see that this (and most downloaders) download their payload(s) to the appdata/temp file directory and attempt to execute from there, so a program which prevents executable files from executing out of uncommon areas such as these would help. The one I use is:

    CryptoPrevent (free version)

    Firefox browser, with appropriate security settings in place (I can go into that in another post).

    Set your email client so it doesn't auto-preview, and never open attachments you are not expecting.

    Defender is good, and certainly saved your bacon this time. ESET NOD32 (paid) would be a step up, and you can find it a lot on sale at Newegg. They also have a 30-day trial if you want to test it out. It's one of my favs.

    Malwarebytes Antimalware: Free is good, but it's passive. If you can swing it, the Pro (paid) version is active protection, and their beta anti-ransomware module will be rolled into the Pro version as soon as it's out of beta.

    SuperAntiSpyware Free: another passive one, clearing tracking cookies and some malware.

    MBAE Malwarebytes Antiexploit: free version provides protection for exploits against your browsers. The paid version provides protection for all internet-facing applications on the computer.

    Unchecky: prevent those unwanted PUPs and PUMs from installing along with other software.

    A layered approach is required, as each program has its niche/specialty.
     
    simrick, Sep 22, 2016
    #33
  4. Computer Infection--Emergency!

    Yes, money wise not much due to being disabled, but i'lll see what I can swing, might try Firefox browser, up for a Clean install, and with 10 it doesn't take that long to do, not sure if I can set Windows 10 Mail app to not preview email messages or not, but i'll check on that as well, I got a lot of files, I spend most of my time gaming, or in Secondlife game, or doing some other tasks at times. So Clean install won't be too much trouble I guess
     
    AMDMan2016, Sep 22, 2016
    #34
  5. simrick Win User
    Understood. Use the free versions where you can, and set reminders to run scans on a regular basis yourself.

    It's unfortunate that we're not able to get the flagged items form the ESET online scan. Reading here:
    JS/Nemucod
    The Nemucod family also try to download password stealers and information grabbers. Might want to keep an eye on your email addresses at these 2 sites:
    Find the source of your leaks
    Have I been pwned? Check if your email has been compromised in a data breach
    And, if you use yahoo mail, be sure to change your password now. Their 2-year-old hack has been put up for sale on the dark web.

    Also, make sure you do not re-use passwords. A password manager like LastPass will help you with that.

    Let me know when you're ready to setup Firefox, and we'll detail that out.
     
    simrick, Sep 22, 2016
    #35
  6. Yeah will change all the passwords after the clean install I think might be best option right now, I don't reuse any passwords, mine are usually 8-10 characters or more long, or longer---remembering them is hard part at times, but I do pretty well so far with most of the passwords.

    Will let know when i'm ready to setup firefox and see if I like it, I might, but not sure yet, never used any other browser except IE, but for now just make sure I got the files I can't lose backed up, then find WIndows 10 Pro 64bit flash drive, and proceed with clean install, then should be feeling safer, and install the suggested security items, and hopefully all good
     
    AMDMan2016, Sep 22, 2016
    #36
  7. simrick Win User
    Get the latest one here:
    Windows 10 ISO

    Listen (don't tell anyone, but) I was a die-hard IE user for many years. *Wink
     
    simrick, Sep 22, 2016
    #37
  8. Computer Infection--Emergency!

    Computer Infection--Emergency! [​IMG]
     
    RubberDucky, Sep 23, 2016
    #38
  9. Kol12 Win User
    Sorry to hijack, but is CryptoPrevent a good all round AV supplement? It can apparently protect against viruses other AV's can't...

    I see that you don't use EMET. I'm trying to find the answer as to whether I should move it on and use MBAE premium instead. Apparently EMET in use with Windows 10 has a secondary login vulnerability but I don't fully understand what that is.

    EMET can protect any app on your machine, can MBAE premium do close to that?
     
    Kol12, Sep 23, 2016
    #39
  10. simrick Win User
    CryptoPrevent: Does it work? - Anti-Virus, Anti-Malware, and Privacy Software
    Wouldn't be without this program.

    Seems MS patched that vulnerability in February.
    Attackers can turn Microsoft's exploit defense tool EMET against itself | PCWorld
    Still, I prefer MBAE.

    From what I understand, MBAE Pro can be configured to protect all internet-facing applications on the machine.

    Frequently Asked Questions - Malwarebytes Anti-Exploit - Malwarebytes Forums

    How to verify that MBAE is working correctly - Malwarebytes Anti-Exploit - Malwarebytes Forums

    And here's an interesting thread to read:
    MBAE and EMET - Anti-Virus, Anti-Malware, and Privacy Software


    .
     
    simrick, Sep 23, 2016
    #40
  11. simrick Win User
    Sssshhhhhh! It's not something I want spread around! *Roflmao2
     
    simrick, Sep 23, 2016
    #41
  12. It already spread when you're on the internet.
     
    RubberDucky, Sep 23, 2016
    #42
  13. Computer Infection--Emergency!

    Windows 10 Clean Install all done, System running fine now, restored personal documents, and files, ran 1 virus scan, all clean, so hopefully stays that way now, Still Not sure on Firefox, so so used to Internet Explorer/MS Edge browser, But maybe i'll warm up to Firefox eventually, adblocker setup on Ms Edge, Slowly changing account passwords, but got a lot, so gonna take a bit on that part. Thank you everyone for the help, marking this thread as solved I think
     
    AMDMan2016, Sep 24, 2016
    #43
  14. simrick Win User
    Good job!
    At this point, it would be wise to start making images of your system, so you don't have to go through this again.
    Macrium Reflect - Backup Restore - Windows 10 Forums

    Cheers! *Thumbs
     
    simrick, Sep 24, 2016
    #44
  15. Already did make an image right after I had the drivers in, and a few programs.. Drive limited on space though, so only can make so many, before I'm out of room
     
    AMDMan2016, Sep 24, 2016
    #45
Thema:

Computer Infection--Emergency!

Loading...
  1. Computer Infection--Emergency! - Similar Threads - Computer Infection Emergency

  2. Emergency help with infected laptop

    in Windows 10 Gaming
    Emergency help with infected laptop: My computer got a virus last year I clicked a downloaded file and got sent to a site and I exited out fast forward early 2022 I go back to using my computer then one day while I'm using it my cursor started moving and my mic was being accessed I shutted down my computer and a...
  3. Emergency help with infected laptop

    in Windows 10 Software and Apps
    Emergency help with infected laptop: My computer got a virus last year I clicked a downloaded file and got sent to a site and I exited out fast forward early 2022 I go back to using my computer then one day while I'm using it my cursor started moving and my mic was being accessed I shutted down my computer and a...
  4. Infected computer

    in Windows 10 Gaming
    Infected computer: My Windows Apps are infected by spyware. https://answers.microsoft.com/en-us/windows/forum/all/infected-computer/b212b029-7987-4bbf-a288-3efa16d9e544
  5. Infected computer

    in Windows 10 Software and Apps
    Infected computer: My Windows Apps are infected by spyware. https://answers.microsoft.com/en-us/windows/forum/all/infected-computer/b212b029-7987-4bbf-a288-3efa16d9e544
  6. Computer is infected

    in AntiVirus, Firewalls and System Security
    Computer is infected: So, uh. This is my first time and I’m doing pretty good. Just uh. The infection in task manager won’t allow me to stop or shut it down. I can’t even edit permissions. This malware or virus is from a website called safe windows. I’m curious if it’s ok to turn the computer off....
  7. Computer is infected

    in Windows 10 Software and Apps
    Computer is infected: So, uh. This is my first time and I’m doing pretty good. Just uh. The infection in task manager won’t allow me to stop or shut it down. I can’t even edit permissions. This malware or virus is from a website called safe windows. I’m curious if it’s ok to turn the computer off....
  8. *EMERGENCY* IS THIS A VIRUS? *EMERGENCY*

    in Windows 10 BSOD Crashes and Debugging
    *EMERGENCY* IS THIS A VIRUS? *EMERGENCY*: I found this in the registry context menu : Computer\HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{48F45200-91E6-11CE-8A4F-0080C81A28D4} Is this a virus of some sort?...
  9. Computer Infected.

    in AntiVirus, Firewalls and System Security
    Computer Infected.: Dear Community, My computer has been acting very strange in the last one or two weeks. Most of the time when my computer is opened I hear a sound like connecting a new device to the computer but I'm not doing anything. I tried running Malware Bytes and Avast but...
  10. infected computer

    in AntiVirus, Firewalls and System Security
    infected computer: can someone help me remove infection from my computer it has ben hacked https://answers.microsoft.com/en-us/protect/forum/all/infected-computer/cfefb8d9-ae88-42fa-9495-2bb8c6899963