Windows 10: WD says I have a trojan at every boot

Discus and support WD says I have a trojan at every boot in AntiVirus, Firewalls and System Security to solve the problem; Hello. Windows Defender says I have a trojan on every boot buy when I check WD Security Center there is nothing there. I haven't noticed anything... Discussion in 'AntiVirus, Firewalls and System Security' started by eLPuSHeR, Jul 26, 2017.

  1. eLPuSHeR Win User

    WD says I have a trojan at every boot


    Hello.

    Windows Defender says I have a trojan on every boot buy when I check WD Security Center there is nothing there.

    I haven't noticed anything weird but the message is getting on my nerves.

    Ran AdwCleaner and it came up clean.

    This is the report and suspected file via Powershell:

    CategoryID : 8
    DidThreatExecute : False
    IsActive : False
    Resources : {file:_C:\Users\LaBusqueda\AppData\Local\Microsoft\Windows\INetCache\IE\CRDA093Q\deploy[1].xml,
    file:_C:\Users\LaBusqueda\AppData\Local\Microsoft\Windows\INetCache\IE\R5XBHIFN\deploy[1].xml,
    file:_C:\Users\LaBusqueda\AppData\Local\Microsoft\Windows\INetCache\IE\XYO5Y5ZK\deploy[1].xml}
    RollupStatus : 33
    SchemaVersion : 1.0.0.0
    SeverityID : 5
    ThreatID : 2147722737
    ThreatName : Trojan:JS/Runsas
    TypeID : 0
    PSComputerName :


    ActionSuccess : True
    AdditionalActionsBitMask : 0
    AMProductVersion : 4.11.15063.447
    CleaningActionID : 2
    CurrentThreatExecutionStatusID : 1
    DetectionID : {296FDAD3-8D05-4216-BD74-D3E87F3DB9C5}
    DetectionSourceTypeID : 3
    DomainUser : LABUSQUEDA\LaBusqueda
    InitialDetectionTime : 26/07/2017 9:34:25
    LastThreatStatusChangeTime : 26/07/2017 9:34:58
    ProcessName : C:\Windows\System32\regsvr32.exe
    RemediationTime : 26/07/2017 9:34:58
    Resources : {file:_C:\Users\LaBusqueda\AppData\Local\Microsoft\Windows\INetCache\IE\R5XBHIFN\deploy[1].xml}
    ThreatID : 2147722737
    ThreatStatusErrorCode : 0
    ThreatStatusID : 3
    PSComputerName :

    That file isn't present because I emptied all my browsers caches.

    Any ideas on how to proceed?

    TIA

    :)
     
    eLPuSHeR, Jul 26, 2017
    #1

  2. I have been infected with Trojan: JS/BlacoleRef.CC

    I got a message from Windows Defender (WD) about been infected by this trojan, JS/BlacoleRef.CC, and I said yes to its deletion asking. Afterwards, as recommended, I ran a full scan of WD and it did not appear back but now all options in WD settings
    are not accessible. I was trying to see excluded files. What to do?

    [Original Title: Trojan: JS/BlacoleRef.CC]
     
    JesúsConde, Jul 26, 2017
    #2
  3. Barbb2019 Win User
    Windows Defender cannot remove Trojan:BAT/Poweliks.A

    Hello,

    If I only have one dllhost running does that mean I don't have the Poweliks Trojan? even though windows defender on occasion, especially while booting up says I have a Trojan threat?

    thanks, Barbb
     
    Barbb2019, Jul 26, 2017
    #3
  4. swarfega Win User

    WD says I have a trojan at every boot

    swarfega, Jul 26, 2017
    #4
  5. eLPuSHeR Win User
    Yes. I have already thought about running an AV program offline but I cannot right now. It's a work PC.

    I will check it later. I may run WD offline too to have a second opinion.

    Thank you very much.
     
    eLPuSHeR, Jul 26, 2017
    #5
  6. swarfega Win User
    This is the opposite, its their online scanner, you don't have to install the full program, just enough to get a scan going.

    An offline scan wouldn't hurt either *Biggrin
     
    swarfega, Jul 26, 2017
    #6
  7. lx07 Win User
    Sign onto another account and delete the C:\Users\LaBusqueda\AppData\Local\Microsoft\Windows\INetCache folder.

    It will be regenerated next time you log on.
     
  8. WD says I have a trojan at every boot

    TairikuOkami, Jul 26, 2017
    #8
  9. Try an offline scan, open WD security center, click advanced on the scan section, select offline scan and click scan then click scan and follow the on-screen instructions
     
    TheGreenNinja9, Jul 26, 2017
    #9
  10. simrick Win User
    simrick, Jul 27, 2017
    #10
  11. eLPuSHeR Win User
    In the end I restored a Macrium Reflect backup copy. Now I have to investigate where and how I caught that. I have made some changes to WD to strengthen security (enable pua dectection) and I have installed MBAE (which wasn't installed).
     
    eLPuSHeR, Jul 27, 2017
    #11
  12. swarfega Win User
    Surprised you've never heard of SAS, its pretty well known on these forums. Its mostly used for scanning for malicious cookies which it does very well.
     
    swarfega, Jul 27, 2017
    #12
  13. simrick Win User

    WD says I have a trojan at every boot

    Oh no - I meant I'd never heard of the infection; SAS I've used for years. *Wink
     
    simrick, Jul 28, 2017
    #13
  14. simrick Win User
    If you ever figure it out, would be interesting to know!
     
    simrick, Jul 28, 2017
    #14
  15. eLPuSHeR Win User
    As far as I know, it was some virus from the Gamarue family or such. I plug in a lot of infected usb sticks, it could have come from there (not very probably) or something we clicked while browsing the web. It's hard to know.
     
    eLPuSHeR, Apr 5, 2018
    #15
Thema:

WD says I have a trojan at every boot

Loading...
  1. WD says I have a trojan at every boot - Similar Threads - says trojan every

  2. I have a trojan

    in Windows 10 Gaming
    I have a trojan: In thereC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\But I can't delete it. https://answers.microsoft.com/en-us/windows/forum/all/i-have-a-trojan/cb994d44-c77a-4743-b2b7-aac80a2f635d
  3. I have a trojan

    in Windows 10 Software and Apps
    I have a trojan: In thereC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\But I can't delete it. https://answers.microsoft.com/en-us/windows/forum/all/i-have-a-trojan/cb994d44-c77a-4743-b2b7-aac80a2f635d
  4. I have a trojan

    in AntiVirus, Firewalls and System Security
    I have a trojan: In thereC:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\DeliveryOptimization\Cache\But I can't delete it. https://answers.microsoft.com/en-us/windows/forum/all/i-have-a-trojan/cb994d44-c77a-4743-b2b7-aac80a2f635d
  5. Windows says I have trojan but it dissapears

    in AntiVirus, Firewalls and System Security
    Windows says I have trojan but it dissapears: Windows says I have a trojan with severe warning level but after about 10 seconds on the security page it disappears and windows says my PC is clean. This has happened 3 times now, and when I look through task manager I don't see anything suspicious...
  6. Windows says I have trojan but it dissapears

    in Windows 10 Gaming
    Windows says I have trojan but it dissapears: Windows says I have a trojan with severe warning level but after about 10 seconds on the security page it disappears and windows says my PC is clean. This has happened 3 times now, and when I look through task manager I don't see anything suspicious...
  7. Windows says I have trojan but it dissapears

    in Windows 10 Software and Apps
    Windows says I have trojan but it dissapears: Windows says I have a trojan with severe warning level but after about 10 seconds on the security page it disappears and windows says my PC is clean. This has happened 3 times now, and when I look through task manager I don't see anything suspicious...
  8. Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?

    in Windows 10 Gaming
    Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?: Currently using Windows 10 on my laptop and Defender has scanned the device and given me a warning about a severe TrojanWin32/Skeeyah. Initially I pressed the take action button on Defender but that appeared to do nothing. After Defender had done nothing I installed the free...
  9. Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?

    in Windows 10 Software and Apps
    Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?: Currently using Windows 10 on my laptop and Defender has scanned the device and given me a warning about a severe TrojanWin32/Skeeyah. Initially I pressed the take action button on Defender but that appeared to do nothing. After Defender had done nothing I installed the free...
  10. Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?

    in AntiVirus, Firewalls and System Security
    Microsoft Defender says that I have a trojan but Malwarebytes says that by laptop is fine?: Currently using Windows 10 on my laptop and Defender has scanned the device and given me a warning about a severe TrojanWin32/Skeeyah. Initially I pressed the take action button on Defender but that appeared to do nothing. After Defender had done nothing I installed the free...