Virus Trojan:32/Wacatac.DC!ml not completely remediated on Windows PC

Page 4 of 5 FirstFirst ... 2345 LastLast

  1. Posts : 55
    win10
       #31

    Thxs, I'll think about it. I'm a little reluctant to add another antivirus program (besides WD I have Emisoft and the script noted above).

    Also, the problem is not finding and blocking wacatac, Windows Defender does a good job of that. I'm puzzled as why after running/deleting everything to ensure my machine is clean, the act of shutting down my computer activates it, or triggers WD to find and block it. Deleting the WD service history file was supposed to prevent a false positive, deleting all temp files (where WD says the trojan is) was supposed to ensure it was actually gone, and the script was supposed to ensure it couldn't be reactivated.
      My Computer


  2. Posts : 6,869
    22H2 64 Bit Pro
       #32

    mitrajoon said:
    Also, the problem is not finding and blocking wacatac, Windows Defender does a good job of that. I'm puzzled as why after running/deleting everything to ensure my machine is clean, the act of shutting down my computer activates it, or triggers WD to find and block it. Deleting the WD service history file was supposed to prevent a false positive, deleting all temp files (where WD says the trojan is) was supposed to ensure it was actually gone, and the script was supposed to ensure it couldn't be reactivated.
    Well I don't use Defender personally. Anyway it is obviously not removing whatever is putting it back on your machine.

    That program I suggested isn't meant to be a permanent install. Maybe install as a test and then see if it does indeed notify you when something dodgy attempts to run. At the moment it's freeware but not for much longer. I used it myself recently with zero issues alongside other security software.

    EDIT: It is also very light on resources.
      My Computer


  3. Posts : 55
    win10
       #33

    OK, thanks again. I'll give it a shot.

    - - - Updated - - -

    I have noted that when I restart my computer a file called unknown.log shows up in the Windows Defender Service History folder which I make sure is empty before I shut down.

    It's dated at the time I shut down my computer which is also about the time that WD reports blocking wacatac. Thoughts?
      My Computer


  4. Posts : 6,869
    22H2 64 Bit Pro
       #34

    I don't use Defender myself and have not used it for years. Even IT Admin at my workplace disables it and they use something else. Anyway with limited knowledge of Defender it looks to me like it would usually create logs named:

    History.Log
    Detections.log
    MPDetection-date.log
    MPLog-date.log
    Unknown.Log

    I suppose that you'd open the unknown log with notepad and read it.
      My Computer


  5. Posts : 6,869
    22H2 64 Bit Pro
       #35

    Some thoughts:

    Check what is actually running before shutdown and kill anything that doesn't actually need to be running.

    Then shutdown and check the next log.
      My Computer


  6. Posts : 55
    win10
       #36

    Nothing in WD Service Folder at shut down. When I restarted unknown.log was there with the following content:
    1446361181
    2613142394
    2500079355
    3222978219

    I'm not a computer person so this is just meaningless.

    I did first close everything obvious in Task manager. Mostly about 10 or so Adobe processes. That was a surprise as well. This feels more and more like my first visit to a sausage factory.
    .
    I'm beginning to think that a reinstall of Windows might be less painful.
      My Computer


  7. Posts : 55
    win10
       #37

    Callender: So I've had wisevector stopx installed for awhile and no reports of virus. Today when I turned on my computer it wouldn't load. I did a hard shutdown and then restarted my computer which came on as it should. Just now, WD reports it has blocked trojan win32/fuery.C!cl

    Again, I have tried at least a half dozen antivirus programs. None detects these viruses except WD.

    Unless you or someone else can come with a better plan, my choice now is to invoke the W10 Recovery option and reset my C Drive, or just let WD continue to block these trojans.
      My Computer


  8. Posts : 6,869
    22H2 64 Bit Pro
       #38

    Maybe check startup items for third party software that might run on boot and disable if not needed.

    On another note it's crap if it doesn't give you the file path.

    Virus Trojan:32/Wacatac.DC!ml not completely remediated on Windows PC-detection.jpg

    A harmless detection from my machine. Without knowing the file path or file name it's too hard to say what the issue is. If you had WiseVector StopX running when Defender detected the trojan I'd say it likely not serious.
      My Computer


  9. Posts : 55
    win10
       #39

    I only have 2 start up items: WD and my monitor profile calibration.

    I also checked File Manager to look for odd items. Checked a couple out but are legit. Even so I turned them off and set them to manual.

    WD does show the path. It's the same path as you show except: Temp\tmp00000071\tmp000d077

    While it doesn't list the name in the path, it does name as part of the report
    Virus Trojan:32/Wacatac.DC!ml not completely remediated on Windows PC-image.png

    For now I'll just assume/hope WD is taking care of things, though the start up issue this morning makes me nervous.
      My Computer


  10. Posts : 6,869
    22H2 64 Bit Pro
       #40

    That just shows a path to a temp directory and not the file name or extension.

    Anyway for startup items consider:

    https://docs.microsoft.com/en-us/sys...loads/autoruns

    If run autoruns.exe 32bit or autoruns64.exe 64bit depending upon your system. (Right click run as admin)

    Set options:

    "hide microsoft entries"

    Then options> scan options> scan virustotal

    Inspect all entries and check for software that you know for a fact does not need to run on boot.

    On another note maybe your Defender settings are too tight? Are they default recommended settings or did you change them?
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:44.
Find Us




Windows 10 Forums