Virus in System32 winevt


  1. Posts : 448
    Windows 10
       #1

    Virus in System32 winevt


    Avast in my Win 10 PC is showing threat as in the attached image but not able to resolve. I am even not able to delete this file manually. What is the importance of this file. How to delete it.Virus  in System32 winevt-winevt.jpg
      My Computer


  2. Posts : 16,325
    W10Prox64
       #2

    Hi.
    Avast have a boot scan feature which you should try. Defo@boot infects the MBR, so it can't be removed while you're in the operating system.
    Running a Boot-time Scan in Avast Antivirus | Official Avast Support

    If that doesn't work, have a look at the steps here:
    https://www.precisesecurity.com/virus/threatdefoboot
    .
    Last edited by simrick; 22 Jun 2018 at 21:37.
      My Computer


  3. Posts : 448
    Windows 10
    Thread Starter
       #3

    simrick said:
    Hi.
    Avast have a boot scan feature which you should try. Defo@boot infects the MBR, so it can't be removed while you're in the operating system.
    Running a Boot-time Scan in Avast Antivirus | Official Avast Support

    If that doesn't work, have a look at the steps here:
    Threatefo@boot - Virus Solution and Removal
    .
    Thanks. I have already tried Avast Boot Scan. Previously it was in MBR in my other hard disk which I had to ultimately formatted. In my this disk, I think this is not in MBR but a log file in System. I simply want to delete or replace this file. I think deleting this file should not make any problem for PC. I have tried TDSS .killer though not in safe mode and it did not detect this.
      My Computer


  4. Posts : 16,325
    W10Prox64
       #4

    sam9 said:
    Thanks. I have already tried Avast Boot Scan. Previously it was in MBR in my other hard disk which I had to ultimately formatted. In my this disk, I think this is not in MBR but a log file in System. I simply want to delete or replace this file. I think deleting this file should not make any problem for PC. I have tried TDSS .killer though not in safe mode and it did not detect this.
    Okay, I guess my question would be: How did this event end up on your new drive? Is the new drive a clone or restored image of the old one?

    I think you should be able to do this (but be sure to have an image made first, in case you have any problems):
    Double-click the log file to open it in Event Viewer.
    In the right pane under Actions, select Clear Log.

    I've never done this myself, so not sure how much will be cleared, but you can try it. If it works, and it's cleared, and then it reappears, I'd say you still have a problem.
      My Computer


  5. Posts : 448
    Windows 10
    Thread Starter
       #5

    simrick said:
    Okay, I guess my question would be: How did this event end up on your new drive? Is the new drive a clone or restored image of the old one?

    I think you should be able to do this (but be sure to have an image made first, in case you have any problems):
    Double-click the log file to open it in Event Viewer.
    In the right pane under Actions, select Clear Log.

    I've never done this myself, so not sure how much will be cleared, but you can try it. If it works, and it's cleared, and then it reappears, I'd say you still have a problem.
    Thanks. Your and my thoughts are just similar. I already cleared all logs but you can yourself check that lots of logs of around 68 kb each reappear. Though this virus was showing in a log file and it may not be harmful but I was not at ease seeing my system affected with virus. So finally I went back to restore my system images one by one and then in third attempt, the image I restored was clean. For information , TDSSkiller, zero access tool and defender could not pick up virus in this file.
      My Computer


  6. Posts : 16,325
    W10Prox64
       #6

    sam9 said:
    Thanks. Your and my thoughts are just similar. I already cleared all logs but you can yourself check that lots of logs of around 68 kb each reappear. Though this virus was showing in a log file and it may not be harmful but I was not at ease seeing my system affected with virus. So finally I went back to restore my system images one by one and then in third attempt, the image I restored was clean. For information , TDSSkiller, zero access tool and defender could not pick up virus in this file.
    Good! I am surprised that TDSSKiller/Zeroaccess tool/Defender picked up nothing. That is so strange. But, glad you have a clean system now - that would bug me too, having it there.
      My Computer


  7. Posts : 16,325
    W10Prox64
       #7

    Please go ahead and mark the thread as solved. Cheers!
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 10:04.
Find Us




Windows 10 Forums