Virus Trojan:32/Wacatac.DC!ml not completely remediated on Windows PC

Page 2 of 5 FirstFirst 1234 ... LastLast

  1. Posts : 98
    Windows 10
    Thread Starter
       #11

    Ah! I did not realise you had added their details to an earlier message.

    Well, Malwarebytes is clear. The other products will be downloaded and run over the weekend.
    Last edited by Mr Morgan; 31 Jul 2020 at 16:25.
      My Computer


  2. Posts : 55
    win10
       #12

    Windows Defender has just started reporting this on my desk top. I have run emisoft, SpyHunter5 and neither can detect it. Is there any evidence that this is real or is it a false positive? I have dozens and dozens of PWs I recently changed. Would not want to go through that again.
      My Computer


  3. Posts : 55
    win10
       #13

    Still looking for help on this. When I turned on my computer this morning and checked Windows Defender it reported wacatac blocked last night about the time I shut down my PC. 2 days ago I had followed instructions provided by SpyHunter and deleted local/appdata/temp files in SafeMode (this is where Windows Defender says the trojan file is located). Really wish someone would jump in here.
      My Computer


  4. Posts : 5,452
    Windows 11 Home
       #14

    mitrajoon said:
    Is there any evidence that this is real or is it a false positive?
    Upload the file to VirusTotal
      My Computer


  5. Posts : 55
    win10
       #15

    Thxs, but the file doesn't exist, it is deleted by Windows Defender. Also it has a different name every time. Here is what I have from yesterday: C:\Users\Jim\AppData\Local\Temp\tmp00000163\tmp000cb084

    If I am misunderstanding please let me know. Also, I found a thread that suggested deleting and turning off Restore Points. I've done that, but frankly it makes me nervous, especially with W10 updates going sideways and my own incompetence. Any thoughts on this would be appreciated.
      My Computer


  6. Posts : 685
    Windows 10 Pro 64-bit
       #16

    It looks like Defender stopped it before it was able to run. I think you doing a System Restore is what is causing it. When you went back to another time you took a snapshot of the current time (at the time) with the trojan still on the system, so when Defender scans, I believe it is picking up the system restore image. Check your System Restore points. If you have one that is available for the date of infection, that's most likely the case. If so delete your restore points, do a scan, and if all is good, create a new restore point.
      My Computer


  7. Posts : 55
    win10
       #17

    Thxs. I deleted all restore points, deleted temp files, did a restart, ran defender (all clean) and then created a restore point. Ran defender again, all clean. I've done all this before except for deleting the restore points. Oh, I also deleted my c: drive image back up (on an external drive) in case that might contain the trojan as well.

    We'll see what happens tomorrow.

    - - - Updated - - -

    Apparently this trojan becomes active when I shut down my computer. I ran defender, emisoft and spy hunter just before I shut down. All indicated no problems. When I turned on my computer this morning I had a notification that defender had found and blocked wacatac about the time I shut my computer down. I will go through the process noted above tonight, carefully note the time I shut down, restart my computer, check again and note the time I shut down for the night, but I'm not optimistic.

    Can anyone help me fix this?
      My Computer


  8. Posts : 5,452
    Windows 11 Home
       #18

    Turn off computer with CCleaner and select to clean everything, except cookies.

    Additionally, run CMD as admin and copy/paste code (it disables scripting used by malware):
    Code:
    reg add "HKLM\Software\Microsoft\Windows Script Host\Settings" /v "Enabled" /t REG_DWORD /d "0" /f
    reg add "HKLM\Software\WOW6432Node\Microsoft\Windows Script Host\Settings" /v "Enabled" /t REG_DWORD /d "0" /f
      My Computer


  9. Posts : 55
    win10
       #19

    Tairku:
    1) Do you mean uncheck "delete all cookies" for all browsers? I currently have delete cookies checked for Edge, Windows Explorer, Chrome and FireFox.
    2) Do you mean copy/paste and run the first CMD prompt, then do the same for the second, so that I am running two sequential commands? Or do I copy/paste them both at the same time? I'm not a computer person so I just want to be sure.

    Also the following sequence of events seems to confirm that wacatac is being triggered by shut down or start up:
    7:29 PM Defender run and reported no threats
    Turned off computer and restarted it
    7:31 PM Defender run and reported no threats
    7:40 Defender reported it detected and blocked wacatac

    I will try your method tomorrow. Just need to understand your instructions.
      My Computer


  10. Posts : 5,452
    Windows 11 Home
       #20

    mitrajoon said:
    Tairku: 1) Do you mean uncheck "delete all cookies" for all browsers? I have delete cookies checked for Edge, Windows Explorer, Chrome and FireFox.
    Then it is fine. It is just that most people would mind, if theirs logins were removed.

    mitrajoon said:
    2) Do you mean copy and paste and run the first CMD prompt, then do the same for the second, so that I am running two sequential commands?
    You can do both at once.
    Attached Thumbnails Attached Thumbnails Virus Trojan:32/Wacatac.DC!ml not completely remediated on Windows PC-capture_08292020_021004.jpg  
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 22:12.
Find Us




Windows 10 Forums