Trojan Detected in OneDrive

Page 1 of 2 12 LastLast

  1. Posts : 605
    Windows 10
       #1

    Trojan Detected in OneDrive


    The odd thing is I don't even use OneDrive except to automatically upload photos from my Android phone to my desktop; nothing has been detected on the phone.
    I've run another full scan with Bitdefender and Malwarebytes Anti-Malware (free) without any further detection.
    Was just wondering if there might be other steps I need to carryout to be sure nothing spreads? Thanks!

    Trojan Detected in OneDrive-capture.jpg
      My Computer


  2. Posts : 558
    Windows 10
       #2

    I don't use OneDrive but i am very familiar with the Heur Trojan , it's a complete nightmare and one of the worst i ever experienced .

    If it was me i would wipe and re install but i never keep anything of importance on my computer so thats easy for me to say .

    I had to use Dban to get rid of that thing completely .
      My Computer


  3. Posts : 22,740
    Windows 10 Home x64
       #3

    I wouldn't be surprised if there are many more Trojan files on One-Drive.
      My Computer


  4. Posts : 552
    Microsoft Windows 10 Home 64-bit
       #4

    I have been checking out different AV's recently, and whilst I liked the look of bitdefender, according to the forum site the free version is not compatible with windows 10, even though it can be installed it is not reliable, could be the reason you got the virus, or maybe bitdefender is giving false info.

    Might be worth checking with another AV first. Hope this helps.

    Bitdefender Antivirus Free Edition Windows 10 - Bitdefender Forum
      My Computer


  5. Posts : 605
    Windows 10
    Thread Starter
       #5

    thegeriatric said:
    I have been checking out different AV's recently, and whilst I liked the look of bitdefender, according to the forum site the free version is not compatible with windows 10, even though it can be installed it is not reliable, could be the reason you got the virus, or maybe bitdefender is giving false info.

    Might be worth checking with another AV first. Hope this helps.

    Bitdefender Antivirus Free Edition Windows 10 - Bitdefender Forum
    Thank you, I've uninstalled Bitdefender and reinstalled Avast (donno why I left it in the first place), as well as followed the complete instructions at the following link, without further detection (besides tracking cookies, which were removed).

    Remove HEUR.Trojan.Win32.Generic (Virus Removal Guide)

    I've also disabled OneDrive on the PC (OneDrive Integration - Enable or Disable in Windows 10 - Windows 10 Forums) and uninstalled it on the phone.

    Do you think it's safe to say, I'm safe now?
      My Computer


  6. Posts : 558
    Windows 10
       #6

    I never assume i am completely clean when i have dealt with the Heur Trojan because i made that mistake before , was convinced it was gone and a day or two later the nightmare repeated.

    That link you posted said it is one that often does install a "backdoor" so your just going to have to keep an eye on your system . It is one of the most resistant Trojans i have ever dealt with.

    The Free Kaspersky one time scan ALWAYS picks up the Heur Trojan so consider running that one time scan , if that says clean i think your clean because it never misses that Trojan if it's on your system hiding.

    Emsisoft and Eset Online Scanner do a great job picking up stuff that others often miss as well .
      My Computer


  7. Posts : 16,325
    W10Prox64
       #7

    fracking4oil said:
    The odd thing is I don't even use OneDrive except to automatically upload photos from my Android phone to my desktop; nothing has been detected on the phone.
    I've run another full scan with Bitdefender and Malwarebytes Anti-Malware (free) without any further detection.
    Was just wondering if there might be other steps I need to carryout to be sure nothing spreads? Thanks!

    Trojan Detected in OneDrive-capture.jpg
    Can I just make an observation here?

    From your pic, it appears that the executable OneDrive.exe has been flagged as a virus. This sounds like a FP (false positive) to me.

    I would suggest you upload that file to VirusTotal website and see what comes up there.

    I have the same file on my system in the same location and it's 536KB. I do not use OneDrive on this particular machine.

    I do not think you are infected with anything. Did TDSSKiller find anything on that file?
      My Computer


  8. Posts : 39,919
    Win 7 32, Win 7 64 Pro, Win 8.1 64 Pro, Win 10 64 Education Edition, Win 11 Pro
       #8

    You could give Norton Power Eraser a shot. You can find it here. It would be advisable to read the tutorial.

    Norton Power Eraser | Free Tool | Easily remove scamware that traditional virus scanning can’t detect.


    Because Norton Power Eraser uses aggressive methods to detect threats, there is a risk that it can select some legitimate programs for removal. If you accidently remove a legitimate program, you can run Norton Power Eraser to review past repair sessions and undo them.


    For more information about using Norton Power Eraser, click here for a tutorial.
      My Computer


  9. Posts : 605
    Windows 10
    Thread Starter
       #9

    simrick said:
    Can I just make an observation here?

    From your pic, it appears that the executable OneDrive.exe has been flagged as a virus. This sounds like a FP (false positive) to me.

    I would suggest you upload that file to VirusTotal website and see what comes up there.

    I have the same file on my system in the same location and it's 536KB. I do not use OneDrive on this particular machine.

    I do not think you are infected with anything. Did TDSSKiller find anything on that file?

    I suspect you may be correct about it being a false positive (or something to do with Bitdefender). Besides Bitdefender alerting to it, I've seen no signs of infection.
    If signs of infection do occur I'll investigate it further, until than I think I'm ok. Thanks all for the help. Peace!
      My Computer


  10. Posts : 16,325
    W10Prox64
       #10

    Sounds good.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 09:52.
Find Us




Windows 10 Forums