Application (.exe) icon changed after fall creator update

Page 2 of 2 FirstFirst 12

  1. Posts : 5,478
    2004
       #11

    moeismu said:
    all of them have original filename TJprojMain.exe.
    That certainly suggests a problem.

    I don't know anything about removing virus but perhaps someone else will suggest something.

    Try running defender scan or Malwarebytes scan in the mean time.
      My Computer


  2. Posts : 31,651
    10 Home x64 (22H2) (10 Pro on 2nd pc)
       #12

    moeismu said:
    hmm, i just checked i think my computer is infected by worm. i checked all those app, and all of them have original filename TJprojMain.exe.
    Bree said:
    Has any one else spotted that the icon resembles a red Defender shield? It could be a clue. Do you have any third-party AV installed?
    moeismu said:
    i dont have any :)
    but i wonder where is it came from.
    As you think you may have a worm, the red shield may actually be a warning from Defender itself. Though I can't find any documentation to confirm this. Your first step should be to try and clean out this worm.
      My Computers


  3. Posts : 12
    Windows 10 Pro
    Thread Starter
       #13

    im scanning using avast right now, and and it's true, they all infected by win32:vb-ojq which by avast detected as worm. thank you for all of you for tried answering my thread.
      My Computer


  4. Posts : 42,983
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #14

    Sounds like a plan..
      My Computers


  5. Posts : 5,478
    2004
       #15

    You could see if @simrick has any suggestions. She knows the best way to get rid of virus stuff which this certainly sounds like.

    I'm sure others do too of course (so as not to tread on toes) but it isn't my métier I'm afraid.
      My Computer


  6. Posts : 16,325
    W10Prox64
       #16

    Hi.
    Just looking up information on this one.
    https://virustotal.com/en/file/f4a80...is/1487901266/

    Looking at the Microsoft description, it appears that this infection is not only a worm, but it is also a backdoor, and information stealer:
    PWS:Win32/VB.CU threat description - Windows Defender Security Intelligence

    So, any other systems that are connected to your network need to be cleaned as well, and all passwords need to be changed from a known-clean system. Also, any flash drives/USB-connected drives should be considered suspect and cleaned. It would be prudent to install Panda USB vaccine.
    Download Panda USB and AutoRun Vaccine - MajorGeeks

    Avast should get the bulk of it out. You may want to run ADWCleaner as well.
    Downloads - AdwCleaner - ToolsLib

    Personally, I would restore a clean image (if you have one). Worms are a bear, and effect your computer's networking.
      My Computer


  7. Posts : 16,325
    W10Prox64
       #17

    After looking at this more, if you don't have a Macrium image to restore, I think a clean install is in order.

    Payload

    Disables network services
    PWS:Win32/VB.CU disables the SharedAccess service which is responsible for the systems network connection activity.

    Steals sensitive information
    This password stealer logs clicks, keystrokes and window titles. It also collects the following information:


    • email configuration (user name, password, email recipients, SMTP server, server port, authentication status, whether it is using SSL)
    • instant messenger credentials
    • downloaded files
    • websites visited
    • search keywords
    • operating system
    • Internet browser and version
    • software installed in the system
    • clipboard contents
    • desktop captures
    • network shared resources connected to the computer

    Overwrites files
    PWS:Win32/VB.CU overwrites executable files found in the same folder in which it was initially executed.

    Additional information

    PWS:Win32/VB.CU enables and starts the Schedule service to make sure the created scheduled job executes its dropped copy every day. To prevent its detection in the affected computer, it terminates its own processes.
      My Computer


  8. Posts : 12
    Windows 10 Pro
    Thread Starter
       #18

    I think if i did a clean installation now isn't a right time, because i have several project to finished by december. And I already finished scanning, and exe files with shield logo is removed. I dont know if the worms are still there, but i just make sure by checking the process that running in the task manager one by one.

    Thanks once again for replying my thread, for now i just mark this thread as solved.
      My Computer


  9. Posts : 42,983
    Win 10 Pro (22H2) (2nd PC is 22H2)
       #19

    You might like to investigate a program such as Secureaplus
    Free Cloud Antivirus Application Control for PC | SecureAPlus

    - It can exist alongside Avast (as I have it); it's a white-listing program, so anything that runs has to be authorised. Initially you can approve everything if you think your PC is clean, and after that it's reasonably unobtrusive.

    In addition you get multi-engine on-line scanning support, with the option of real-time protection.

    They run giveaways sometimes of 18 month or so licenses- there was another recently.

    Also as we constantly advise, protect your PC (especially as you're doing a time-critical project) by using disk imaging routinely so you can be back up and running quite quickly without technical help even if your PC becomes unbootable or your disk fails, or you suffer a severe virus. E.g. Macrium Reflect (free) + external disk to store disk image sets.
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:33.
Find Us




Windows 10 Forums