Help with malware/trojan

Can you recommend good online sources for help/forums with malware/viruses? There was a trojan found on one of my friends computer, he does not know if it might be a false positive.

Thank you!

1 Like

Do you know exactly which file is responsible? If so you can upload it to VirusTotal .

Quarantine the device first. Disconnect everything else from the network. Don’t input any personal information. If the Trojan is intirgrated into the system it requires a different approach

1 Like

I just asked him, the file is already deleted by the AV scanner but it was “Trojan.SupectCRC” in /WinSxS/…/WindowsPersonaCard.dll”.

1 Like

upload the file to virustotal.com, then I could help determine if it’s a false positiv.

I mean if you share the url result.

1 Like
  1. Shutdown the infected device
  2. Whipe all disks (reformat should be enough)
  3. Install a new OS
  4. Check other devices for malware
  5. Logout/reset the sessions of all accounts
  6. Change the password of all accounts
  7. Enable MFA of all accounts

Be aware that restoring a backup might be risky due the fact that you currently have no information when the device was infected. So a backup might already contain the malware.

1 Like

The AV scanner already deleted the file, so he cannot upload it.

The computer has also been fully cleaned with new installment but as @Onscreen5341 mentioned the backups might be infected, too. My friend had been using Notepad++, and the infection of the updater had been going on since June 25 - but again, it might have been a false positive.

1 Like

Notepad++ is definitely not a false positive.
Hopefully there is no rootkit coming with it.

1 Like

Well yes, of course Notepad++ has been attacked and that is not a false positive, but the odd thing is he had fully cleaned the computer BEFORE the AV scan and then did not connect to the internet again, only attached and external drive with some of his documents. And then the AV scan was performed.

1 Like

I’ve slowly rendered down the data I feel is worth preserving down into only text & photo data. Much easier to store offsite in dedicated storage formats.

BleepingComputer and MalwareBytes forums have malware removal help sections. You need to run elevated scanners and post logs on the public forums. BC asks you to run fewer logs and may remove fewer suspicious files from the computer, whereas MB asks you to run MB tools along with other tools, and remove suspicious files more comprehensively.