Trojan.Downloader Detected

Hi There

Asked in another forum, which they recommended to use Defender after upcoming clean install, Defender so far has quarantined the file which is TrojanDownload.JS/Nemucod.HC

I can’t do Clean install today, stuff to do, you know, anyways is it safe to use Avast if I choose to after Windows 10 Pro clean install? Use Ms Edge and IE for browsing, how I got it, I’m not really sure, probably from a site I would guess, or email possibly

I can provide logs from all the scans I ran if need be, I just wanna feel comfortable the machine is totally clean, and doesn’t spread to entire network of systems. So in morning doing clean install

https://forum.avast.com/index.php?topic=53253.0

Oops wrong area sorry there…

Clean install of what? … wipe the computer and resinstall?

Yeah thinking doing that, Another forum suggested after clean install done, to stick with Windows 10 Defender, I forgot I had Avast installed yesterday, should’ve asked here in the first place, (last week or two was switching between Defender/Avast trying to decide which protection program to stay with, and may have gotten the infection then possibly, not sure)

Moral of the story is I guess I have to be more careful, stay with 1 Antivirus program.

If you are going to reinstall then why all this?

a .dat file can be detected as malicious, but it doesn’t run without something else.
I suggest you provide the log files and let us have a look at them.
A good check will not hurt :wink:

As far as Defender or avast…
Defender has (to put it simple) just a database that is used to scan files.
avast has a lot more other protection methods than just a database (VPS).

Will do, Keep in mind original detection quarantined in Defender still, so maybe that is why other programs found nothing

Hi Patrick :slight_smile:

As far as providing log files, Eddy is meaning the log files from the sticky as well :

https://forum.avast.com/index.php?topic=53253.0

Greetz, Red.

Sure can do that, one moment here

Note Getting Rest of the logs might be a bit, checking External drives as well, maybe not such a good idea lol, 500gb times x 2, usb 2.0 speeds, rest of logs posted soon as possible though

Checking externals will make sure files are fully clean anyways before full clean system install early tomorrow anyhow, last night I only checked Internal C Drive

To add to what Rednose mentioned, the main log needed was FRST.txt and Addition.txt.

Well I can provide those logs, but those showed clean when I ran those, wasn’t sure if previous Antivirus removed the Threat fully, so went ahead with Clean PC install anyways, despite all the other scans and programs showed clean, can re run those scans, to make sure still clean though after data restored and such

Well I can provide those logs, but those showed clean when I ran those
Do you know how to read those logs?

FRST is a diagnostic program and will not show any detection

Ohhh didn’t know that, well that programs logs are posted now, will get rest posted in a few moments here, or after lunch…got a lot to learn still I guess on various programs, and such it appears, Still wonders if I hadn’t switch to Defender if Avast would’ve seen the original threat, which I paniced on a bit, and ended up rushing thru Windows 10 Clean install, changed all account passwords even.

Little back story on this situation

Had some folks in another forum telling me to stick with Windows Defender, Malwarebytes, and Malwarebyes Anti Exploit, Well then I felt a little unsafe after Defender blocked a Severe Threat–Trojan Downloader, (exact name I can get easily), then reinstalled Avast remotely via Remote desktop from my phone that late night, didn’t feel safe after that even, so decided to do a complete clean install, and so far so good

Ah, cheers. As Pondus mentioned these are custom logs. Most people can’t read them.

@Pondus, have you PM’d dbrise?

@Patrick2, is this a commercial PC? The reason I ask is because you’re running Windows 10 Pro, and you have a commercial version of Windows Defender. “Windows Defender Advanced Threat Protection”

More on that here: https://www.microsoft.com/en-us/WindowsForBusiness/Windows-ATP

Also, can you find this file: C:\Users\amdma\AppData\Local\Temp\sonarinst.exe

Scan it at www.virustotal.com and post results back here.

Someone else will take care of you, dbrisendine I’m sure.

Not Commerical PC, Brought Pro since my original HP system that I gave to Mom, had Windows 10 Pro (Free) upgrade from 8.1 Media Center…So decided to get the same version for this system when I bought it in January 2016 from Newegg, freely upgraded to Windows 10 Home First, then later on bought Pro version

Results of virustotal scan

https://www.virustotal.com/en/file/5424c12fdf736034b39cf6aa843236b428d9e6707876dbd9e33c99db8ac76d3c/analysis/

Based on System Performance since system clean install, it feels the Trojan Downloader original infection is gone at this point, but i’ll feel much safer once I hear back nothing else in the logs that are concerning…I use Remote Desktop at times to do system maintenance, Home edition didn’t include that, so why I bought Pro Edition of Windows 10. Didn’t restore files from backup either, redownloaded all drivers, games, and such, did disable built in wifi, since thought would interfere with Ethernet

No worries about Windows 10 Pro. Just isn’t quite normal to see. Generally we don’t work on Corporate computers.

I’ll send a message to dbrisendine just to make sure he knows about this thread and your logs have been posted.

Can you re-upload that file and click “New Analysis” that scan is 4 weeks old.

sure can do that

https://www.virustotal.com/en/file/5424c12fdf736034b39cf6aa843236b428d9e6707876dbd9e33c99db8ac76d3c/analysis/1474935304/

Re Checked, results there

Ah, I see what it is now. BattleField 4 file.

https://battlelog.battlefield.com/bf3/forum/threadview/2955065670154489854/

Signers
[+] Electronic Sports Network i Sverige AB

Yeah what I thought it was connected to myself, but wasn’t positive

Hopefully all the other files are safe, and yay!, Not sure how I even got ahold of The Trojan Downloader, not sure if panicing was right way to handle it, I have learned switching Antivirus programs too much isn’t a good idea either, last month I was switching between Avast Free, and Defender, maybe I got the infection then