Threat found - action needed (Spam)

Anonymous
2024-07-18T18:11:32+00:00

It's been a couple of days now facing this issue.
(Trojan:BAT/PSRunner.VS!MSR)

Started with getting this threat detection (actions needed in the task bar)

when I get into it it says quarantined.

I can't share the screen shots for some reason.. Here's a link for them: https://drive.google.com/drive/folders/1KzyQH5HNSkcVW-dw8Rn5lTe0XgPCPEzS?usp=drive_link It keeps on going spamming in the protection history every 30 to 60 seconds

When I leave it and keep on doing something else I get a freeze for a couple of milliseconds but this time windows couldn't quarantine it and gave me action needed: Block threat & allow on device.

If I didn't press take action it goes away and gets back again in a few minutes.

I'm really tired of this and hope someone could help!

Windows for home | Windows 11 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Ramesh 181.9K Reputation points Volunteer Moderator
2024-07-19T11:56:59+00:00

Your system is still infected by a miner.

Please run the Farbar Scanner and share your logs.

  1. Download Farbar Recovery Scan Tool (FRST64.exe)

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Note: If Microsoft Edge or Chrome mislabels the Farbar Scanner executable as PUA/malware, choose to keep it by tapping … in the bottom bar, choosing Keep, and then choosing Keep anyway in the dialog that appears.

  1. If the OS language is non-English, rename FRST64.exe to FRST64English.exe.
  2. Run the program. Don't check or uncheck any options. Click "Scan".
  3. Upload the two logs, FRST.txt and Addition.txt, to your OneDrive and share the link here.

How-To: Share OneDrive files and folders - Microsoft Support

https://support.microsoft.com/en-us/office/share-onedrive-files-and-folders-9fcc2f7d-de0c-4cec-93b0-a82024800c07

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments
Answer accepted by question author
Ferdinand Nanalig 32,975 Reputation points Independent Advisor
2024-07-18T18:43:20+00:00

Hi, I am an Independent Advisor.

Let me help you with this issue.

I understand your computer is infected with Trojan:BAT/PSRunner.VS!MSR.

Have you tried running a different scanner?

Please follow the steps below on how to scan your machine further.

Please also try Microsoft Safety Scanner - https://learn.microsoft.com/en-us/microsoft-365...

And follow these additional steps.

Uninstall an unwanted application in Programs and features,

Go to start type in Control Panel, then go to Programs and then Programs and Features then go to the list of the programs look for anything unusual or any application that you are not aware right click then uninstall.

Delete Temporary files off Windows 10.

Tap the Windows Key then R on your keyboard, on the Run box type in %temp% then press enter.

Once it is up highlight all then delete, if there is a filé open that can't be deleted just skip it.

I hope this helps.

If the above scanner did not detect any please use these 3rd party tools.

Let's try downloading the free version of Malwarebytes, it is a freeware that you can use to scan, detect, and delete viruses like the one you currently have.

You can download the free version from this link

https://www.malwarebytes.com/

Once installed please make a full scan. You may remove this software once you are done with it.

You can also try an online malware scanner - https://www.eset.com/int/home/online-scanner/

URL Disclaimer please read.

Note: This is a non-Microsoft website. The page appears to be providing accurate, safe information. Watch out for ads on the site that may advertise products frequently classified as PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the site before you decide to download and install it.

Was this answer helpful?

1 person found this answer helpful.
0 comments No comments

48 additional answers

Sort by: Oldest
  1. Anonymous
    2024-07-19T09:04:45+00:00

    I tried Microsoft Safety Scanner and here's the result...

    Results Summary:


    No infection found.

    Successfully Submitted MAPS Report

    Successfully Submitted Heartbeat Report

    Microsoft Safety Scanner Finished On Fri Jul 19 01:02:32 2024

    And everything is still the same.

    There's no strange application installed

     Malwarebytes Results:

    -Scan Summary-

    Scan Type: Threat Scan

    Scan Initiated By: Manual

    Result: Completed

    Objects Scanned: 269321

    Threats Detected: 6

    Threats Quarantined: 0

    Time Elapsed: 1 min, 27 sec

    After quarantine, this keeps popping up every 30 seconds or so..

    Online malware scanner:

    7/19/2024 3:48:25 AM

    Scanned files: 689380

    Detected files: 4

    Cleaned files: 5

    Total scan time 00:47:03

    Scan status: Finished

    After all this was done I turned off Malwarebytes as it was taking over Windows Defender's job and did a custom scan on the C partition (Containing the software)

    So I did a full scan after to make sure everything was ok...

    So far I haven't faced anything yet. Still testing tho.

    I just want to know what's (xboxwindows.com) domain and IP that showed up in Malwarebytes?

    Thank you in advance for your help.

    Was this answer helpful?

    0 comments No comments
  2. Ferdinand Nanalig 32,975 Reputation points Independent Advisor
    2024-07-19T10:44:36+00:00

    Do not go to that website (xboxwindows), my McAfee WebSecurity Advisor detected it as a malicious website and if you go directly to it, it downloads a file. So do not go to that site, do not attempt as well.

    Since you are not getting any more threats on your scan, your machine is now safe from any threats.

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2024-07-19T11:51:54+00:00

    Do not go to that website (xboxwindows), my McAfee WebSecurity Advisor detected it as a malicious website and if you go directly to it, it downloads a file. So do not go to that site, do not attempt as well.

    Since you are not getting any more threats on your scan, your machine is now safe from any threats.
    Image

    Yeah I noticed when I looked it up on (Whois) Website.

    Thanks for your help man, I really appreciate it.

    Was this answer helpful?

    0 comments No comments