F5F Stay Refreshed Software Operating Systems Windows Defender detecting suspicious activity from a Trojan on Windows 11

Windows Defender detecting suspicious activity from a Trojan on Windows 11

Windows Defender detecting suspicious activity from a Trojan on Windows 11

Pages (2): 1 2 Next
P
PikachuPro952
Junior Member
15
03-04-2021, 03:11 PM
#1
Hello everyone. I’m dealing with a strange problem. I’ve been trying to track down a Trojan that keeps reappearing, but it doesn’t show up in standard scans or Windows Defender checks. It shows up intermittently, sometimes appearing and disappearing at random times. Every time I remove it, it seems to vanish for a while before reappearing later. This issue is happening on both my Windows 11 laptop and desktop. Both systems are set up similarly, as I run a small audio and video project studio, and the problem affects both of them. The threat appears as a Trojan, and Defender labels it as Trojan:JS/KryptoStealer.GA!MSR. It always ends up in the same hidden folder, though the file name changes each time. The latest version was found just recently, with a name like C:\Users\myusername\AppData\Local\Microsoft\Windows\INetCache\IE\6XDAO3K1\U5O2133D.htm. Other versions also show up, but the preceding file name varies. The only advice I’ve gotten was to reset and reinstall Windows, which is risky since I have important software with licenses. I’m unsure what steps to take and need guidance on how to permanently remove it. I tried a Malware bytes scan before and after removal, but nothing came up. If I run a full Windows Defender scan afterward, nothing appears. It seems to reappear at random intervals. Any suggestions would be appreciated. Thanks ahead for your help.
P
PikachuPro952
03-04-2021, 03:11 PM #1

Hello everyone. I’m dealing with a strange problem. I’ve been trying to track down a Trojan that keeps reappearing, but it doesn’t show up in standard scans or Windows Defender checks. It shows up intermittently, sometimes appearing and disappearing at random times. Every time I remove it, it seems to vanish for a while before reappearing later. This issue is happening on both my Windows 11 laptop and desktop. Both systems are set up similarly, as I run a small audio and video project studio, and the problem affects both of them. The threat appears as a Trojan, and Defender labels it as Trojan:JS/KryptoStealer.GA!MSR. It always ends up in the same hidden folder, though the file name changes each time. The latest version was found just recently, with a name like C:\Users\myusername\AppData\Local\Microsoft\Windows\INetCache\IE\6XDAO3K1\U5O2133D.htm. Other versions also show up, but the preceding file name varies. The only advice I’ve gotten was to reset and reinstall Windows, which is risky since I have important software with licenses. I’m unsure what steps to take and need guidance on how to permanently remove it. I tried a Malware bytes scan before and after removal, but nothing came up. If I run a full Windows Defender scan afterward, nothing appears. It seems to reappear at random intervals. Any suggestions would be appreciated. Thanks ahead for your help.

D
DJKiller22
Member
138
03-04-2021, 05:12 PM
#2
Consider using a web-based scan such as Trend Micro's House Call to compare outcomes. The directory might be cached in Internet Explorer, so clearing its temporary files could help.
D
DJKiller22
03-04-2021, 05:12 PM #2

Consider using a web-based scan such as Trend Micro's House Call to compare outcomes. The directory might be cached in Internet Explorer, so clearing its temporary files could help.

F
filcio1234
Member
211
03-05-2021, 09:11 AM
#3
The Bitdefender free version should work well enough. Edge is now almost identical to Chrome, so unless it lacks support for Firefox or Chrome, I wouldn’t recommend it. Microsoft once dominated browser development, but that’s a long time ago.
F
filcio1234
03-05-2021, 09:11 AM #3

The Bitdefender free version should work well enough. Edge is now almost identical to Chrome, so unless it lacks support for Firefox or Chrome, I wouldn’t recommend it. Microsoft once dominated browser development, but that’s a long time ago.

H
Hermi_123
Member
204
03-12-2021, 05:38 PM
#4
It seems to be connected to an internet browser. More research shows people often reset their default browsers and try again. The issue first appeared after using Edge briefly. Although I don’t use Edge much, I do a few times daily. I reset all three browsers to see if it helps. It’s unclear if this resolves the problem. This has been happening less frequently lately, but I’m trying to understand its cause. I haven’t encountered malware or viruses before since I avoid risky activities. I’m looking into where this problem might be coming from. No relevant search results came up for this exact issue.
H
Hermi_123
03-12-2021, 05:38 PM #4

It seems to be connected to an internet browser. More research shows people often reset their default browsers and try again. The issue first appeared after using Edge briefly. Although I don’t use Edge much, I do a few times daily. I reset all three browsers to see if it helps. It’s unclear if this resolves the problem. This has been happening less frequently lately, but I’m trying to understand its cause. I haven’t encountered malware or viruses before since I avoid risky activities. I’m looking into where this problem might be coming from. No relevant search results came up for this exact issue.

D
DinglyDongg
Member
174
03-18-2021, 10:43 PM
#5
I once used Bitdefender free, but later they removed the free version I believed it was.
D
DinglyDongg
03-18-2021, 10:43 PM #5

I once used Bitdefender free, but later they removed the free version I believed it was.

H
HumbleHawk
Junior Member
31
03-19-2021, 08:19 AM
#6
Nope, although honestly, retailers have been running like 24hr fire sales for bitdefender subscriptions, I recently got mine from staples 6-devices 1yr for $21 tax included If you are US based: https://www.bestbuy.com/site/bitdefender...lsrc=aw.ds
H
HumbleHawk
03-19-2021, 08:19 AM #6

Nope, although honestly, retailers have been running like 24hr fire sales for bitdefender subscriptions, I recently got mine from staples 6-devices 1yr for $21 tax included If you are US based: https://www.bestbuy.com/site/bitdefender...lsrc=aw.ds

S
Soccerdude0
Member
106
03-19-2021, 09:06 AM
#7
S
Soccerdude0
03-19-2021, 09:06 AM #7

N
NoahWraith
Member
199
03-19-2021, 03:38 PM
#8
Have you used ADWCleaner? It usually removes browser-specific threats more effectively than antivirus software, such as redirecters, persistent URLs, and pop-ups. Worth a look if you're still facing problems—it's free.
N
NoahWraith
03-19-2021, 03:38 PM #8

Have you used ADWCleaner? It usually removes browser-specific threats more effectively than antivirus software, such as redirecters, persistent URLs, and pop-ups. Worth a look if you're still facing problems—it's free.

K
Klod_n_Load
Junior Member
19
03-19-2021, 09:17 PM
#9
Great. I’ve restored the free version and signed in with my old account. I’m based in the US and I’ll definitely take a look at the offers. The free option seems sufficient for now, but after this mess I might switch to a paid plan for a while. That’s what happened to me too—I mentioned it last time. They suggested clearing everything and reinstalling Windows, which I’ve done before when a persistent problem kept coming up. But since I often use license keys for my production tasks and it’s super frustrating to manage all those accounts, I’m considering giving this a try. Thanks a lot for the advice!
K
Klod_n_Load
03-19-2021, 09:17 PM #9

Great. I’ve restored the free version and signed in with my old account. I’m based in the US and I’ll definitely take a look at the offers. The free option seems sufficient for now, but after this mess I might switch to a paid plan for a while. That’s what happened to me too—I mentioned it last time. They suggested clearing everything and reinstalling Windows, which I’ve done before when a persistent problem kept coming up. But since I often use license keys for my production tasks and it’s super frustrating to manage all those accounts, I’m considering giving this a try. Thanks a lot for the advice!

N
Niall001
Member
170
03-20-2021, 10:20 PM
#10
I don't have a solution to share, but I can confirm whether one was identified.
N
Niall001
03-20-2021, 10:20 PM #10

I don't have a solution to share, but I can confirm whether one was identified.

Pages (2): 1 2 Next