Endpoint Protection

 View Only
Expand all | Collapse all

Virus detected but not cleaned

ℬrίαη

ℬrίαηMay 25, 2017 10:20 AM

Migration User

Migration UserMay 26, 2017 08:19 AM

ℬrίαη

ℬrίαηJun 01, 2017 04:07 PM

  • 1.  Virus detected but not cleaned

    Posted May 25, 2017 09:51 AM

    Thw W64.Viknok.B!.inf virus was detected by the Endpoint but cannot be cleaned. I used the SymDiag and Norton Power Eraser tools with no success. Is there a manual method to follow to delete the virus or some other tool I can use.

    Thanks....Bob



  • 2.  RE: Virus detected but not cleaned

    Posted May 25, 2017 09:54 AM

    Have you tried manually deleting? In safe mode?



  • 3.  RE: Virus detected but not cleaned

    Posted May 25, 2017 10:20 AM

    Thanks, let me now how it goes.



  • 4.  RE: Virus detected but not cleaned

    Posted May 25, 2017 10:20 AM

    I have not but will try on endusers computer this afternoon.

    Thanks...Bob



  • 5.  RE: Virus detected but not cleaned

    Posted May 25, 2017 10:45 AM

    I had a similar issue once where the infected file kept reappearing. symantec suggested to restart the PC so the infection gets flushed out of the memory. so I would suggest you the same. if you are facing a similar issue.



  • 6.  RE: Virus detected but not cleaned

    Posted May 25, 2017 11:42 AM

    Hi Bob,

    W64.Viknok.B!inf is a detection for 64-bit files infected by Trojan.Viknok. Here's a little more on that one:

    Sophisticated Viknok Malware Proves That Click-fraud Is Still a Moneymaker for Scammers
    https://www.symantec.com/connect/blogs/sophisticated-viknok-malware-proves-click-fraud-still-moneymaker-scammers

    What action is SEP taking-? And where are these files located-?  With AutoProtect or manual scans?  It might help if you posted an excerpt from the Risk Report.

     

     



  • 7.  RE: Virus detected but not cleaned

    Posted May 25, 2017 12:30 PM

    SEP states "no repair currently available" - so its just logged - AutoProtect found it - file name - eoxcy.dll - I also ran a full manual scan and infected file is - hrngeej.dll - same SEP msg "no repair currently available"  I can't get the Risk Report at the moment but I will post later when I visit the end user

     

    Thanks....Bob



  • 8.  RE: Virus detected but not cleaned

    Posted May 25, 2017 02:36 PM

    Thanks Mick2009 , was trying to find any article that explained exactly what Viknok Malware does. 



  • 9.  RE: Virus detected but not cleaned

    Posted May 26, 2017 08:09 AM
      |   view attached

    I tried Malwarbytes - found nothing doing a full scan last night. I will check the link provided. Attached, please find the XLS risk report from SEP.

    Thanks, 

    Bob 

    Attachment(s)

    zip
    RiskRpt.zip   490 B 1 version


  • 10.  RE: Virus detected but not cleaned

    Posted May 26, 2017 08:19 AM
      |   view attached

    Here' the risk Report. 

    Attachment(s)

    zip
    RiskRpt_0.zip   490 B 1 version


  • 11.  RE: Virus detected but not cleaned

    Posted May 26, 2017 08:22 AM

    According to the report:

    The non-repairable infections are related to copies of legitimate infected dlls, which can be safely deleted without affecting the computer. 

    Have you tried deleting the DLL named 'hrngeej.dll' ? 



  • 12.  RE: Virus detected but not cleaned

    Posted May 26, 2017 08:25 AM

    I ran the PC in safe mode but SEP was unable to delete the virus.

    Thanks, 

    Bob 



  • 13.  RE: Virus detected but not cleaned

    Posted May 26, 2017 08:29 AM

    According to the report:

    The non-repairable infections are related to copies of legitimate infected dlls, which can be safely deleted without affecting the computer. 

    Have you tried manually deleting the DLL named 'hrngeej.dll' ? 

    If what the report says is true, I don't expect SEP to delete it. It will need to be removed manually.



  • 14.  RE: Virus detected but not cleaned

    Posted May 26, 2017 09:17 AM

    Many thanks Bob!

    Have you tied manually deleting this "c:\users\mazura\appdata\roaming\hrngeej.dll" -?  Even if SEP's engines cannot automatically access and act upon that file, it's good that the product is raising a red flag.



  • 15.  RE: Virus detected but not cleaned

    Posted May 26, 2017 09:27 AM


    Explanation of Action field values in Symantec Endpoint Protection 12.1 and 14
    http://www.symantec.com/docs/TECH102052
     



  • 16.  RE: Virus detected but not cleaned

    Posted May 31, 2017 10:28 AM

    I deleted the file including the entire user path and then ran a scan - the virus was not detected but an odd behavior is occurring. I logged out of the PC and logged back in and the user path I deleted was recreated. I ran a quick scan only on the user directory and it was clean but this evening I will run a full SEP scan. 

    .....Bob 



  • 17.  RE: Virus detected but not cleaned

    Posted May 31, 2017 11:35 AM

    I deleted the file including the entire user path and then ran a scan - the virus was not detected but an odd behavior is occurring. I logged out of the PC and logged back in and the user path I deleted was recreated. I ran a quick scan only on the user directory and it was clean but this evening I will run a full SEP scan. 

    .....Bob 



  • 18.  RE: Virus detected but not cleaned

    Posted May 31, 2017 11:41 AM

    Thanks for the update.  It sounds like there is something in the load points which re-created that file you deleted. 

    You may wish to open a case with Tech Support for their help in hunting that down, if the full system scan does not find anything.



  • 19.  RE: Virus detected but not cleaned

    Posted Jun 01, 2017 04:06 PM

    I deleted the entire user directory again and ran Symdiag full scan - virus is gone and user dir was not recreated on logon following a reboot. 

    Thanks....Bob 

     



  • 20.  RE: Virus detected but not cleaned

    Posted Jun 01, 2017 04:07 PM

    Thanks for the update.

    -Brian