Share via

Trojan:Script/Oneeva.a!ml is removed from quarantine every day at 3:17am

Anonymous
2021-04-09T14:33:40+00:00

Since April 4th Microsoft Defender reports that Oneeva is being removed or restored from Quarantine, multiple times per day as well as 3:17am.

I have run a complete scan, twice, and it finds nothing.   I have even done Defender Offline, nothing.

Who or what is doing this?

Eventually, 5 copies of PowerShell are running consuming all my CPU time.  I can't find what's doing that.  A reboot clears that conditions for a few days.

I suspect I am under the control of a BOT.

I am up to date as far Windows Update goes.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

5 answers

Sort by: Most helpful
  1. Anonymous
    2021-04-12T14:56:09+00:00

    Safety scan reported "No Virus" found at the end, but during the scan it report 580 files infected.

    MalwareBytes reported "No Virus" found at the end, but it too reported infected files while the scan was running.

    I poked around and found a bunch of weirdly named files in my Local and Roaming directories.  I moved them off to the side, compressed them and then deleted them.  They look very suspect as to the PowerShell issue.  I can send them to you, if you'd like, they are in a 7z archive. 

    I have not logged back into my account, since finding these files, as I have other accounts that I can use.

    I tried BitDefender.  And it reports these files as suspect with Heur.BZC.ONG.Pantera.35.3F9DD540 as  its threat name.

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-04-10T00:29:08+00:00

    Hi Russ,

    Assuming that the PowerShell problem may be unrelated to the Trojan, please consider this.

    Both Microsoft Defender and the Microsoft Safety Scanner should be capable of removing

    this Trojan. And they both use the same Intelligence definitions.

    If you find that the Safety Scanner does not detect this Trojan, but Defender still does, then

    Defender is probably showing a False Positive.

    Defender has a tendency to "Detect" notifications in its Protection History, and reports them

    as current threats, when they are not.  You can avoid the repeating alerts by deleting the

    "Detection History" folder from Defender's Protection History.

    It is a safe procedure.  Windows rebuilds the folder when it needs it again.

    The following link provides instructions for deleting the Detection History folder.

    https://answers.microsoft.com/en-us/protect/forum/all/windows-defender-identifies-the-same-pup-as-a/63f17794-3815-4784-b9cd-c6059c8e0828

    If you are able to eliminate the Defender alerts, then you can attack the PowerShell problem.

    Good luck,  Glen

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-04-10T10:52:43+00:00

    Hi RussMonckton,

    If that's the case, have you also tried to run the scan using Malwarebytes? Were you also able to perform the repair install?

    Hoping for your feedback. Thank you.

    0 comments No comments
  4. Anonymous
    2021-04-09T21:15:48+00:00

    I have started the safety scan, it will take days to compete

    0 comments No comments
  5. Anonymous
    2021-04-09T15:49:30+00:00

    Good day! I'm Raniel, an Independent Advisor and a Microsoft user like you.

    Kindly install the Microsoft Safety Scanner and Malwarebytes Free, then perform a scan to ensure that your machine is free from virus. Here are the links to download them:

    Microsoft Safety Scanner: https://docs.microsoft.com/en-us/windows/securi...

    Malwarebytes Free (select Free Download): https://www.malwarebytes.com/premium/

    Once done, perform a reboot, then monitor your machine.

    However, if the issue still persist, kindly perform a repair install of your Windows. I suggest that you watch the video on this article(https://www.yourwindowsguide.com/2016/06/how-to... or https://www.tenforums.com/tutorials/16397-repai...) for you to have an idea regarding the process of repair install. There should be no worries in performing it since you will select the option to keep your files during the process.

    I hope this helps. Good luck!

    ________________________________________________________

    Standard Disclaimer: There are links to non-Microsoft websites. The pages appear to be providing accurate, safe information. Watch out for ads on the sites that may advertise products frequently classified as a PUP (Potentially Unwanted Products). Thoroughly research any product advertised on the sites before you decide to download and install it.

    0 comments No comments