Dela via

NSudo.exe trojan?

Anonym
2023-07-14T07:21:08+00:00

Hello Everyone!

Some days ago I downloaded a plugin to After effects. And after that i noticed that my computer was a bit slower. Then i made a scan in Windows defender and it alerted about NSudo!msr Trojan, and i removed it and it said that the danger was deleted. But now when i make scans again the same file seems to appear in defender again. It shows danger in a Adobe Master Collection iso file and microsoft edge 00000 file. I have read about it and some says that this is a trojan and some says that nsudo.exe is a tool for opening programs in admin mode. Someone who knows something about this?

Windows för hemmet | Windows 11 | Säkerhet och sekretess

Låst fråga. Den här frågan har migrerats från Microsoft Support Community. Du kan rösta på om det är till hjälp, men du kan inte lägga till kommentarer eller svar eller följa frågan.

0 kommentarer Inga kommentarer

13 svar

Sortera efter: Mest användbara
  1. DaveM121 872.6K Ryktespoäng Oberoende rådgivare
    2023-07-14T14:20:34+00:00

    To find out if your account is an administrator account, click your Start Button, then just type netplwiz and press Enter, does that utility open?

    Thank you for the screenshot, Defender is indicating those files were found yesterday, they have not been found today, did you run a scan today?

    0 kommentarer Inga kommentarer
  2. Anonym
    2023-07-14T14:13:36+00:00

    I think my account is a full administrator and i think my PC is not linked with any other account, but to be on the safe side, could i check this in anyway?

    And here is the image of the malware it found

    0 kommentarer Inga kommentarer
  3. DaveM121 872.6K Ryktespoäng Oberoende rådgivare
    2023-07-14T13:35:48+00:00

    Is your user account on the PC a full administrator account or is your PC linked to a work or school account?

    Please provide a screenshot of the list of malware found in Defender.

    0 kommentarer Inga kommentarer
  4. Anonym
    2023-07-14T13:33:03+00:00

    Hi Alf,

    I am Dave, I will help you with this.

    Open File Explorer, then on the View menu at the top, temporarily turn on 'Hidden Items'.

    Navigate to this folder: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service

    Delete the contents of that Service folder.

    Navigate to this folder:

    C:\ProgramData\Microsoft\Windows Defender\Quarantine

    Delete the contents of that Quarantine folder.

    Close File Explorer.

    Open Defender and select the option to perform an offline scan, your PC will restart to perform that scan.

    Then check if that malware list is clear.

    Hi Dave!

    Thanks for your quick response, i have been in a car during the day and that is why i am a bit late.

    But now i am home and tried to acces these maps, but unfortunaly i didnt had the right permissions to acces these, it says
    "Du saknar för tillfället rättighet att använda den här mappen" = "You currently do not have permission to use this folder".

    How do i solve this?

    Best regards

    0 kommentarer Inga kommentarer
  5. DaveM121 872.6K Ryktespoäng Oberoende rådgivare
    2023-07-14T07:54:53+00:00

    Hi Alf,

    I am Dave, I will help you with this.

    Open File Explorer, then on the View menu at the top, temporarily turn on 'Hidden Items'.

    Navigate to this folder: C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service

    Delete the contents of that Service folder.

    Navigate to this folder:

    C:\ProgramData\Microsoft\Windows Defender\Quarantine

    Delete the contents of that Quarantine folder.

    Close File Explorer.

    Open Defender and select the option to perform an offline scan, your PC will restart to perform that scan.

    Then check if that malware list is clear.

    0 kommentarer Inga kommentarer