VirTool:Win32/DefenderTamperingRestore

Solved
Jensenviolin -  
 Jensenviolin -

Hello,

I’m not sure if my computer is infected with the virus VirTool:Win32/DefenderTamperingRestore, I wasn’t even aware of this virus until now, but having doubts about a possible infection, I ran the Microsoft Safety Scanner (MSERT) to check if my computer was infected.

The report from this scan indicated that I was infected with this virus but that it has been removed from my computer. Afterwards, I ran the same scan several times and while it was analyzing all my files, it always showed 1 infected file, and at the end of the scan, strangely I received a report stating that no virus was found or removed.

I want to be sure that my computer is not infected with this virus.

Can you please help me?

Thank you in advance


12 réponses

MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

Hello

We're going to start with a PC diagnosis:

Read the entire procedure carefully before posting the reports
Do not post them directly in the messages as they are unreadable and incomplete

The reports FRST.txt and Addition.txt are expected

All reports must be hosted on https://security-x.fr/up/ and you should include the obtained links in your response

---------------------------------------------------------------------------------------------

--> The SmartScreen filter may trigger an alert. Click on Actions or More info then on Run anyway

---------------------------------------------------------------------------------------------

--> Download the FRST version of Farbar, compatible with your system, and save the file to your Desktop

--> For a 32-bit system
--> For a 64-bit system

How to find out which version is running on my system, 32-bit or 64-bit?

--> Wait for your browser to prompt you to download and save, without clicking anywhere, especially not on the sponsors of the page.
--> Close all applications, including your browser
--> Double-click on FRST.exe and click Yes to accept the Disclaimer
--> Under Vista, Windows 7 / 8 and 10, you must launch the file by right-clicking -> Run as administrator
--> Wait until it indicates The tool is ready to run
--> On the main menu, click on Scan and wait for the analysis to complete
--> At the end of the scan, the reports FRST.txt and Addition.txt are created. Post these reports in your next response.
--> The reports are saved in the same location as the tool and under C:\FRST\Logs


0
jensenviolin
 

https://up.security-x.fr/file.php?h=R8bacbd3b0c914a401cbb254ef5594d2d
https://up.security-x.fr/file.php?h=R7b94ba0966849093c5298af15563041b

here are the 2 links, I hope I didn't make a mistake and send the same ones twice

0
Jensenviolin
 

Sorry, I just read your email

I'll get on it right away,

thank you for your response

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

You have too many antivirus programs on this PC, Windows Defender is more than enough.

Uninstall:

=> Avast Free Antivirus
=> Avast Secure Browser

=> McAfee Security Scan Plus
=> McAfee True Key
--> Unless useful

=> Intel® Security Assist

Once done, delete the two reports on your desktop, then restart a FRST scan and post the new reports.

PS: Can you copy/paste in your response the detection found by MSERT?


0
Jensenviolin
 

Hi,

Yes, so regarding my antivirus, I wanted to activate Windows Defender, but I got a message saying that Avast was my antivirus. So I removed all the other antivirus programs except for Avast. I'm not sure if I dare to uninstall Avast and then activate Windows Defender...

If I understood correctly, I can't activate Windows Defender while Avast is on my computer. Windows is protecting me with its firewalls, but when I click on Virus and threat protection, it says that Avast Anti-Virus is active. (start-->pc settings-->update and security-->windows security-->virus and threat protection).

I'm a little scared because I started the scan for current threats (in Virus and threat protection) and the scan is very long, it's not progressing...

And my PDF files, their location on my desktop, the icon has turned into a blank page, it's no longer the icon I was used to. Also, for some of my downloads, I have a blank page instead...

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

Two solutions:

=> Either you follow my instructions without doing anything else and wait the necessary time for troubleshooting

=> Or you do things on your own and manage by yourself.

It's not possible to make progress if you don't follow my instructions and want to rush ahead.

Stop launching analyses left and right and do what I ask you.


0
Jensenviolin
 

I'm sorry, I was scared because I'm not used to doing this,

and when I received the message from Microsoft saying that I wasn't protected, I got scared.

So I removed all the antivirus programs you mentioned, and I restarted FRST.

Here are the two new analyses:

https://up.security-x.fr/file.php?h=R59c350900b59da04047254f817655384
https://up.security-x.fr/file.php?h=R4e22c716a39d2422a6aec286684ed55f

Regarding the MSERT report, I don't know how to find it, I misphrased in my main post, it's not a report but just a sentence that said:

"The scan completed successfully and no viruses, spyware, and other potentially unwanted software were detected."

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

And did you translate it? That means:

The scan completed successfully and no viruses, spyware, or other potentially unwanted software was detected.

******

-> Copy what is found HERE from start:: to end:: (without pasting it anywhere)

--> Open FRST (or FRST64) as an administrator and click on Fix
If FRST seems to freeze or is unresponsive, let it run.

--> The PC will restart

--> A fixlog file is created in the same location as FRST, post it like the other reports

--> The fix will clean the firewall, the programs you launch afterwards will ask for access on the first launch

--> Open the security center (Windows Defender) and let me know if you still have the issue.


0
Jensenviolin
 

Here is the result of the FRST

https://up.security-x.fr/file.php?h=R6980414db7ff2bb7c53089ed4dc25ed1

I don't know if I still have the problem because initially,

I found out about it through a message from Microsoft Safety Scanner.

Have you seen any viruses in the reports I sent you?

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

Okay for the report.

No, it’s not an infection, and there is no security breach; it’s an alert to indicate that Windows Defender is disabled and a fix is being applied.

However, since there were several active AVs, despite the fix, the deactivation of Windows Defender was continuously present, hence the detection of VirTool:Win32/DefenderTamperingRestore.

Otherwise, the PC was clean, no infection, only obsolete files.

*********

What does the security center say? Is everything okay as shown below:

*************************

Uninstall Avast Update Helper which must have appeared in the list of programs


0
Jensenviolin
 

Okay, good, I'm glad I didn't get any viruses, it’s always scary.

Good to know, I didn't realize that just Windows Defender was enough as an antivirus!

As for the security center, everything is fine, except "virus and threat protection," "ransomware protection" because I haven't configured OneDrive in case of an attack. I'll see if it's useful or not.

Could these reports have deleted obsolete files like you said?

0
Jensenviolin
 

Yes, I will remove Avast Update Helper

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

except for "protection against viruses and threats", "protection against ransomware" because I have not configured OneDrive

Just click on "ignore", you will no longer receive the notification

For Windows Defender, more details HERE and HERE

*************

If it's OK, to finish, to automatically delete all files/folders created by FRST and the tool itself, rename FRST/FRST64.exe to uninstall.exe and run it.

The procedure requires a restart


0
Jensenviolin
 

I have removed the FRST folder. Everything is okay.

And I will read the links on Windows Defender.

In any case, thank you for your help and for your quick replies.

Have a great day!

0
MisteryBean Posted messages 8947 Registration date   Status Modérateur Last intervention   1 292
 

RE_

Okay, see you later on CCM


0
Jensenviolin
 

See you later

0