Link to home
Start Free TrialLog in
Avatar of Oscar
OscarFlag for United States of America

asked on

why Antivirus tools dont find " RDN/Trojan.worm!055BCC2967574 Infection?

Hello,

A newly installed Dell all-in-one computer with windows 10 pro got a popup malware named "RDN/Trojan.worm!055BCC2967574 Infection”. Attached file shows the popup.

The installed anti Malwarebyte did not detect anything. I ran the app manually again. In addition I downloaded few more and scanned the computer , neither of these tools find anything..

Last week He hit with similar popup and again the tools claimed his PC is cleaned.
Can anyone advise if I should take any step further or his computer in fact is clean?

The following are the tools that I used.
1- Malwarebytes (Paid License).
2- Malwarebytes Anti Exploit (Paid License).
3- HitManPro (Evaluation - Free download).
4- Adware Cleaner (Evaluation- Free download).
5- Zemana (Evaluation- Free download)

Thank you.
VirusPict.PNG
Avatar of Thomas Zucker-Scharff
Thomas Zucker-Scharff
Flag of United States of America image

I see you tried HitmanPro, but have you tried the crytoguard/interceptx/hitmanpro. alert product line?
SOLUTION
Avatar of John
John
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
it looks like the real time protection detected it when you visited that site
i t suggests  - it did not get on the pc
Upload the sample to virustotal.com
You will see that for new viruses, detection rates are low. Often, I submitted samples and only 5 of 56 scanners detected anything. That is normal.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Oscar

ASKER

Hello all,
Thank you all for your thoughts and recommendation.
I am kind of agree to all of you and lean more to that it is just a script and it is not a virus. This warning happened when a user lunched MS Edge before visiting any page. And by closing it from TaskMGR it is being removed.
I am charged the client first time and another hour for last time and it is not practical to analyze it through sysinternal utilities for one PC. As I mentioned it is a Dell computer and I suggested to client that if it happens again I will format it and reinstall OS this way after few hours I guarantee that I have clean system the other approach it is not guarantee and it might even damage OS more that I will end up formatting any way,.
I hope it would not happen again but if it happened I format the disk. Thanks again and I hope you all agreed with my selections.
>>  Thanks again and I hope you all agreed with my selections.   <<  what do you mean?
Avatar of Oscar

ASKER

Hi nobus
If I was not clear or said something wrong, please forgive me since I did not meant bad. What I was trying to say was that all of you guys said something useful but I most agreed to the one there is no virus on system it was just a text and meant to make the user to call and then get control the system and damage might start at that point on or simply do what I did and charge the user some $$.
On this new portal I don't see to distribute point so I might got confused on my closing statement. That is all..
You did not close, yet.
select "BEST Answer" and "assisted"
Avatar of Oscar

ASKER

Thank you all.
You are very welcome. Happy to help