Jump to content

Win64/Rozena.ABC


Go to solution Solved by Marcos,

Recommended Posts

Hello all, after years of being able to rid myself of malware without help, I'm now stuck.

Nod32 is popping up the usual warning window saying a threat was found in file ... etc. When I click to see what files they are, they are .exe files, such as logitec mouse options, Nvidia Container and so on, but also various windows system apps when I try to open them.

I've rebooted as the Eset window suggests, to complete the cleaning, but the same warnings pop up after every reboot. I have Nod32 (paid subscription) and Malwarebytes Premier running.

A deep MalwareBytes scan is finding nothing and gleefully telling me my system is clean. I ran NKill and that found nothing. Have reset my Chrome browser so no extensions running.

Ran a full Nod32 scan with today's detection updates installed (29419 20240619), nothing found.

Has anyone got experience with a Win64/Rozena.ABC infection? Any idea how to clean it? All suggestions very much appreciated.

Link to comment
Share on other sites

  • Administrators
  • Solution

This was a false positive. An update is being prepared which will fix it. In the mean time you can create a detection exclusion by the detection name.

Link to comment
Share on other sites

Hi, this issue is being addressed here:

https://forum.eset.com/topic/41396-eset-is-flagging-hundreds-of-legitimate-system32-processes-as-malware-and-running-my-computer-unusable/#comment-185846

In my case, the problem was solved by disabling the Windhawk program, which modifies the visual aspects of windows.

I hope that solves the problem.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...