• 0

Am I clean? Potential infection in W11


Question

Hi,

Received a file from somebody which had an .exe infected with HackTool:Win32/AutoKMS!ml.

The ideea is that I didn't opened it, only saved it on my NAS.

After Defender from W11 detected the trojan.. I ran a quick-scan with it and  got the following :

image.png.34deb8a73c46433c8c6d8d3ef9b3efa5.png           image.png.05f7e1b996ecc6a597efbba5b346266c.png                          image.png.0b1e8362b0dcb3fbe34bc10fc842043f.png

 

I also ran Malwarebytes and got the following results. During the time Malwarebytes was installed I noticed that Defender icon was green.. not with the x as was before install MB. and after uninstalling Malwarebytes

Red : image.png.5ebd4c75e4957e0d5bf78936b0ae4684.png

 

image.png.230317f145dad6d78bd59d98286bee11.png

 

Conclusion :

1. Defender doesn't seem to be able to change something with quarantine or remove. I think that remembers the file as Affected items at that path.. but it's empty right now. Cannot get rid of the message anyway.

2. Malwarebytes gives a clean report.

3. That file was also manually removed from NAS. Should I scan the entire drive also?

What do you recommend? Thanks a lot!

 

 

5 answers to this question

Recommended Posts

  • 0

Hello,

As long as you do not run the file the computer should not be infected.  If you are concerned (and still have the file), you can try uploading it to Google's multi-engine scanning tool at https://www.virustotal.com and see what it reports.

 

Regards,

 

Aryeh Goretsky

 

  • Like 2
  • 0

I think goretsky summed it up.

 

 

On 07/11/2021 at 14:05, Cosmin said:

Received a file from somebody which had an .exe infected with HackTool:Win32/AutoKMS!ml.

 

As a general rule... never open EXE files from a random person who sends you them. because there is a fair chance it will be a virus (or the like), especially if it's someone you don't know and you were not expecting to receive something specific.

  • Like 2
  • 0

I did not open/run it but simply erased. Was saved on my NAS and now Windows Security from W11 "remembers" that something was there...

Indeed.. I've scanned my pc with both Windows Security & Malwarebytes & the NAS drive only with Windows Security. Can be NAS be infected by itself? It's not an O.S on it's own..

 

If everything is fine how can I get rid of the notification from Windows Security regarding it (with the path from the NAS) ? Thanks!

  • 0
On 08/11/2021 at 17:46, Cosmin said:

I did not open/run it but simply erased. Was saved on my NAS and now Windows Security from W11 "remembers" that something was there...

Indeed.. I've scanned my pc with both Windows Security & Malwarebytes & the NAS drive only with Windows Security. Can be NAS be infected by itself? It's not an O.S on it's own..

 

If everything is fine how can I get rid of the notification from Windows Security regarding it (with the path from the NAS) ? Thanks!

Your NAS might have a network recycle bin (as in the file is not yet deleted and still available in the mapped network drive) if you can login to your NAS might want to check you have deleted the recycle bin.

  • 0

It's a WD My Cloud 2TB - I don't see anything related to recycle bin.. but even so - as far as I know a file is not removed but overwritten.

Attached is the sample setup for Media Folder.. all the others are the same.

Do you suggest scanning everything with an additional tool? Any recommended?

image.png.87b4965c1c25be4bae83b5327f60599e.png

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Google Chrome 149.0.7827.156 (offline installer) by Razvan Serea The web browser is arguably the most important piece of software on your computer. You spend much of your time online inside a browser: when you search, chat, email, shop, bank, read the news, and watch videos online, you often do all this using a browser. Google Chrome is a browser that combines a minimal design with sophisticated technology to make the web faster, safer, and easier. Use one box for everything--type in the address bar and get suggestions for both search and Web pages. Thumbnails of your top sites let you access your favorite pages instantly with lightning speed from any new tab. Desktop shortcuts allow you to launch your favorite Web apps straight from your desktop. Chrome has many useful features built in, including automatic full-page translation and access to thousands of apps, extensions, and themes from the Chrome Web Store. Google Chrome is one of the best solutions for Internet browsing giving you high level of security, speed and great features. This update includes 33 security fixes. [N/A][516496659] Critical CVE-2026-12437: Use after free in WebShare. Reported by Google on 2026-05-25 [N/A][516947912] Critical CVE-2026-12438: Inappropriate implementation in WebView. Reported by Google on 2026-05-27 [N/A][519728275] Critical CVE-2026-12439: Use after free in Digital Credentials. Reported by Google on 2026-06-03 [N/A][519731619] Critical CVE-2026-12440: Use after free in DigitalCredentials. Reported by Google on 2026-06-03 [N/A][520157118] Critical CVE-2026-12441: Use after free in File Input. Reported by Google on 2026-06-05 [N/A][521950423] Critical CVE-2026-12442: Use after free in Passwords. Reported by Google on 2026-06-09 [N/A][522566295] Critical CVE-2026-12443: Use after free in Web Authentication. Reported by Google on 2026-06-11 [N/A][513160088] High CVE-2026-12444: Out of bounds read in Chromoting. Reported by Google on 2026-05-14 [N/A][513199795] High CVE-2026-12445: Use after free in Extensions. Reported by Google on 2026-05-14 [N/A][513313107] High CVE-2026-12446: Insufficient data validation in Passwords. Reported by Google on 2026-05-14 [N/A][513405023] High CVE-2026-12447: Heap buffer overflow in WebRTC. Reported by Google on 2026-05-15 [N/A][513458233] High CVE-2026-12448: Inappropriate implementation in WebView. Reported by Google on 2026-05-15 [N/A][513480539] High CVE-2026-12449: Use after free in Chromoting. Reported by Google on 2026-05-15 [N/A][514531776] High CVE-2026-12450: Inappropriate implementation in Media. Reported by Zhixin Tu on 2026-05-19 [N/A][514741076] High CVE-2026-12451: Use after free in DigitalCredentials. Reported by Google on 2026-05-19 [N/A][515462244] High CVE-2026-12452: Use after free in Downloads. Reported by Google on 2026-05-21 [N/A][516448843] High CVE-2026-12453: Insufficient validation of untrusted input in Input. Reported by Google on 2026-05-25 [N/A][516926968] High CVE-2026-12454: Race in Safe Browsing. Reported by Google on 2026-05-27 [N/A][517069848] High CVE-2026-12455: Use after free in Tab Strip. Reported by Google on 2026-05-27 [N/A][517124587] High CVE-2026-12456: Insufficient validation of untrusted input in Extensions. Reported by Google on 2026-05-27 [N/A][517153117] High CVE-2026-12457: Insufficient data validation in Extensions. Reported by Google on 2026-05-27 [N/A][517258337] High CVE-2026-12458: Incorrect security UI in Passwords. Reported by Google on 2026-05-27 [N/A][517406035] High CVE-2026-12459: Inappropriate implementation in Serial. Reported by Google on 2026-05-28 [N/A][517484284] High CVE-2026-12460: Insufficient policy enforcement in File System Access. Reported by Google on 2026-05-28 [N/A][517727318] High CVE-2026-12461: Out of bounds read in WebRTC. Reported by Google on 2026-05-29 [N/A][517916024] High CVE-2026-12462: Use after free in Media. Reported by Google on 2026-05-29 [N/A][518042749] High CVE-2026-12463: Inappropriate implementation in Views. Reported by Google on 2026-05-30 [N/A][519358344] High CVE-2026-12464: Use after free in Browser. Reported by Google on 2026-06-03 [N/A][520189702] High CVE-2026-12465: Insufficient validation of untrusted input in Metrics. Reported by Google on 2026-06-05 [N/A][520199394] High CVE-2026-12466: Heap buffer overflow in WebRTC. Reported by Google on 2026-06-05 [N/A][520202726] High CVE-2026-12467: Use after free in Extensions. Reported by Google on 2026-06-05 [N/A][521485244] High CVE-2026-12468: Inappropriate implementation in Updater. Reported by Google on 2026-06-08 [N/A][521618871] High CVE-2026-12469: Uninitialized Use in GPU. Reported by Google on 2026-06-09 Important to know! The offline installer links do not include the automatic update feature. Download web installer: Google Chrome Web 32-bit | Google Chrome 64-bit | Freeware Download: Google Chrome Offline Installer 64-bit | Direct Link | 131.0 MB Download: Google Chrome Offline Installer 32-bit | Direct Link | 119.0 MB Download page: Google Chrome Portable Download: Chrome ARM64 | Direct Link View: Chrome Website | Release Notes Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • they couldnt do W11 LTSC so the support lasts longer....
    • The fact that the pref is not enabled by default tells you that what you see is what you get...for now. Hopefully the final version will have all the quirks ironed out.
    • It's enterprise, not consumer. And "...affected scenarios involve third-party software..." Would be good to know that in headline, not way down in the article. Instead, you lead with Windows update, which is not very helpful and misleading, IMHO. Just saying.
  • Recent Achievements

    • Week One Done
      suprememobiles48 earned a badge
      Week One Done
    • One Month Later
      Windows Guy earned a badge
      One Month Later
    • One Month Later
      Prasann earned a badge
      One Month Later
    • Week One Done
      Prasann earned a badge
      Week One Done
    • First Post
      Dys Topia earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      503
    2. 2
      +Edouard
      173
    3. 3
      PsYcHoKiLLa
      97
    4. 4
      Steven P.
      85
    5. 5
      ATLien_0
      71
  • Tell a friend

    Love Neowin? Tell a friend!