Author Topic: what is wscript.exe??  (Read 1972 times)

0 Members and 3 Guests are viewing this topic.

REDACTED

  • Guest
what is wscript.exe??
« on: March 10, 2018, 09:20:56 AM »
This started happening yesterday. I googled it and it says it's a trustworthy file. Here is a screenshot. As you can see it happens a lot and always at 13 minutes after the hour. If it's not a bad file what is happening and how do I stop it? It's very annoying.



It seems this file can be manipulated through malware. I've run my avast and it didn't detect anything. Just need to know how to fix this. Thank you.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76012
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: what is wscript.exe??
« Reply #1 on: March 10, 2018, 09:52:51 AM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: what is wscript.exe??
« Reply #2 on: March 10, 2018, 04:08:17 PM »
Hi,

download the autoruns from here https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns and go to tasks page. Look for task which spawns wscript. I may have name staring with Yahoo.

Delete that task and you will get rid of this.

Regards,
PDI

REDACTED

  • Guest
Re: what is wscript.exe??
« Reply #3 on: March 11, 2018, 01:19:29 AM »
this is what i see now


Offline PDI

  • Avast team
  • Full Member
  • *
  • Posts: 159
Re: what is wscript.exe??
« Reply #4 on: March 11, 2018, 09:59:11 AM »
Hi gishbunny,

please share the info based on this post.

Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892

Regards,
PDI