Author Topic: Windows Updates Service.vbe virus  (Read 3730 times)

0 Members and 1 Guest are viewing this topic.

Offline wardbesseling2

  • Newbie
  • *
  • Posts: 2
Windows Updates Service.vbe virus
« on: December 29, 2020, 10:37:23 PM »
Today I got a strange message that my "Windows update service" cloudn't start.
I forgoto to take a screenshot.
But i have fount the location of the encoded .VBE file and decoded it to .VBS.
Path: C:\Users\User\AppData\Roaming\Windows Updates Files\Windows Updates Service.vbe

When scanning with Avast, I get a virus warning. But on 7 December I did a full virus scan. I am curious how this got here.
Here is the decoded virus:
https://paste.ubuntu.com/p/XWqNrFp3jy/
This has a very weird site. And I got like 3 antivirus vendors to react: ESET, Kaspersky and Sophos.

Can someone tell me if i need to wipe all my data  :P ;D?
I got  a back-up to Nextcloud. And this data is back-upped on a write protected drive in Debian. That is only accessible in a certain format XD

Here the Encoded file:
https://paste.ubuntu.com/p/mcZYkbDgWv/


Offline wardbesseling2

  • Newbie
  • *
  • Posts: 2
Re: Windows Updates Service.vbe virus
« Reply #2 on: December 30, 2020, 07:58:11 AM »
Yes im seeing successfull installed virus register values as well TEMP files.
Now removing them. Thanks bot, good idea to scan the .vbs file

But it's still going to the website...
Did a full Avast scan and that even didn't work and blocking the site in the firewall isn't preventing the query of the website...
What is best for me to do?
Did a Malwarebytes, Avast and Adwcleaner scan.
« Last Edit: December 30, 2020, 09:18:17 AM by wardbesseling2 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Windows Updates Service.vbe virus
« Reply #3 on: December 30, 2020, 09:36:18 AM »
Start a topic in V&W and post your logs there: https://forum.avast.com/index.php?action=post;board=4
Instructions (basic diagnostic logs): https://forum.avast.com/index.php?topic=194892.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0