window script host error

hlots123

Supremacy Member
Joined
Apr 5, 2006
Messages
5,207
Reaction score
11
help u post pic...
i dun have lsass folder inside c:\amd.
worst case could be some kind of bitcoin virus that didn't install properly. eg. some trojan managed to install the startup shortcut but couldn't download the other files like WMI.vbe etc.
suggest scanning for virus & look at running processes for anything suspicious/unknown.

30adnrq.png
 

bladeknight

Senior Member
Joined
Nov 27, 2008
Messages
899
Reaction score
0
help u post pic...
i dun have lsass folder inside c:\amd.
worst case could be some kind of bitcoin virus that didn't install properly. eg. some trojan managed to install the startup shortcut but couldn't download the other files like WMI.vbe etc.
suggest scanning for virus & look at running processes for anything suspicious/unknown.

30adnrq.png

I had try to scan but no virus detect.
 

havetobuy

Banned
Joined
Dec 28, 2011
Messages
1,488
Reaction score
0
View image: Error

Having this error message after starting up.

i went thru googlin..80% says its not a virus butt a driver loadup problemo
i know becoz amd muz run the visual basic program first b4 driver installation is approved
as for me
i wud rather run
regedit
searched un local/blah/blah software
find AMD
find this file
c:\amd\lsass\WMI.vbe
and delete it from the registry
since it cannot find the bootup file in the FIRSTplace
 

bladeknight

Senior Member
Joined
Nov 27, 2008
Messages
899
Reaction score
0
i went thru googlin..80% says its not a virus butt a driver loadup problemo
i know becoz amd muz run the visual basic program first b4 driver installation is approved
as for me
i wud rather run
regedit
searched un local/blah/blah software
find AMD
find this file
c:\amd\lsass\WMI.vbe
and delete it from the registry
since it cannot find the bootup file in the FIRSTplace

i just took a malwarebytes scan and the results shown that it is a Trojan.BitCoinMiner...

I found that the c:\amd\lsass\WMI.vbe was found in C drive, not in regedit so i already delete from there. So far never appear that message for now.
 
Last edited:

hlots123

Supremacy Member
Joined
Apr 5, 2006
Messages
5,207
Reaction score
11
i just took a malwarebytes scan and the results shown that it is a Trojan.BitCoinMiner...

I found that the c:\amd\lsass\WMI.vbe was found in C drive, not in regedit so i already delete from there. So far never appear that message for now.
besides this file, were any others detected? if got "installed" w/o UAC prompting u, i'm guessing there cud be some other existing program/service (malware) tat is running...
 

ykgoh

Master Member
Joined
Jan 1, 2000
Messages
2,782
Reaction score
0
It means MSE and Spybot are quite ineffective. Missed out all these PUP previously.

So what other malware scanners did you use, apart from MalwareBytes?
 

bladeknight

Senior Member
Joined
Nov 27, 2008
Messages
899
Reaction score
0
It means MSE and Spybot are quite ineffective. Missed out all these PUP previously.

So what other malware scanners did you use, apart from MalwareBytes?

Typo error. Is detect at the same time. But I rescan , there isn't any malware found.
 
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top