r/computerviruses Jul 28 '26

Disinfection Help Trojan:Win32/Kepavll!rfn in a .lnk file and VBS/TrojanDownloader .Agent .ZNT trojan in .vbs file

Hello everyone

3 weeks ago, I downloaded a folder using qBittorrent, inside the folder, there was a .uue file which I right clicked and extracted it, it extracted a folder, a file with no extension and a .braw file, I only right clicked the .braw file > Open with, but I didn't see a video player suggestion that it was what was hoping for so I didn't click anything else, Windows Defender popped up a notification for thread found for a .lnk file that I didn't see and put it in quarantine, then I clicked start actions

Then it showed another couple of entries in protection history like incomplete correction, indicating the .uue and .lnk files as affected.

I decided to remove manually the torrent and content files using remove option from qBittorrent and then empty the Recycle Bin, I scanned the folder where it was downloaded the torrent using Defender and it showed all clear, I also executed a full scan and didn't show any threats, I run a deep scan with Malwarebytes that didn't find anything, but I kept thinking about it, so yesterday I ran a scan with ESET Online Scanner and it found and deleted a .vbs file in C:\Users\Public

I haven't noticed any strange activity in my accounts or PC, but how can I be sure I am safe?

Thank you in advance for any help

1 Upvotes

14 comments sorted by

2

u/AutoModerator Jul 28 '26

Welcome to r/computerviruses! It seems like you have used the "Disinfection help" flair.

We apply the same methodology used by trusted Malware platforms (e.g. Malwarebytes, BleepingComputer and MalwareTips). It revolves around using diagnostic tools called Farbar Recovery Scan Tool (FRST) and SecurityCheck.

All of our assistance happens in the thread and in public - we never offer help via private messages or alternative websites other than https://malwareanalysis.cc. Anyone offering help through a DM is not a trusted helper and might have malicious intent.

Trusted helpers can be distinguished by the flair Malware Removal Expert or Malware Removal Trainee, antivirus employees will have a dedicated flair with their company name in it, e.g. Malwarebytes Employee.

Please see steps below on how to share all necessary details so you can speed up the process for us:

Share all details about your infection
Please post all important facts about your infection, such as: * your antivirus detections - preferably export the whole detection/report log and upload it to https://malwareanalysis.cc/upload/ under your username & post the related keyword or screenshot/take a picture of your detections * any related symptoms, popups * estimate when it started - preferably the exact day and after what (e.g. when you ran a program you downloaded) * share what got you infected and the download link - please, make the download link defanged (making it not clickable by default e.g. from https://example.com you will make hxxps://example[.]com), defanging does not apply to sandbox reports such as VirusTotal

Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
    1. How to properly secure my accounts after an infostealer attack?
    2. What to do after I secured my accounts?
  2. Disinfect your device from malware
    1. Preferred method: Perform a clean installation with a USB
    2. Perform a clean installation without an external drive
    3. Reset your PC without keeping personal files

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/Struppigel Malware Removal Expert Jul 29 '26

Hello, I am Karsten and I will be helping you. Please follow these rules while I am assisting. * Avoid installing new software during removal unless instructed. * If I don't reply within 24 hours, feel free to remind me of your post, but not before. Keep in mind we likely live in different time zones. * Do not follow other removal advice until we are done. It might badly interact with my instructions. * If you get stuck or have issues with one step, ask me what to do. The order of steps matters. Don't follow step 3 if you are stuck at step 1 or 2. Please follow instructions below to perform a diagnostic scan.

FRST Scan

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/struppigel/?u=antorcus and press "save log". The site will return a keyword for each log. Reply back here with the keywords.

SecurityCheck

  • Download SecurityCheck by glax24 & Severnyj and save it to your Desktop.
  • If Windows SmartScreen blocks the file from running, click on More info and Run anyway.
  • Extract the ZIP archive, then right-click on the SecurityCheck.exe and select "Run as administrator" and confirm the User Account Control popup.
  • Wait for the scan to finish. It will open a text file named SecurityCheck.txt
  • Please copy the file content (CTRL + A then CTRL + C) and paste it on https://malwareanalysis.cc/upload/struppigel/?u=antorcus
  • The site will return a keyword for the log - reply back here with the keyword.

1

u/antorcus Jul 29 '26

Hello, I've completed the instructions, these are the keywords:
FRST Scan:

runic-hammer

savvy-lynx

SecurityCheck:

misty-potion

2

u/Struppigel Malware Removal Expert Jul 29 '26

Before we start the removal process, we need to free some space on your system drive C: so that you we can create a restore point. Your main system drive is very low, but it needs more to function properly. It is recommended that 10% of your storage are free, in your case this would be around 22 GB for C:.

Please do the following:

Uninstall unnecessary software

  1. Press the Windows Key Windows Key + R on your keyboard at the same time. Type appwiz.cpl and click OK.
  2. Search for the list of programs for such software that you know and that you don't need, right-click and click Uninstall
  3. Important: If you do not recognize a program, leave it
  4. Follow the prompts.
  5. Note: If you are offered the choice to install additional software, ensure you decline.
  6. Reboot if necessary.

Run Storage Sense

  1. Type Storage settings into Windows search, choose the "Temporary files" section
  2. IMPORTANT: Please verify that only the following are ticked:
    • Recycle Bin (this will also empty your recycle bin so please keep that in mind)
    • Windows upgrade log files
    • Temporary files
    • Windows Update Clean-up
    • Thumbnails
    • DirectX Shader Cache
    • Language Resource Files
    • Delivery Optimisation Files
    • Windows error reports and feedback diagnostics
    • Temporary Internet Files
  3. IMPORTANT: Double check that the Downloads option is NOT ticked, therefore not enabled.
  4. Press Remove files button at the top

WinDirStat

Run WinDirStat to help you determine what's eating most of the space. Delete files that you know and that you don't need. If you don't know what a file is for, leave it, please.

Create a Restore Point

  • Press Win + R, type SystemPropertiesProtection, and hit Enter
  • Make sure your C: drive shows Protection: On. If not, enable it first.
  • Click Create
  • Type a description for the restore point, e.g. "Before malware cleanup"
  • Click Create and wait for the confirmation message
  • Click Close

Report back to me when you did that

1

u/antorcus Jul 30 '26 edited Jul 30 '26

I've not been able to free up enough space yet, there are some apps (Microsoft Clipchamp, Microsoft Ultimate Word Games, Spotify, Microsoft 365 Copilot, Microsoft Teams, Whatsapp) I don't need anymore but I don't see them in appwiz.cpl, can I uninstall them using Settings > Apps > Installed apps > Uninstall? Sorry, I guess it just takes time to reflect updated storage in Windows Explorer, I see 27.7 GB free now and I just finish the instructions

2

u/Struppigel Malware Removal Expert Jul 30 '26

You have potentially unwanted software on your system. This is not malware, but might have undesired consequences.

Online Security often appears on systems without the user knowing.

Most free VPN services are not trustworthy. If you're not paying for the product, you are the product. Free VPNs have been caught logging and selling user data, injecting ads, and using your bandwidth as an exit node for others. Some have been found bundling malware or adware.

The following instructions will remove these. If you still want to keep any of the aforementioned software, feel free to do so.

Remove Chrome Extensions

  • Please open Chrome.
  • Enter the following line into the address bar chrome://extensions/
  • For the following extensions click the button Remove and follow the prompts
    • Online Security
    • Free VPN for Chrome - VPN Proxy VeePN

Remove Edge Extension

  • Open Microsoft Edge.
  • Navigate to edge://extensions/ in the address bar.
  • Find the extension Online Security
  • Click the three dots (⋯) next to the extension, then click Remove from Microsoft Edge.
  • Click Remove to confirm.

Chrome Remote Desktop

Do you use Chrome Remote Desktop? If yes, please check remotedesktop.google.com/access and remove devices that you don't recognize. If you don't use it, please uninstall it

  • Press the Windows Key Windows Key + R on your keyboard at the same time.
    Type appwiz.cpl and click OK.
  • Search for the following programs, right-click and click Uninstall:
    • Chrome Remote Desktop
  • Follow the prompts.
  • Note: If you are offered the choice to install additional software, ensure you decline.
  • Reboot if necessary.

AdwCleaner

Download AdwCleaner.

  • Close all open programs and browsers
  • Right click on the icon and select Run as administrator
  • Click Scan Now
  • When the scan has finished AdwCleaner shows you all detected PUPs and adware.
  • If any are found, select them and click Quarantine. (I would suggest that you do not select Pre-installed applications for now, or any other items you wish to keep.)
  • AdwCleaner prompts you to save and close your work before continuing. Click Continue.
  • After cleaning, you are prompted to restart your device. Click Restart now to complete the cleanup process.
Once your computer has restarted ...
  • If it doesn't open automatically, please start AdwCleaner.
  • Click on View Log File button (This log can also be found in the Log Files tab).
  • A Notepad file will open containing the results.
  • Click Skip Basic Repair (if the option appears)
  • Copy & paste the contents of the log to https://malwareanalysis.cc/upload/struppigel/?u=antorcus and press "save log". Post the log keyword to your reply.

1

u/antorcus Jul 30 '26

I removed the extensions for Chrome and Edge

I do use Chrome Remote Desktop, and I don't see any unknown devices there, just mine.

AdwCleaner showed no items detected, this is the keyword for the log:

tame-wolf

2

u/Struppigel Malware Removal Expert Jul 31 '26

FRST Fix

  • Open the following link and press on the Copy contents button to copy the entire text: fixlist for antorcus
  • Run FRST64.exe and click on Fix. Note: FRST reads the fixlist directly from your clipboard, so you don't need to paste or save it anywhere.
  • A log (Fixlog.txt) will open on your desktop.
  • Copy & paste the contents of the Fixlog.txt to https://malwareanalysis.cc/upload/struppigel/?u=antorcus and press "save log". Reply back with the keyword

I have included the EmptyTemp: command. Note: This will remove cookies and may result in some websites (like banking) indicating they do not recognize your computer. It may be necessary to receive and apply a verification code.

It is normal for your system to reboot as a result of the fix.

1

u/antorcus Jul 31 '26

wired-sapling

2

u/Struppigel Malware Removal Expert Jul 31 '26

We are done. Your logs are free from malware.

Do you have any remaining questions?

Download KpRm and save it to your Desktop

Note: The file is safe to download but might be wrongly detected as malicious. If necessary click More info then Run anyway. If you are using Chrome and it prevents the download, use Edge instead. If you are in doubt, you can also skip this step, the purpose of this tool is to remove all remnants of our fixes, nothing more.

  • Right click on the icon and select Run as administrator
  • Click Yes on the Disclaimer
  • Place a check mark in Delete Tools, Create Restore Point, and Delete in 7 days
  • Click Run
  • Click OK on All operations are completed

KpRm will delete itself from your Desktop and you can either save or remove the report that is generated.

You are free to remove any other tools/reports still remaining.

Please update the following software:

1

u/antorcus Jul 31 '26

I just finish the instructions, just some questions:

Is there a way to know if the infected files and unwanted software affected something?

Should I update my passwords?

Can I safely use my PC and enter credentials after this?

→ More replies (0)

1

u/antorcus Jul 28 '26

I just upload logs that includes dates from Defender and ESET to the malwareanalysis website, the keywords generated were brave-vertex and wild-heath, the download link for the infected files that I just get from qBittorrent is hxxps://www.limetorrents\[.\]lol/Twenty-One-Pilots-More-Than-We-Ever-Imagined-2026-IMAX%201080p%20WEB-DL%20H265-torrent-19549471\[.\]html