[SOLVED] Windows Defender detected something weird. Not sure what to do.

Apr 7, 2021
1
0
10
So I was sort of in a rush to do this because I needed the footage for a video and may have accidentally downloaded something malicious. I was trying to find a method to run Crash Bandicoot 4 on ultrawide. Eventually I found a method where you just modify a couple hex which is working perfectly for me now but before this I downloaded some .exe from a random Polish website, I assumed it was something you just put in the game directory and it made ultrawide work, as I've downloaded similar mods for other games in the past. When I downloaded the file, I thought it looked odd, the name of the file was 'Crash Bandicoot™ 4 It's About Time.exe' which is not the name of any file in the game directory and the site said you were supposed to replace it with the main .exe of the game.

Here is a translation of the website basically claiming it to be safe:

"Note: some anti-viruses may mistakenly detect this mod as dangerous. This is nonsense, because the mod is completely safe and proven. It is simply not in the antivirus databases, and for that its purpose is to change other files, hence the incorrect threat detection."

As soon as I thought it was suspicious, I deleted it. I can't recall if I ran the .exe or not but I'm 99% sure I didn't. I then did a full scan on Windows Defender and got this. (Strangely nothing is showing up in my protection history now? I did take screenshots of it all though) Wacapew.C!ml. Can barely find any info on it.

https://cdn.discordapp.com/attachments/812514296520245279/829084983871668294/unknown.png

(I went to the locations of the files and deleted them, then I chose remove which probably did nothing as I already deleted them beforehand)

Windows Defender now says no current threats.

Still paranoid, I downloaded Adwcleaner and Malwarebytes. Adwcleaner found nothing, I did a full scan of the C: drive on Malwarebytes and that found nothing.

I also had a friend upload the file to virustotal and he got this (Some sites do detect it as malicious :L)

https://cdn.discordapp.com/attachments/384069359548760074/829108578974826606/20210406_174123.jpg

No idea what to think or what actions I should take next, should I backup and format the C: drive? Very unknowledgeable when it comes to this sort of stuff, viruses and malware have always made me extremely paranoid. Any help/advice appreciated. Thanks.
 
Solution
If you can, use system restore to reset your pc back to a time before you installed the software.
The restore app will have an open checkbox for you to select earlier checkpoints.
Your instincts were correct.

The big flag:

"Note: some anti-viruses may mistakenly detect this mod as dangerous. This is nonsense, because the mod is completely safe and proven. It is simply not in the antivirus databases, and for that its purpose is to change other files, hence the incorrect threat detection."

Pretty much the equivalent of "Send us your personal information. We promise not to use that information to defraud you in some manner."

And do pay attention to the source website. Remember that such things can be spoofed so "geography" per se is not a reliable indicator with respect to "safe" or "not safe".

Yes. Continue to run scans etc. All computers and files anywhere on your network.

Windows Security Defender is a very good starting point. However you can use other products for spot scans as you chose. Malwarebytes is a good choice.

Other AV recommendations may be suggested as well.

Hopefully you got the virus removed before it caused any more serious issues. Or opened a door to do so.

However, keep a close eye on finances, etc. for signs of unauthorized activity.

And do backup all drives and important data. You should always be doing that anyway.

At least 2 sets of copies: one set on another system/NAS and a second set kept off-line. Verify that the copies are recoverable and readable.