Emsisoft Employee
  • Content Count

  • Joined

  • Last visited

  • Days Won


Elise last won the day on February 19

Elise had the most liked content!

Community Reputation

262 Excellent

About Elise

  • Rank
    Forum Veteran

Profile Information

  • Gender

Recent Profile Visitors

31981 profile views
  1. The short answer to that is: no. It can be broken by malware (as in: won't run) or blocked (a replacement is attempted but after a reboot the original bad file is back), but that is about it. That being said, malware doesn't need to manipulate it, if it can just circumvent it. If a system is infected and a replaced system file has sufficient permissions to fool Windows into thinking it is legitimate (this typically is rootkit-level), you can run SFC all you want and Windows will report everything is fine, while in fact you can have one or more infected system files. So running SFC is not a malware scan nor should it be used as such.
  2. I will test this a bit next week, in the mean time you may want to check what the alert was for, because I highly doubt it was for 7zip and rather for the malware file(s).
  3. It depends completely on how this script is executed; in a "normal" malware scenario it will be dropped or downloaded, which will lead it to be blocked.
  4. Unfortunately I can't access that topic. I have checked the files and I suspect the issue is with the powershell script (mal.ps1). A script like that one is usually the result of being dropped by other malware or ending up on the system using exploit code, which will be blocked. To simulate that correctly in a test you would need to find out what malware dropped this script and run that instead.
  5. Can you share the password as well?
  6. Thank you for your feedback. Could you please send us the samples that weren't blocked so we can check out why they were able to encrypt files?
  7. Generally speaking if you see (A) or (B) behind a detection name it is a signature detection. If it is not there and the detection is not from the Surf Protection (URLs), then it usually is a heuristics detection.
  8. Yes, always use only one antivirus with real-time protection on to avoid conflicts. Windows 10 is smart enough to allow only one AV to be turned on though, so if you'd like to try the Emsisoft Anti-Malware trial, you could install it and it would automatically disable Windows Defender. Likewise if your trial were to expire, it would automatically turn on Windows Defender again.
  9. Hello Peter, Good to hear everything went well. That box just is an offer to install the actual Emsisoft Anti-Malware program so the computer will be protected in real time. The emergency kit scanner only will scan a computer for malicious files, it doesn't offer any actual protection.
  10. Merry Christmas to you both! Peter, it's completely normal to feel a bit confused when you are new to a forum, no need to apologize for that. If you have any other questions, please don't hesitate to ask!
  11. Hello Peter, It does not matter where you save the EEK files. If you have them on your desktop for example, you can simply copy/paste them to a flash drive. To download it, open Emsisoft Anti-Malware on any device and make sure your flash drive is plugged in. Click in the left pane on Scan and then scroll down to Emergency Kit Maker. Select the platform version (most modern computers are x64 so if you're not sure just try that) and select the location to save the files by clicking on the ... button next to "Save to:". If you want to save the files to your flash drive it's recommended to create a folder (for example named EEK) on the flash drive and use that. Finally click the Create Emergency Kit button to start the download. Now all you have to do is to start the scanner from the location you saved the files to. You don't need to reboot or anything and nothing will be installed. All necessary files are present in the location you selected when you created the emergency kit. If you want to remove the files later it's as easy as just deleting them (or the folder you put them in). You can also download the emsisoft emergency kit from here (please note you will have to extract the files yourself if you do this): https://www.emsisoft.com/en/home/emergencykit/ If you have any further question about this, please let me know.
  12. I can't comment on recommendations given by different security products since I don't know what their reasoning behind it is. You'll have to ask them about it.
  13. If only the service is enabled and windows otherwise is configured as default there is no way that this service running can allow anyone to connect to your computer's registry remotely. As far as I know you can only do that using this service if the computers are on the same network and visible to each other. If your computer is accessible to the entire internet that way you have much bigger problems than a possibility that an attacker might access your registry (they could get to all your files).
  14. Why would you want to disable it in the first place? It's a legitimate windows service. Unless you are a system admin just keep your windows services settings at the default level to ensure your OS functions properly.