Trojan:Win32/Woreflint.A!cl Please Help

 FC1_Trainer


Joined:  17 July 2007
Posts: 44
发布25 January 2021 - 3:40 am
Hello Voobly team,

a couple of weeks ago I made the latest Microsoft Windows 10 update.
Since then the Microsoft virus software detects a Trojan/Virus in the Voobly software.
I tried to deinstall and reinstall voobly but this didnt fix the issue.
As soon as I reinstalled voobly, the microsoft antivirus dected the trojan again:
Trojan:Win32/Woreflint.A!cl

containerfile: C:\Program Files (x86)\Voobly\voobly-update.exe
file: C:\Program Files (x86)\Microsoft Games\Age of Empires II\age2_x1\anticheat2.dll
file: C:\Program Files (x86)\Microsoft Games\Age of Empires II\anticheat2.dll
file: C:\Program Files (x86)\Voobly\voobly-update.exe->(inno#000007)

Can anyone please help me?
I made screenshot via microsoft snipping tool attached.

Thank you.
附件:
snip2.JPG (文件大小: 75.05 KB)
snip1.JPG (文件大小: 70.61 KB)

链接 | 回复 | 引用
 hassan


Joined:  14 July 2007
Posts: 828
发布25 January 2021 - 10:03 am
Hello there.

Please read carefully this thread : https://www.voobly.com/forum/thread/333898 where everything is explained with solutions to try.

Don't hesitate if you need help about any step. Sorry for the inconvenience.
链接 | 回复 | 引用
 +chris@voobly

Voobly Team


Joined:  3 October 2007
Posts: 41361
发布25 January 2021 - 10:50 am
This post explains how to update the virus signatures of your Windows Defender:
https://www.voobly.com/forum/thread/333898/:1405739#post1405739
链接 | 回复 | 引用
 FC1_Trainer


Joined:  17 July 2007
Posts: 44
编辑25 January 2021 - 3:04 pm通过FC1_Trainer
Hello Hassan & Chris,

so I did the following:

run cmd as administrator and put in the following commands (copy & paste):
cd c:\Program Files\Windows Defender
MpCmdRun.exe -removedefinitions -dynamicsignatures
MpCmdRun.exe -SignatureUpdate

(it said signature updated sucessful)

afterwards I ran quick scan which still detected the "Trojan"
maybe this is due to old detections of previous searches?

Can you please try to help me here? I am no programmer or anything so please keep it as simple as possible.

Thanks.
链接 | 回复 | 引用
 +chris@voobly

Voobly Team


Joined:  3 October 2007
Posts: 41361
发布25 January 2021 - 3:39 pm
Which version of Windows are you running? Click Start > type "winver" > hit Enter.
链接 | 回复 | 引用
 FC1_Trainer


Joined:  17 July 2007
Posts: 44
发布25 January 2021 - 3:48 pm
please see attached, i always do all updates so it should be the latest version + i update windows defender at least once per day
附件:
snip3.JPG (文件大小: 35.64 KB)

链接 | 回复 | 引用
 arslan


Joined:  14 September 2011
Posts: 220
发布26 January 2021 - 11:04 am
Hi,

Instead of using :
Code:
MpCmdRun.exe -RemoveDefinitions -DynamicSignatures

Use:
Code:
MpCmdRun.exe -RemoveDefinitions -All
Quote:
Restores the installed Security intelligence to a previous backup copy or to the original default set


After this:
Code:
MpCmdRun.exe -SignatureUpdate

Once finished Restart your PC and scan again.
链接 | 回复 | 引用
 gerandtjan


Joined:  21 March 2020
Posts: 2
发布26 January 2021 - 4:21 pm
me sucedio algo parecido, pero se soluciono solo, despues de un par de dias, me dio la impresion que fue se habia colado un troyano y luego se dieron cuenta
链接 | 回复 | 引用
 FC1_Trainer


Joined:  17 July 2007
Posts: 44
发布27 January 2021 - 12:43 pm
It looks like the issue has been fixed now, although the code said rollback.... error (see attached)

Afterwards I rebooted my computer and deinstalled + reinstalled voobly without receiving notifications from microsoft antivirus/ Windows Defender. However the old virus messages and notification are still there.

Is there any way to get these out of the system or rechecked so that it updates them and does not consider them as threats anymore? 2nd and 3rd attachment.
Thanks for your help & support so far.

Best regards,

Matthias
附件:
26-01-2021.JPG (文件大小: 51.54 KB)
27-01-2021.JPG (文件大小: 43.46 KB)
27-01-2021-2.JPG (文件大小: 70.71 KB)

链接 | 回复 | 引用
 +chris@voobly

Voobly Team


Joined:  3 October 2007
Posts: 41361
发布27 January 2021 - 1:31 pm
Run this in an administrator command prompt
Code:
dism /online /cleanup-image /scanhealth dism /online /cleanup-image /checkhealth dism /online /cleanup-image /restorehealth sfc /scannow
链接 | 回复 | 引用
 FC1_Trainer


Joined:  17 July 2007
Posts: 44
发布28 January 2021 - 5:50 pm
i have done it, thanks for your help.

Hope, that everything is fine now.
附件:
snip29-01.2021.JPG (文件大小: 80.85 KB)




链接 | 回复 | 引用
[1]
从 1 11中展现11 - 0
讨论区跳转:
1用户正在阅读这个话题 (在过去的30分钟)
0成员1游客

Dân số hiện tại:
Photos of Voobly Players (51 Người chơi)
This is War 2016 (34 Người chơi)
1.6 reward campaing (28 Người chơi)
TIW 2020 Map votes (26 Người chơi)
TDII (19 Người chơi)
Chủ đề tích cực nhất tuần qua: