Downloaded Horizon Zero Dawn from Ocean of Games (which I now know is suspicious). Installed everything, followed instructions, and the game ran okay. But then I noticed Windows Defender was disabled! Tried fixing it, but nothing worked. Read the megathread - turns out Ocean of Games is a risk. Downloaded Malwarebytes and found a ton of viruses. Should I just remove the viruses and keep Windows, or is a reinstall necessary? Worried about the consequences of keeping it.
Videos
Hi, I am Dave, I will help you with this.
Cracked games are wrapped in malware, they usually ask you to disable Defender when you are installing the game so they can install malware on your PC.
Be sure you have now deleted that game from your PC.
Click your Start Button, type regedit and hit Enter to open the Registry Editor.
Click View and make sure 'Address Bar' is turned on.
Paste this into the Address Bar at the top and hit Enter.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender
Please provide a screenshot of that Registry Editor page.
Hi Adam,
Please run a scan with Farbar Recovery Scan Tool (FRST) and share your logs.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
Note: If you are using Edge, SmartScreen may initially block the download.
Click on the three dots next to the warning and select Keep => Show more => Keep anyway.
- If your computer's language is not English, rename FRST64.exe to FRST64English.exe
- Run the tool, leave the default settings, and press Scan.
- Zip the logs, FRST.txt and Addition.txt, then upload to a cloud storage service like OneDrive, Google Drive or gofile.io
- Post the share link.
Share OneDrive files and folders - Microsoft Support
I downloaded a game from their website called "Tomato Way"
It comes with a VBE file that "decodes" the archive into an iso.
WHEN INFACT IT PUTS MALWARE ONTO YOUR PC AND LITERALLY RENAMES A DLL WHICH IS THE ISO TO AN ISO.
The VBE was encrypted, although was able to decrypt it with https://master.ayra.ch/vbs/vbs.aspx
Here is a screenshot of the VBE and what it does:
https://imgur.com/a/hCMhzly
If you don't believe me, download this game, decode the VBE and see for yourself.
The file it infects you with is another VBE, which opens a silent window of a malicious site (update your pc . info) (DO NOT VISIT)
https://imgur.com/a/ZPtqQH1
It first tries to do it in chrome. Then tries to do it in firefox.
Be careful when downloading games. If you get a vbs, or bat, make sure to decode it and READ WHAT IT DOES FIRST.
The actual game and installer appears to be clean though. It's just this "unpacker" that is infected.
Hi, I am Dave, I will help you with this.
Cracked games are usually wrapped with malware and can cause a ransomware attack, that is why they ask you to disable Defender, you should never do that.
Download this file:
https://1drv.ms/u/s!AvS3D6xKILoj335BRsl0Uomm1RD...
Then right click that file and select 'Run as Administrator'.
When that completes, restart (not shut down) your PC and then check if Windows Security is working correctly.
If not, your best option is to either reset or clean install Windows to ensure your system is malware free.
should i ignore the problem and install another virus protection or solve this thing?
where should i upload the defender.log file?
The app may have disabled Defender-related services or enabled some policy settings. You need to inspect the Microsoft Defender Antivirus service registration and other settings. Please download defender_diag.bat and run it as administrator.
The Batch file queries Defender-related settings/Policies and outputs the results to a log file. Upload this log to your OneDrive and share the link here.
(Note: Before uploading the log to your OneDrive, edit the defender.log file and remove your MSA ID if found.)