Question regarding Trojan attached to a TrueType Font File


Hello all,
 
I'll start off with saying first time to the forums and first time posting here (obviously). Any help on this matter is greatly appreciated.
 
With that out of the way, I had been starting to have some trouble with my system, software wise (specs will be listed at the bottom) about a month ago. Primarily in the realm of what I thought was a Windows 10 or even a BIOS issue. Heck, I even chased down new firmware on my mouse.
 
After a few "clean and fresh" installs of Windows 10 (including dumping the windows.old file), a flash of the BIOS, I  did have some issues with regaining some adming rights which I found odd. Though tonight I end up getting a Webroot Warning stating that I have a "bova2.dll" in my C:userappdatalocal emp    and it was under a folder named "js-kmp3d.tmp" . It contained 2 files, one named "RobotoRegular" (which is a .tff or TrueType Font File) and another named "WarHeliosCondC" (and is also a .tff file).
 
Webroot did its thing and alerted me, gave me options and I stopped the Trojan. However, upon checking the folder creation date, it was created 05/09/2017 and that was the last time it was modified as were the files. In case this thread gets a little dated, today is 05/26/2017 and this is after performing the clean and fresh installs of Windows 10.
 
On another note, when I started having issues with my PC, scanning my SSD and HD were my first go-to, I scanned it with both Webroot and Windows Defender,  but neither found anything malicious. I know that updates occur regularly, so in turn my scans were either daily or every other day for both, again neither yielding results.
 
So I guess my question is, how do I know it's gone or that something else isn't on my PC? Let alone after going through all that I did trying to chase a proverbial rabbit down a hole thinking the problem was something else, only to find it most likely was an infection that my anti-virus didn't pick up.
 
What can I do here?  As I typed this, I double checked my security settings (Shields and such), they are all set as high as I can set them.
 
 
 
 
Computer specs:
 
OS: Windows 10 Pro
CPU i7 6700k 4,0 Quad Core Skylake
GPU: EVGA Nvidia 980ti
MoBo: MSI z170a M7 gaming
RAM: Corsair 32gb DDR4
Storage: (Primary) 500gb SSD (Secondary) 1Tb HD
 
 
Again, thank you in advance.
 
Miner

3 replies

Userlevel 7
Hi Miner78
 
Welcome to the Community Forums.
 
Manythanks for a very clear description of your issue.
 
If you scans with WRSA are coming up clean then you should be in the clear. YOu have used a 2nd opinion scanner (not my favourite) and that has come up clear too.
 
However, if you are concerned still then what I would do is to Open a Support Ticket, providing a link to this thread so that the Support Team can review the position and see what & how they can assist you in relation to this. Only professional help will provide the reassurance that you need in these circumstances, in my view.
 
The service is free for users with an active WRSA subscription.
 
Hope that helps?
 
Regards, Baldrick
"If you scans with WRSA are coming up clean then you should be in the clear. YOu have used a 2nd opinion scanner (not my favourite) and that has come up clear too."
 
That's the only part that concerns me is that the weeks leading up to this I performed quite a few full system scans with Webroot and nothing popped up. Leaves one a little paranoid ya know.
 
I'll go ahead and open a ticket to see what they can do on their end.
 
Thank you for the help and direction.
 
Miner
Userlevel 7
Hi Miner78
 
I can understand when you say "Leaves one a little paranoid ya know." but then again it is a question of trust. And as far as WRSA is concerned...I trust, as it has never let me down.
 
Having said that no protection however good is 100% effective 100% of the time...not even WRSA, so a tad of of paranoia is not unhelpful. Hence the recommendation to get the Support Team involved...which wisely you have done.
 
If you have survived with no ill effects this long then I am fairly certain that you are clean but always best to check and a little more time waiting for the Support Team to come back (may be a little delayed due to the Memorial Day weekend) should not change that unduly.
 
Please let us know what they come back to you with/what the final outcome is...such feedback is extremely useful to us in looking to help others in the future/will be much appreciated.
 
Regards, Baldrick

Reply