Jump to content

DanielLC

Members
  • Posts

    8
  • Joined

  • Last visited

Everything posted by DanielLC

  1. Ah my bad for jumping the gun. The scan shows 0 threats found but unfortunately there doesnt appear to be a log file. I know this is a different matter but their network program says that my network may be compromised. Not too sure what to make of it.
  2. Looks like I had something preventing windows defender from working properly. I've been suspecting this since when I would turn off malwarebytes, a notification would appear warning me that both my anti-virus and windows defender were deactivated. But when I would go to the windows defender page, it would say that it was indeed running. I've also ran this scan before and nothing was detected. This is spooky haha. Here is the log. msert.log
  3. My bad for the double post but I`ve just noticed that it`s possible to export the actual virus file summary. Here they are for both opening task manager while a game is running and trying to access the IP through firefox (dumb, I know.) GameTrojanExport.txt FirefoxTrojanExport.txt
  4. Hello everyone, I would like to begin by saying that this website is amazing. It has led me to find out why my PC performance is so poor in less than an hour when I have been troubleshooting it for months, so thank you. I've been having game performance issues for a few months now. I tried dozens upon dozens of troubleshooting methods without a solution in sight until I noticed something. When I was running a game and opened task manager, my CPU usage would instantly drop from 99% to 50-60%. This reminded me of something I read online about bitcoin miners hiding itself as you open task manager. What I didn't actually know was that it was possible for the virus to camouflage itself under the game. I started by installing Malwarebytes and AdwCleaner as instructed by @AdvancedSetupin other user's threads. I did a scan with Malwarebyte with rootkit scan enable in the settings yet nothing was found. After scanning with ADWcleaner, two ''PUP.OptionalLegacy'' files were found which I believe are irrelevant. Feeling discouraged after thinking I had found finally found a fix, I decided to play a bit of a game thats easier to run with the performance issues. Out of curiosity, I opened task manager and the first thing I see is Malwarebyte warning me about my game being a trojan. I do a bit of research on the matter and most search results foolishly chalk it up to being a false-positive. I looked at the summary of the programs findings and was given an IP which I will not put here since it directly leads to a MWB warning saying the link/IP is a trojan. I then used a geographical IP location finder and it told me that the location is in Georgia, Kvemo Kartli. There is no way this is a false-positive since the company who made the game is located in Canada, Vancouver. I also never joined a multiplayer server and only stayed on the main menu screen so there is no way that a P2P false-positive could have happened. This leads me to believe that there is an infected file on my computer which acts as a proxy between my PC and a website. It camouflages itself under whatever video game I'm playing to act as if the cause of the high CPU usage was the game. What Malwarebytes picked up on is the command which tells the file or site to pause the mining when I open TM. Here are all the required scans 1. The scan is unable to spot the virus but shows up in detection history. This happens everytime I open taskmanager while a game is running. Here is the file summary clearly showing that the virus is concealing itself as my game, the IP address geographical location and the browser page warning. 2. AdwCleaner detects nothing. Please note that this is all speculation on my part. I have next to no knowledge in this type of stuff and I may be wrong. What do you think? Thank you. MWBscan.txt RPT detection trojan.txt Addition.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.