Backdoor on my pc (Solved)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Ichigo
    PCHF Member
    • Dec 2022
    • 61

    #61
    Here’s the fixlog but does it mean that I still had the backdoor on my computer or was it for something else?

    Comment

    • Ichigo
      PCHF Member
      • Dec 2022
      • 61

      #62
      Im currently scanning with eset scanner

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #63
        The fix was just me being thorough, there were remnants of the infection …

        But as I suspected, there is a bit of another piece of malware, that has been detected. I had FRST check it at virus total.



        We will need to remove it with FRST. It is this file, the last thing I suspected from your logs.
        [COLOR=rgb(184, 49, 47)]
        c:\users\pcgamer\appdata\roaming\modestmenu\secret scan.exe

        Here is your fixlist. Run this when Eset is done, Eset is a bit aggresive, so it may detect minor things, no need to be alarmed if the detection level is high.[/COLOR]

        Comment

        • Ichigo
          PCHF Member
          • Dec 2022
          • 61

          #64
          okay

          Comment

          • Ichigo
            PCHF Member
            • Dec 2022
            • 61

            #65
            what are the consequences of this malware?

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #66
              What you already know, they had access to your accounts of social media, possibly your banking information what ever pictures files etc you had on your machine, a fresh format is not going to change that, the malware is gone now. It is up to you to change all your passwords and notify your bank that your computer was infected. From this point on I’d stay away from torrents.

              Comment

              • Ichigo
                PCHF Member
                • Dec 2022
                • 61

                #67
                I meant what are the consequences of this one
                c:\users\pcgamer\appdata\roaming\modestmenu\secret scan.exe

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7041

                  #68
                  If you are asking about the latest detection from VirusTotal. I am not sure it is the last file I thought might be a problem, there is not much information about it. It may well be safe, but if two or more engines detect something, then I remove it. Unless it is known to be safe to the user.

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #69
                    These scanners do get things wrong sometimes. I just play things on the safe side.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #70
                      @Ichigo Do you have questions about anything else, or do you consider the issue resolved?

                      Comment

                      • Ichigo
                        PCHF Member
                        • Dec 2022
                        • 61

                        #71
                        Here is the eset log (this was before the FRST fix)

                        Comment

                        • Ichigo
                          PCHF Member
                          • Dec 2022
                          • 61

                          #72
                          Originally posted by Malnutrition
                          @Ichigo Do you have questions about anything else, or do you consider the issue resolved?
                          I don’t have any question if you are 100% sure the backdoor isnt on my computer anymore, thank you so much for the help! Have a good day.

                          Comment

                          • Ichigo
                            PCHF Member
                            • Dec 2022
                            • 61

                            #73
                            Actually I got a question

                            Comment

                            • Ichigo
                              PCHF Member
                              • Dec 2022
                              • 61

                              #74
                              [ATTACH type=“full”]11100[/ATTACH]
                              I used to use the clipboard, but now I can’t activate it

                              Comment

                              • Ichigo
                                PCHF Member
                                • Dec 2022
                                • 61

                                #75
                                it says in yellow that some of these settings are hidden or managed by my organization

                                Comment

                                Working...