Solved Possible Network Intrusion.

Status
Not open for further replies.
Hello!

After giving malwarebytes forums my FRST logs they said they noticed Kaspersky running from the temp folder. This would align with what Practical Response said.

I did notice show file extensions get turned off randomly then turned back on. Or well Kaspersky said they got turned off. Not sure if it’s a bug or something but 6 antivirus scanners came back clean and I’m on malware removal forums.

Hello!

After giving malwarebytes forums my FRST logs they said they noticed Kaspersky running from the temp folder. This would align with what Practical Response said.

I did notice show file extensions get turned off randomly then turned back on. Or well Kaspersky said they got turned off. Not sure if it’s a bug or something but 6 antivirus scanners came back clean and I’m on malware removal forums.
There are for some reason weird Kaspersky drives installed when Kaspersky isn’t installed.
 

Attachments

  • IMG_0038.jpeg
    IMG_0038.jpeg
    365.5 KB · Views: 158
Yes, this is a common behavior of KVRT, it generates random names when running in a system, to avoid possible malware running to identify and try or kill it :)
 
Status
Not open for further replies.