Solved Privacy invasion - virus removal help

FusionPredz

New Member
Thread author
Apr 1, 2017
4
Pretty much after connecting to a wifi connection that is used by a community of flats i was infected by some kind of trojan/spyware which stole data/video and provided it to some user. I've rebooted by computer and done multiple scans but can't find anything.
I've noticed however through TCPview (an application that views firewall connections going outwards) that bytes are being sent through my 'system' and 'svchost.exe' which i found unusual. There were times that these processes got to 100,000 bytes (svchost.eve) and 20,000 bytes (system), whether or not these are normal process or if its just paranoia, nevertheless a second opinion would help

Btw I have never connected to this public wifi ever again however the infection has remained on my PC even after the system reboot.
I want to remove whatever has been installed on my computer and strengthen my firewall so this doesn't happen again.

Thanks
 

Attachments

  • Addition.txt
    35.9 KB · Views: 4
  • FRST.txt
    128.8 KB · Views: 3

FusionPredz

New Member
Thread author
Apr 1, 2017
4
Hello,


Your computer isn't infected.

You were saying?? How is my flatmate inbedding trojans on my PC if im not using peer-to-peer networking anymore?
Would you also happen to know specifically how to improve my firewall so this doesn't happen again?
 

Attachments

  • quaran.png
    quaran.png
    242.3 KB · Views: 9
  • Redirector.png
    Redirector.png
    257.7 KB · Views: 11

FusionPredz

New Member
Thread author
Apr 1, 2017
4
JS/Redirector.dg or whatever it was found on mcaffee.
After finding that and removing it, i downloaded bitdefender and continued finding a TCP connection via my youcam (my camera file) addressing to a strange IP.
(Mind you im using a university connection).
 

Attachments

  • BTS.png
    BTS.png
    36 KB · Views: 4

FusionPredz

New Member
Thread author
Apr 1, 2017
4
Whatever it is, its sending either my keylogged keys and/or history, files, and now even accessing my camera.
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
JS/Redirector is a Chrome cache detection, if you clean your cache, that would be gone.

Like I said, there is not keylogger on your computer, at least I don't see anything like that in your logs.
 
  • Like
Reactions: Sunshine-boy

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top