Jump to content

Recommended Posts

Posted

Thanks,

I will read them and use autoruns tomorrow

 

  • Like 1
Posted

I have run autoruns now. So what is the next step? I don`t have the computer knowledge to know if something is suspicious or not.

 

harlan4096
Posted

You should have a new column in Your AutoRuns called Virustotal, that shows if that object line has some detections in that online service.

 

You can do the same with tool Process Explorer:

 

image.thumb.png.9b882e43993b385b29ea76b8f9f399b2.png

 

This tool shows and analyses all the processes running in Your system. THat will add also a new column for VirusTotal service, thay will show the possible detection of every service/process running.

Posted

In the Virustotal column all processes are showing 0/77 or error

 

  • Like 1
harlan4096
Posted

Are You using torrent tools?

 

Posted

What do you mean? If I use a torrent client?

 

Posted

I use qbittorrent.

There are 6 processes marked with red color because they are not verified.

 

harlan4096
Posted

And are you using that torrent site to download contents?

 

Can You provide capture of those processes in red?

harlan4096
Posted

The 1st 3 are related to Bluetooth drivers, the 4th belongs to Kaspersky.

 

In 2nd pic, that red dll is clean.

 

What about Process Explorer info while reproducing the detection of that site?

  • Like 1
Posted

I don`t understand your last question

 

harlan4096
Posted

image.png

 

Did you enable this in Process Explorer? If so, please reproduce the detection with Process Explorer Running.

  • Like 1
Posted (edited)

Done that. But what do I look for?

All chrome processes show 0/77

Edited by 4343
  • Like 1
harlan4096
Posted

Don't check Chrome processes, but all running at that moment in Your system.

Posted

all processes are 0/76 or "A device attached to the system is not functioning " or "the system can not find the specific file"

 

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...