Jump to content

Recommended Posts

Posted

Thanks,

I will read them and use autoruns tomorrow

 

  • Like 1
Posted

I have run autoruns now. So what is the next step? I don`t have the computer knowledge to know if something is suspicious or not.

 

Posted

You should have a new column in Your AutoRuns called Virustotal, that shows if that object line has some detections in that online service.

 

You can do the same with tool Process Explorer:

 

image.thumb.png.9b882e43993b385b29ea76b8f9f399b2.png

 

This tool shows and analyses all the processes running in Your system. THat will add also a new column for VirusTotal service, thay will show the possible detection of every service/process running.

Posted

In the Virustotal column all processes are showing 0/77 or error

 

  • Like 1
Posted

I use qbittorrent.

There are 6 processes marked with red color because they are not verified.

 

Posted

And are you using that torrent site to download contents?

 

Can You provide capture of those processes in red?

Posted

The 1st 3 are related to Bluetooth drivers, the 4th belongs to Kaspersky.

 

In 2nd pic, that red dll is clean.

 

What about Process Explorer info while reproducing the detection of that site?

  • Like 1
Posted

image.png

 

Did you enable this in Process Explorer? If so, please reproduce the detection with Process Explorer Running.

  • Like 1
Posted (edited)

Done that. But what do I look for?

All chrome processes show 0/77

Edited by 4343
  • Like 1
Posted

Don't check Chrome processes, but all running at that moment in Your system.

Posted

all processes are 0/76 or "A device attached to the system is not functioning " or "the system can not find the specific file"

 

  • Like 1
harlan4096
Posted

Check also if You have enabled notifications (in Your Chrome) for that site. 

 

Probably, one of Your legit apps is accessing to that site.

Posted

My notification settings are off, so no sites are allowed to send notifications

 

  • Confused 1
harlan4096
Posted

There is another user with a similar behavior:

 

 

Posted

I get the same warning if I click on a torrent on 1337x as well.

 

  • Like 1
harlan4096
Posted

That detection is correct.

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...