Jump to content

Virus Undetected - Backdoor:PHP/Dirtelti.MTF


Recommended Posts

Spare_Profile7853
Posted

I have the virus go on scheduled scan and automatic updates, but it never detected Backdoor:PHP/Dirtelti.MTF

Quote

This threat can perform a number of actions of a malicious actor's choice on your device.

 

Devices affected by this threat might exhibit the following unexpected behavior:

  • Slow performance
  • Presence of added or modified files
  • Changes in desktop settings
  • Freezing or crashing
  • Diminished storage space

I recently decided to update Microsoft Defender Antivirus and do a Full Scan. It detected the trojan!

Apparently, I have been experiencing random crashes and BSOD so I'm suspicious. Why did Kaspersky didn't detect the virus?

Also, it's constantly detecting that my database is not updated.

image.png.9771d311263463747ad07645d2688d51.png 

 

What is it that I don't understand here? Why is Kaspersky on my device like this? 

Posted

Welcome to Kaspersky Community.

 

Can You provide the detection details of Microsoft Defender? also provide version of K. produco installed.

  • Like 1
Spare_Profile7853
Posted

Here is the detection of Microsoft Defender

image.thumb.png.240bb32e460f3075e4a448a4459ccc45.png

 

Here's the Kaspersky scans

image.thumb.png.6858a92197c8ebb4ae2a3ce92a771c4e.png

 

Installed K Premium and VPN

Posted

image.png.6ab049d5be113651259ed73c7f4b648e.png

 

Ok, but no info of the file name, and where was located 🤔

Spare_Profile7853
Posted

Ooh, good point. I thought of not including it for privacy. Here you go!

image.thumb.png.5aacaf6f6d83e36ba0845f3f1f107990.png

If the virus is doing something in the background, regardless of where the file is saved, wouldn't Kaspersky detect its activity anyhow?

  • Like 1
Posted

Looks like the detection was not active, since it is in G: drive, maybe an external device? also it is a compressed file in format .bz2, usually used in Linux systems.

 

And looks like this file was taken from there, but an older version:

 

https://www.php.net/releases/7_4_4.php

 

https://www.php.net/downloads.php

 

and I would bet that is not malware, but a MD false positive 🤔

  • Like 1
Spare_Profile7853
Posted

I see. So, it shouldn't be affecting my system?

I'm just too anxious about it.

My laptop has been getting BSOD, lags and super slow prior to the removal.

What is the explanation for the database though?

  • Like 1
Posted

Was there an external drive? did you download that file?

 

The BSOD maybe caused, probably by other system issues, You can find the cause with a free tool called WhoCrashed, and setting in Your Windows, the full memory dump, if there is a new BSOD.

 

Also, run a ScanDisk of Your main drive C :

  • Like 1
Spare_Profile7853
Posted

Thanks for the suggestion but I paid for Kaspersky thinking it would help all with the issues I have raised here.

I have tried all the Windows tools like CHKDSK, ScanDisk, SFC Scannow, and DISM but they do not detect any error.

Maybe you are right that a file on my external drive might not be the problem. My laptop is a mess. Slowdowns, freezes, crashes, blue screens... it's happening. 

 

Shouldn't Kaspersky be able to find and stop something like that? 

 

Why would it report a false positive database update? image.png.9771d311263463747ad07645d2688d51.png

 

Spare_Profile7853
Posted

I have read those before posting here in the forum.

Apparently, Kaspersky wouldn't update when it is connected on its own VPN server. I need to turn VPN and Kill Switch for the update. I need to turn off Kill Switch for Kaspersky VPN to connect too.

Why would it block its own app when connected on its own VPN server?

  • Confused 1
Posted

If You are in US or use a US node in VPN, then it's normal, due to the ban.

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...