Employer Says My Home Pc Is Sending Out Scans - Eset Detects Nothing

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peewiglet, Jul 8, 2022.

  1. Peewiglet

    Peewiglet Private E-2

    HI there, and many thanks for any help.

    I use my home PC to work from home via a VPN.

    Earlier this week my employer (large organisation) contacted me to say they’d detected that my PC was sending out scans and disconnected me from the VPN.

    I’ve got Eset Internet Security installed (used NOD32 for years) and it had not raised anything. I immediately ran a scan and it found no threat, though it did say there were some folders it couldn’t get into. Today I downloaded Malwarebytes and did a scan. The scan was very quick and found nothing.

    I’m worried, though, that there may be something there. The IT tech at work told me they’d detected something he called a ‘web crawler’ which he said he hasn’t seen for many years.

    Can anybody suggest how I can go about trying to find out whether there is something wrong? I tried to download a trial version of Bitdefender but it wouldn’t install unless I uninstalled Eset first, which I didn’t want to do.

    Many thanks again for any help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Switch browsers and see if there is still a problem.
     
  3. Peewiglet

    Peewiglet Private E-2

    Thanks TimW.

    I’m using Chrome at the moment. I can switch, but unfortunately I’m not going to know now whether there’s still a problem as they’ve issued me with a laptop instead and so I’m not going to be connecting to them again with my home PC. That’s why I’m wondering whether there may be something on the market (I’m happy to pay for a good product) that might help me work out whether I”m infected. It’s quite a long time since I really looked at this area, and Malwarebytes was the thing that always seemed to be recommended. I wasn’t sure today whether it was still as good as before, though, as when I tried it it seemed to have become an AV, and the scan was very fast.

    Edited to add: Ah, I've just seen the thread in the other forum that makes a number of suggestions. I'll go and try those out.
     
  4. Peewiglet

    Peewiglet Private E-2

    Hi there. I've downloaded the programmes and produced the three logs. I'd be very grateful if you'd take a look and advise.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you know what this is:

    [Suspicious.Path (Potentially Malicious)] HWiNFO_163 (0) -- \??\C:\Users\ADMINI~1\AppData\Local\Temp\HWiNFO64A_163.SYS ->

    Would you also run and attach a log from ADWCleaner, please
     
  6. Peewiglet

    Peewiglet Private E-2

    Hi there, and thanks very much again for helping.

    I don't know what that is, but I'm not any kind of expert user so there would prolly be many things I wouldn't recognise.

    I've attached the ADWCleaner log, and again - thank you!
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's a temp folder, so right click start, click run and type in %temp% and remove all you find. Reboot and rerun RogueKiller and attach the log.
     
  8. Peewiglet

    Peewiglet Private E-2

    Hi there.

    I couldn't remove all the temp files it found. It said that 5 were open in Chrome and even when I closed Chrome it couldn't remove them. I've attached a picture of the message I got, showing the files, as well as the new RogueKiller log.

    Many thanks!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you allow RogueKiller to delete them? If not, do so now, reboot and rescan with Roguekiller.
     
  10. Peewiglet

    Peewiglet Private E-2

    Hi there. I've done that now and attached the log. It hasn't found anything. Do you think I can safely assume there is nothing more there, or is there some other process I should try? Many thanks.
     

    Attached Files:

  11. Eldon

    Eldon Major Geek Extraordinaire

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Possibly, but there is nothing showing that would indicate a web crawler.
    I think you are clean. However, it might be wise to uninstall all browsers but one ( save edge ) then run CCleaner, both files and registry. Then reboot and reinstall the browsers you prefer.
     
  13. Peewiglet

    Peewiglet Private E-2

    Thanks for all your help with this - I really appreciate it. I’ll do what you’ve suggested, and tomorrow I’ll ask the IT tech at work why he thought I had a web crawler. Will go and donate - thank goodness this site is here!
     
  14. Peewiglet

    Peewiglet Private E-2

    I've uninstalled Chrome (leaving only Edge) and then I d/loaded and ran CCCleaner. I couldn't immediately see how to choose both files and registry so I went for the registry check first. It came up with I think 135 issues. They may all be nothing but I don't know enough to tell. I couldn't see a way to generate a report so I've attached four screenshots that between them show the whole list. I've not deleted anything yet. Are you able to tell me whether this looks odd?
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There is no problem deleting the registry files. It will make a back up in case something goes wrong. Sometimes when you uninstall a program, you need to delete everything so that no issues return when you reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds