Jump to content

Soul

Members
  • Posts

    14
  • Joined

  • Last visited

About Soul

  • Rank
    Newbie
    Newbie

Profile Information

  • Location
    USA
  1. i can see it while using fiddler. It keeps making request to that api.chatting url. Something weird is that before it was always red meaning it cant reach im guessing but now its status 200 so im assuming the host is up now? As soon as i stop the powershell from task manager, the links stop
  2. ahhhh and yea, when using procexp, i can go to the powershell and the netowkr tab and it shows there is a connection establish to a ip. Would it work if i were to block that ip directly on my router?
  3. interesting. Yea it seems hard to find as im running various scans and deep scans, manually deleting files but not having any luck finding the malicious files.
  4. there seems to be nothing related to powershell on autorun.
  5. So what would be the necessary steps in order to eliminate this?
  6. sorry for the late reply. Interestingly enough, this was fixed for last 2 days or so and just started again today. Powershell opened and is doing the same thing. I just saw this so i am updating vmware right now.
  7. I just installed ESET again and now running the log collector
  8. I did but i removed because i wanted to see if the script it blocked was permanent or temp and i couldnt turn it off so i uninstalled it and the script executed.
  9. yea i could do that. Also to add to this, I restarted my computer and ESET did block the script that was running but i want more of a permanent solution if thats possible. To fully remove whats even initiating that script to open to begin with
  10. sorry im a little confused. Which log file should i be giving you. I scanned the system_log file with eset and it said it was fine.
  11. It is exactly the same stuff above. Exact same ip addresses and the api.chatting thing. Exact same shell command that is causing powershell to run in the background. What Itman posted is the shell command being executed.
  12. I am going through the exact same thing and if this is indeed malicious, what could be done to remove it? Could you possible give a solution please? thank you!
×
×
  • Create New...