Author Topic: ==> Proc.Injected <==  (Read 28657 times)

0 Members and 1 Guest are viewing this topic.

Reply #45November 13, 2017, 01:20:15 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #45 on: November 13, 2017, 01:20:15 pm »
Hi BoxDirty,

Welcome to Adlice.com Forum.
Could you please attach RogueKiller report ? Are you doing active developement on your computer (VB or C#, especially) ?

Regards.

Reply #46November 13, 2017, 08:23:16 pm

BoxDirty

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #46 on: November 13, 2017, 08:23:16 pm »
Hey Curson,

Thanks alot and I uploaded the rogue killer report into the same google drive link. https://drive.google.com/drive/folders/1xg5bB5N04wjLh7kL2QVZJeDmUbSrnWd_
I wasnt sure what you wanted exactly so i added anything i could :D  and no no develpment is being done on that computer.

Reply #47November 13, 2017, 11:53:28 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #47 on: November 13, 2017, 11:53:28 pm »
Hi BoxDirty,

These are not legit injections. Your computer is infected.
Please open a new theard in the Malware removal section of the forum. I will then help you to get rid of it.

Regards.

Reply #48January 10, 2018, 10:08:34 am

tienchien1

  • Newbie

  • Offline
  • *

  • 7
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #48 on: January 10, 2018, 10:08:34 am »
When I create dump file. It has 6GB, can you help me?

Reply #49January 10, 2018, 01:12:51 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #49 on: January 10, 2018, 01:12:51 pm »
Hi tienchien1,

Welcome to Adlice.com Forum.
Could you please attach RogueKiller report with your next reply ?

Regards.

Reply #50January 10, 2018, 04:57:15 pm

tienchien1

  • Newbie

  • Offline
  • *

  • 7
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #50 on: January 10, 2018, 04:57:15 pm »
After deleting a time, it comes back again?

Reply #51January 10, 2018, 05:16:22 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #51 on: January 10, 2018, 05:16:22 pm »
I tienchien1,

PUMs detections are not not necessary malicious. Here, they match the MSN search engine and so, are legit.
The [Proc.Injected] detection is not present in your report. Could you please restart your computer, redo a scan and post the report with your next reply ?

Regards.

Reply #52January 12, 2018, 08:08:53 pm

tienchien1

  • Newbie

  • Offline
  • *

  • 7
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #52 on: January 12, 2018, 08:08:53 pm »
 I was confused. I'm running a new scan, now. And will give you logs files, in a few minutes.


Reply #53January 12, 2018, 09:04:42 pm

tienchien1

  • Newbie

  • Offline
  • *

  • 7
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #53 on: January 12, 2018, 09:04:42 pm »
I tienchien1,

PUMs detections are not not necessary malicious. Here, they match the MSN search engine and so, are legit.
The [Proc.Injected] detection is not present in your report. Could you please restart your computer, redo a scan and post the report with your next reply ?

Regards.

My computer starts acting oddly, it's not like what I know. From 2 years ago. I realized myself leaking information, but I still do not understand why, even though I reformatted my hard drive several times. Run multiple anti-virus software, all unable to detect this infection (only RogueKiller good) .

And now I know why. Thanks very much. And can help me remove this infection.

Reply #54January 13, 2018, 02:11:45 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #54 on: January 13, 2018, 02:11:45 pm »
Hi tienchien1,

The injected executable is Battlefield 1 main executable. Since it's a very large file, it will be difficult.
Did you install any mod or hacking software ? If that's not the case, I think it's Origin anticheat feature being detected.

Regards.

Reply #55January 14, 2018, 04:17:41 am

tienchien1

  • Newbie

  • Offline
  • *

  • 7
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #55 on: January 14, 2018, 04:17:41 am »
I do not think this is a false positive.  If this is really an infection, will Format and Settings solve the problem? Thanks so much.

Reply #56January 15, 2018, 01:40:48 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #56 on: January 15, 2018, 01:40:48 pm »
Hi tienchien1,

Yes, if it's an infection a full system reformat will get rid of it.
However, since this is the only injected process, I really doubt there is an infection.

Regards.

Reply #57March 05, 2018, 03:12:45 am

Reply #58March 07, 2018, 02:23:04 pm

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2033
  • Reputation:
    75
    • View Profile
Re: ==> Proc.Injected <==
« Reply #58 on: March 07, 2018, 02:23:04 pm »
Hi Booky Banton,

Welcome to Adlice.com Forum.
These injections are legit, we will whitelist them as soon as possible.

Regards.

Reply #59April 04, 2018, 01:22:39 pm

Siddharth Kumar

  • Newbie

  • Offline
  • *

  • 2
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #59 on: April 04, 2018, 01:22:39 pm »
Hi!
Today I ran a scan with Roguekiller and it found explorer.exe as Proc.Infected.
I'm giving link to the rogurkiller log and explorer.exe dmp file. Kindly analyse it asap and let me know
https://www.sendspace.com/file/0lc8zj
https://www.sendspace.com/file/py4l6w

Regards,
Siddharth