Author Topic: ==> Proc.Injected <==  (Read 99006 times)

0 Members and 1 Guest are viewing this topic.

Reply #45November 13, 2017, 01:20:15 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #45 on: November 13, 2017, 01:20:15 PM »
Hi BoxDirty,

Welcome to Adlice.com Forum.
Could you please attach RogueKiller report ? Are you doing active developement on your computer (VB or C#, especially) ?

Regards.

Reply #46November 13, 2017, 08:23:16 PM

BoxDirty

  • Newbie

  • Offline
  • *

  • 4
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #46 on: November 13, 2017, 08:23:16 PM »
Hey Curson,

Thanks alot and I uploaded the rogue killer report into the same google drive link. https://drive.google.com/drive/folders/1xg5bB5N04wjLh7kL2QVZJeDmUbSrnWd_
I wasnt sure what you wanted exactly so i added anything i could :D  and no no develpment is being done on that computer.

Reply #47November 13, 2017, 11:53:28 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #47 on: November 13, 2017, 11:53:28 PM »
Hi BoxDirty,

These are not legit injections. Your computer is infected.
Please open a new theard in the Malware removal section of the forum. I will then help you to get rid of it.

Regards.

Reply #48January 10, 2018, 10:08:34 AM

tienchien1

  • Newbie

  • Offline
  • *

  • 8
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #48 on: January 10, 2018, 10:08:34 AM »
When I create dump file. It has 6GB, can you help me?

Reply #49January 10, 2018, 01:12:51 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #49 on: January 10, 2018, 01:12:51 PM »
Hi tienchien1,

Welcome to Adlice.com Forum.
Could you please attach RogueKiller report with your next reply ?

Regards.

Reply #50January 10, 2018, 04:57:15 PM

tienchien1

  • Newbie

  • Offline
  • *

  • 8
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #50 on: January 10, 2018, 04:57:15 PM »
After deleting a time, it comes back again?

Reply #51January 10, 2018, 05:16:22 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #51 on: January 10, 2018, 05:16:22 PM »
I tienchien1,

PUMs detections are not not necessary malicious. Here, they match the MSN search engine and so, are legit.
The [Proc.Injected] detection is not present in your report. Could you please restart your computer, redo a scan and post the report with your next reply ?

Regards.

Reply #52January 12, 2018, 08:08:53 PM

tienchien1

  • Newbie

  • Offline
  • *

  • 8
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #52 on: January 12, 2018, 08:08:53 PM »
 I was confused. I'm running a new scan, now. And will give you logs files, in a few minutes.


Reply #53January 12, 2018, 09:04:42 PM

tienchien1

  • Newbie

  • Offline
  • *

  • 8
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #53 on: January 12, 2018, 09:04:42 PM »
I tienchien1,

PUMs detections are not not necessary malicious. Here, they match the MSN search engine and so, are legit.
The [Proc.Injected] detection is not present in your report. Could you please restart your computer, redo a scan and post the report with your next reply ?

Regards.

My computer starts acting oddly, it's not like what I know. From 2 years ago. I realized myself leaking information, but I still do not understand why, even though I reformatted my hard drive several times. Run multiple anti-virus software, all unable to detect this infection (only RogueKiller good) .

And now I know why. Thanks very much. And can help me remove this infection.

Reply #54January 13, 2018, 02:11:45 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #54 on: January 13, 2018, 02:11:45 PM »
Hi tienchien1,

The injected executable is Battlefield 1 main executable. Since it's a very large file, it will be difficult.
Did you install any mod or hacking software ? If that's not the case, I think it's Origin anticheat feature being detected.

Regards.

Reply #55January 14, 2018, 04:17:41 AM

tienchien1

  • Newbie

  • Offline
  • *

  • 8
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #55 on: January 14, 2018, 04:17:41 AM »
I do not think this is a false positive.  If this is really an infection, will Format and Settings solve the problem? Thanks so much.

Reply #56January 15, 2018, 01:40:48 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #56 on: January 15, 2018, 01:40:48 PM »
Hi tienchien1,

Yes, if it's an infection a full system reformat will get rid of it.
However, since this is the only injected process, I really doubt there is an infection.

Regards.

Reply #57March 05, 2018, 03:12:45 AM

Reply #58March 07, 2018, 02:23:04 PM

Curson

  • Global Moderator
  • Hero Member

  • Offline
  • *****

  • 2812
  • Reputation:
    100
    • View Profile
Re: ==> Proc.Injected <==
« Reply #58 on: March 07, 2018, 02:23:04 PM »
Hi Booky Banton,

Welcome to Adlice.com Forum.
These injections are legit, we will whitelist them as soon as possible.

Regards.

Reply #59April 04, 2018, 01:22:39 PM

Siddharth Kumar

  • Newbie

  • Offline
  • *

  • 2
  • Reputation:
    0
    • View Profile
Re: ==> Proc.Injected <==
« Reply #59 on: April 04, 2018, 01:22:39 PM »
Hi!
Today I ran a scan with Roguekiller and it found explorer.exe as Proc.Infected.
I'm giving link to the rogurkiller log and explorer.exe dmp file. Kindly analyse it asap and let me know
https://www.sendspace.com/file/0lc8zj
https://www.sendspace.com/file/py4l6w

Regards,
Siddharth