S
Straciuc Vlad
Guest
Hi, so I'm dealing with a very stubborn browser extension virus who, no matter how many times i delete it's folder which is located in "CrogramDatarreq" (it's a hidden folder, which says EMPTY but if you open it it contains 4 files, one called "backround" and 3 others i don't recall right now but i will tell you if neccessary because it will appear again.
I have tried malwarebytes, kaspersky, malware fox, and other anti viruses, i tried scanning these files on virustotal, i tried using developer mode on browser, get the extension ID, use search Local Disk C: and find the folders with the extension, deleting them only for them to reappear soon after.
My last desperate solution which i tried just now and made me come ask here for help (which i never do, i will stay hours and battle things myself using google and figuring it out, but now I just couldnt) Was downloading bandicam, with PROGRAM DATA and TASK MANAGER opened next to each other, so I can see the exact moment the folder is created, which process is using more resources so I can maybe track it somehow.
So i started it, and after 5 minutes there it was, the folder "Prreq" appeared right in front of me, so i went to quickly stop the video and watch it so i can see the exact time it all happened.
(Bandicam crashed but lets say it was just a coincidence, fortunately bandicam has a tool to fix corrupt videos so i was able to watch it after fixing it)
So I watch it, with the programdata window and task manager still opened on my screen, and I could see the folder "Prreq" on my pc, but I couldnt in the video, it literally skipped it, like it wasn't there, Im not even sure how that's possible since I thought Bandicam was supposed to record my screen so how could I see something Bandicam doesnt?
The thing you can actually see in the last let's say 10-15 seconds in the video (before I stopped it since the folder was created and it fulfilled it's purpose)
is that Chrome goes from like 5-10% percent CPU usage to around 44-48 % CPU usage, with me not touching it at all. Which is totally caused by the virus reinstalling itself or maybe starting to mine or steal my data I don't know.
So yeah i'm here because I'm desperate and I would appreciate any help. Cheers!
More...
I have tried malwarebytes, kaspersky, malware fox, and other anti viruses, i tried scanning these files on virustotal, i tried using developer mode on browser, get the extension ID, use search Local Disk C: and find the folders with the extension, deleting them only for them to reappear soon after.
My last desperate solution which i tried just now and made me come ask here for help (which i never do, i will stay hours and battle things myself using google and figuring it out, but now I just couldnt) Was downloading bandicam, with PROGRAM DATA and TASK MANAGER opened next to each other, so I can see the exact moment the folder is created, which process is using more resources so I can maybe track it somehow.
So i started it, and after 5 minutes there it was, the folder "Prreq" appeared right in front of me, so i went to quickly stop the video and watch it so i can see the exact time it all happened.
(Bandicam crashed but lets say it was just a coincidence, fortunately bandicam has a tool to fix corrupt videos so i was able to watch it after fixing it)
So I watch it, with the programdata window and task manager still opened on my screen, and I could see the folder "Prreq" on my pc, but I couldnt in the video, it literally skipped it, like it wasn't there, Im not even sure how that's possible since I thought Bandicam was supposed to record my screen so how could I see something Bandicam doesnt?
The thing you can actually see in the last let's say 10-15 seconds in the video (before I stopped it since the folder was created and it fulfilled it's purpose)
is that Chrome goes from like 5-10% percent CPU usage to around 44-48 % CPU usage, with me not touching it at all. Which is totally caused by the virus reinstalling itself or maybe starting to mine or steal my data I don't know.
So yeah i'm here because I'm desperate and I would appreciate any help. Cheers!
More...