[SOLVED] I'm 90% Sure I have a trojan. Please help!

Solution
my computer is infested with virus. i tried to think of a joke for that one but couldn't.
The way you do an "investigation" with stuff like this is to do a full forensic clone copy off to some other isolated hardware.
Then, on this main system....you wipe it clean.

Any playing around and "GOTCHA!" can continue to happen under controlled conditions on the other box.

Unless you like playing fast and loose with with your data, on a system that is known to be compromised.

sebastianredwood

Reputable
Mar 12, 2018
43
1
4,535
Personal computer
Windows 10

I completely wiped the hard drive and solid state drive, at least I think I did.
I chose the wipe everything option before hand and it took a few hours.

I found a folder named "services" with Verisign.bmp located inside.
Google said it's a trojan so I simply deleted it. I haven't found much else other then literally 90c cpu temperatures with 100% cpu usage.
 

USAFRet

Titan
Moderator
Personal computer
Windows 10

I completely wiped the hard drive and solid state drive, at least I think I did.
I chose the wipe everything option before hand and it took a few hours.

I found a folder named "services" with Verisign.bmp located inside.
Google said it's a trojan so I simply deleted it. I haven't found much else other then literally 90c cpu temperatures with 100% cpu usage.
"I chose the wipe everything option"

You did this from within the running Windows instance?
That is NOT the same as a full clean install.

There, you boot from a Win 10 USB, and DELETE all existing partitions in the process.
 

sebastianredwood

Reputable
Mar 12, 2018
43
1
4,535
its not letting me post pictures.


also, I don't really want to reset my computer again because it took me the entire day to customize it the way I like not to mention the 6 hours of wiping and reinstalling...
I'd like to get to the bottom of this though.
 

sebastianredwood

Reputable
Mar 12, 2018
43
1
4,535
I live alone so there should be no one but myself that has access to my computer.
Check these 2 pics out... nevermind... tomshardware is making this extremely frustrated. I basically have a screenshot of my task manger showing 1% cpu usage and then another half a second screenshot of it being at 98% cpu usage. Website won't let me share that though.
 
Deletion of partitions takes but a second within the Win10 USB installer...

Installation of WIn10 takes about 5 minutes with any SSD and CPU made within the last 4 years...

Drivers packages, then apps, then WIndows updates...

Or, chase malware 3-6 hours, then up doing the above anyway. :)

"Best to nuke the site from orbit; it's the only way to be sure!"
Corporal Hicks, Colonial Marines
 

deesider

Honorable
Jun 15, 2017
298
135
10,890
You could try running a linux install from a bootable usb, and scan the other drives from there - you may be able to eradicate the culprit without formatting everything (although that is the 'best' option).
 

sebastianredwood

Reputable
Mar 12, 2018
43
1
4,535
Deletion of partitions takes but a second within the Win10 USB installer...

Installation of WIn10 takes about 5 minutes with any SSD and CPU made within the last 4 years...

Drivers packages, then apps, then WIndows updates...

Or, chase malware 3-6 hours, then up doing the above anyway. :)

"Best to nuke the site from orbit; it's the only way to be sure!"
Corporal Hicks, Colonial Marines
It took me hours last time..