Instalar Steam
iniciar sesión
|
idioma
简体中文 (chino simplificado)
繁體中文 (chino tradicional)
日本語 (japonés)
한국어 (coreano)
ไทย (tailandés)
Български (búlgaro)
Čeština (checo)
Dansk (danés)
Deutsch (alemán)
English (inglés)
Español de Hispanoamérica
Ελληνικά (griego)
Français (francés)
Italiano
Bahasa Indonesia (indonesio)
Magyar (húngaro)
Nederlands (holandés)
Norsk (noruego)
Polski (polaco)
Português (Portugués de Portugal)
Português-Brasil (portugués de Brasil)
Română (rumano)
Русский (ruso)
Suomi (finés)
Svenska (sueco)
Türkçe (turco)
Tiếng Việt (vietnamita)
Українська (ucraniano)
Comunicar un error de traducción
It might still use less your hardwares but the infection is still there.
I think it's important that we know where this is coming from since I only use my desktop for gaming. Hardly any internet browsing at all except for school related stuff. Any real internet tasks happen on my MacBook.
Either way, very much appreciated OP.
No. It's gone. Manually deleting and running a scan will completely remove it. No malware author adds a "surrender" feature to their stuff. It either runs or it's gone.
One scan hardly eradicated all.
You'd be surprised how a virus can regenerate or have a facade and run something else more hidden.
The author may have updated it since to use different folders, but ordering by date will still allow you to easily find what folders contain the recent infection. If "winrar" contains Steam.exe, you'll know it's fake. AFAIK Winrar doesn't install to that folder.
Mine was in appdata\adobe\
None of my antivirus was able to detect the files even when I scanned the directory it was located in. So that's disturbing. But deleting the files as OP suggested solved the issue for me.
I don't know if this was posted before but i will say this.
Malware came to my computer with ClassicShell program for win 8.1
And it installed virus here: C:\Users\User_Name\AppData\Roaming\ClassicShell\googleupd.exe
My Malwarebytes Anti-Malware v2 free detected it as RiskWare.BitMiner.
I quarantined it so if anyone want's that exe i shall send them for analyze.
I Also deleted files from steam folder in roaming like OP mentioned and system32\tasks file
Your rig like you call it is just not protected well.
I wanted to add that I found mine in : AppData\Roaming\BSplayer\CODEXi\Steam Client
and the win32 task was : Steam_x64-S-2-106-91
I didnt have the Reversed folder and it wasn't a 'steam.exe' but a command and many dlls, so I deleted the whole CODEXi folder and the task
I also spent 3 days looking at what was wrong with my GPU.. I'm so glad I've found that thread! Thanks again for all the help!
If you have so many suspicious files, better do a full scans again and again instead of manual delete.