#caught a virus while playing

1 messages · Page 1 of 1 (latest)

fervent cave
#

tonight, Moscow time, I came across a player with software that gained access to my computer, I had to turn off the Internet to access the keyboard, which entered the data itself, I was also warned before turning off the PC that other users using the computer might be disconnected. Later, with the help of an antivirus, I found a couple of "host rat" files of the Rdpwrapper type that were infected. I also lost my admin rights. I solved the problem myself, but the situation upset me a lot. I haven't downloaded any software other than Battlebit in the last two weeks.

high pulsarBOT
#

To help others find answers, you can mark your question as solved via Right click solution message -> Apps -> ✅ Mark Solution

fervent cave
#

the incident occurred (last game) at ±2:10 Moscow time from an account under the nickname ZXCBOT (steam), I bought the game the same day. I can't say anything else

vocal quarry
#

huh
did you download anything sketchy at all?
could you DM me the host rat file if you still have it somewhere
i dont expect the game to have any RCE's specially due to dedicated servers

first time ive heard of anyone in BBR getting RCEed

common on call of duty tho (older titles)

#

also what was the profile picture or steamID of the ZXCBOT person?

#

also id highly suggest reinstalling your windows and formatting any drive connected to your PC

vocal quarry
#

his steamID
76561198999477314
incase you want to make a report to @viscid agate

#

also
did you ever visit any sketchy link?
download anything recently?

id suggest running an extension called noscript which disables javascript on untrusted websites (if a website is broken youll need to enable permissions on said site)

fervent cave
#

unfortunately, I didn't save the file, I deleted everything, I only have a picture of the antivirus screen

vocal quarry
#

hosts looks like the normal windows hosts file
maybe a sketchy link in there but shouldnt hurt anything
now the DLL and exe id be iffy on if they were spoofed (like how people used calculator to hide malware back in the day)

fervent cave
vocal quarry
#

yeah i personally cant see any RCE with battlebit itself

#

but report would be ideal to see

#

if you also have a spare USB
id suggest installing medicat USB
bunch of useful tools for repairing

fervent cave
vocal quarry
#

so it was a dormant virus then
not from BBR
probably from something way in the past

glacial cloud
#

а причем тут баттлбит то?

crystal violet
#

I wonder if this is related to what happened in Apex today?

vocal quarry
#

thats what im wondering

silver hull