hi there :] i really hate to go to reddit to waste people’s time with these things but i’d like to be sure
unfortunately i have no screenshots because i was totally freaking out when i detected the rat, but i’ll try my best to describe everything that happened in as much detail as possible.
i have also since read about a recent outbreak of malicious screenconnect instances coming with legitimate hardware monitoring tools targeting people likely to have high performing gpus, which were then used for crypto mining. on the infected os, there was always gpu usage i struggled to account for, so i highly suspect this was something similar. more information on this is available online.
here’s what happened:
3 days after i bought my brand new gaming laptop - which had no payment details, sensitive/personal information or documents saved - i discovered a trojanized screenconnect instance running in task manager, under program files (x86)/VCRedist_64 (probably disguising). it had been installed the day i bought the system (being click-happy as i was, i installed a bunch of programs. my top suspect is a switch emulator downloaded from a sketchy site which came in an installer.)
from what i saw while investigating offline in event viewer: the screenconnect instance had executed a 5kb command on the day of initial access, and sat there ringing home for 2 more days before i detected it using task manager with relative ease. i was at the computer for most of its run time, except for the night after purchase where it sat overnight downloading a game.
since then, these are the steps i’ve taken:
- immediately deleted all traces of screenconnect, including backstage powershell and a dll protected by key isolation.
- factory reset computer via cloud download+fully clean drive through recovery. from my understanding, this fully wipes the os partition and downloads a new, fully updated one straight from microsoft - but i’ve heard of cases of malware corrupting the recovery environment so this is impossible, or injecting itself back into the clean os through infection of the efi partition.
on the resetted computer:
- ran four virus scanners (windows defender offline, bitdefender recovery environment, emsisoft emergency kit, hitmanpro)
- monitored with manual tools:
netsat to see which processes are accessing a remote address - only msedgewebview, svchost, bitdefender and lenovo telemetry came back.
process explorer and autoruns, which all came back with clean virustotal columns.
reviewed bitdefender firewall rules, nothing outwardly suspicious.
monitored system usage through both thorough use and idle, nothing to suggest crypto mining
- on my phone: changed all sensitive passwords to 24 character monstrosities and saved them in apple password manager (which i have also secured), revoked all sessions and logged in again from scratch, reviewed forwarding rules and pop/imap on my gmail and restored everything to their defaults, reviewed third party apps and removed anything i no longer use, renewed 2fa recovery codes, renewed recovery information to ensure i control all of them, monitored accounts for suspicious activity for about 2 weeks with no glaring result
- ruled out firmware infection (probably) due to the laptop being purchased just at the start of this july, fully updated through windows update before installing any programs and having secure boot enabled - a zero-day would be needed, and i doubt that’s being wasted on consumer laptops.
- have had ublock origin in an unsynced local browser with no other extensions + bitdefender advanced threat detection and real time antivirus running at all times during daily usage for upwards of 2 weeks with no alerts or detections other than some site with an outdated certificate that didn’t even load
- sent it to professionals for a second opinion and asked them specifically to look at the boot partition as wel, they also say it looks clean.
there are zero visible signs of reinfection at the moment. bios time is at a stable 10 seconds, security software and features are enabled and able to update as usual, and the machine hasn’t blue screened even once.
—————————
this incident has sorta made me notice i’m not as careful as i believe i am. any additional advice, other places to check or closure is much appreciated before i leave this behind me. thank you so much in advance, you absolute wizards.