[SOLVED] How can I make sure that my PC hasn't been compromised (Remote Hacking) ?

Page 2 - Seeking answers? Join the Tom's Hardware community: where nearly two million members share solutions and discuss the latest tech.

Vellaura

Reputable
Nov 30, 2020
194
10
4,585
Hey all!

I was using discord web on chrome incognito. While I was browsing on a AI Art Server I got some dm's related to a discussion I was having, relevant to the type of art I was interested in. I got sent some cool images and downloaded a couple onto my harddrive. They where wepb files.

I already had kaspersky free installed and have never had any issues with it. I've been using Kaspersky for 10+ years. Paid and non. And it always IMMEDIATELY picks up on sus files.

Anyways. While I was chilling maybe an hour or more later I decided to open up OBS Studio to do some configuring and randomly my PC got SUPER slow. My mouse was either incredibly laggy or delayed or it was being controlled, at least it felt that way. I noticed my Kaspersky icon had turned Red, which usually indicates some kind of issue.

The cursor felt like it was making its way to the bottom right settings. I paniced when I saw the red kaspersky icon and immediately restarted my PC.

Upon logging back in everything was perfectly fine, nothing looked out of place, missing etc. I immediately did a full scan on Kaspersky. Then to be extra safe I downloaded Malwarebytes and did another scan. I scanned the files I downloaded, nothing (I'v since deleted them). I scanned it again on both with the internet disconnected. I did some research on youtube and did some command prompts for suspicious IP's, nothing, no new programs installed, nothing new on startup.

I checked the Kaspersky logs to see what had happened. Nothing. Just normal log stuff.

I am completely bewildered. Did my PC just have a mega fart and I freaked out thinking I was infiltrated?

What are some other checks I can do to make sure my PC isn't exposed, compromised or vulnerable. Or at least be able to figure out wtf happened through some kind of logs.

Any information is appreciated.

Thank you :)
 
I just had one last request. Would you be able to help me with recommending the Top 3 file/url scanning websites.

You know the ones where you upload a file or link and it spits out whether its malicious or not. I only know of the Kaspersky one.
The VirusTotal already mentioned in this thread checks with all of them.

If Kaspersky has been banned from selling its software or providing any updates in the United States since September 29, 2024, where have you been getting updates from?
 
  • Like
Reactions: Vellaura
The VirusTotal already mentioned in this thread checks with all of them.

If Kaspersky has been banned from selling its software or providing any updates in the United States since September 29, 2024, where have you been getting updates from?
Oh ok thank you! I will use virus total.

I am based in Australia matey. Maybe thats why? Also I think I saw they where based in Germany now?

I remember hearing about that whole debauchle but never looked into it because it felt political. As I mentioned I have been a Kaspersky user since 2010 and its worked and protected me like a dream since then which is why I didn't think much of it.
 
Ah, then it should still work for you, but you won't find too many here familiar with its current iteration. Over here all Kaspersky installs automatically uninstalled themselves and installed Pango AV without asking.

Moscow-based Kaspersky was banned by the Australian government beginning April 1, 2025, but that's only on government computers, much like how the US government banned use on their government computers back in September 2017, both civilian and military.
 
  • Like
Reactions: Vellaura
Ah, then it should still work for you, but you won't find too many here familiar with its current iteration. Over here all Kaspersky installs automatically uninstalled themselves and installed Pango AV without asking.

Moscow-based Kaspersky was banned by the Australian government beginning April 1, 2025, but that's only on government computers, much like how the US government banned use on their government computers back in September 2017, both civilian and military.
Yeah thats totally understandable. It seems to have had a impact globally.

But I did do some reading up on it and found arguments from both sides like Kaspersky denying connections, basing operations in Switzerland or even inviting experts to look into their source code. What is true, what is bs, who really knows. Like I said its very political and thats another thing entirely. Also probably another discussion for another post aha.
 
Alright guys so I had a bit of a crazy idea. Because the lack of a logical conclusive result was really pissing me off.

So what I did was go right back to the bloody crime scene. Where it all began.

I found the discord server and scrolled through the entire history up until I found the dude, clicked on his icon, reentered the dm's and found the images. Initially I clicked and right clicked to get the image address. I then submitted the image address on Virus Total, completely clean. I did the same for the other 2 images, completely clean. But that wasn't enough (because I'm a madman). I redownloaded the webp file itself and reuploaded to Virus Total, just to make sure it wasn't scanning something unrelated or irrelevant, absolutely clean.

I also had a chat with a mate and he told me the file sent on discord is no longer the original file anyways as it goes through Discord's scanning process thing and then it produces the result the user sees. As a added layer of protection. Call it coping but its another thing that would rule it out. Not entirely but its something and its more peace of mind for me.

My PC must've just had a brainfart when I launched OBS, turns out it was outdated as well. I've since updated it. There where no logs on my AV because there was nothing to log, the red icon must've been a stability notification. And that one PUP that was in my system was probably there from the beginning and as mentioned a False Positive. But it's gone anyways. I don't think it would have been a important file for windows?

If I run into the same issue with the PC slowing to a crawl I'll make another post and try figure it out from a hardware/software issue pov.

I want to thank everyone for helping out, providing solid information and the guidance. This whole ordeal has been a giant learning lesson. I feel less anxious as I understand it more. I feel like I gained a certificate II in cyber security or something. From now on, before I download any files or click links I'll be checking with Virus Total beforehand as a added extra step.

This is a case closed for me.

Thank you <3
 
OSZAR »