MSbuild.exe is contacting gamorar.cc 3 times every 10 minutes it is being flagged as a trojan and connection is blocked by malwarebytes

AKSHAY R B 30 Reputation points
2026-07-11T06:48:18.2+00:00

Screenshot 2026-07-11 114417.png
this is the exact popup
I have run scan in every antivirus program still nothing detected
could you please help me out with this

Windows for home | Other | Security and privacy

Answer accepted by question author
_AW_ 69,416 Reputation points Volunteer Moderator
2026-07-11T07:04:37.8633333+00:00

We can manually remove it. Please provide Farbar Recovery Scan Tool (FRST) logs for analysis.

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Note: If you are using Edge or Chrome, SmartScreen may initially block the download. Click on the three dots next to the warning and select Keep => Click the Delete drop arrow => Keep anyway.

  • If your computer's language is not English, rename FRST64.exe to FRST64English.exe
  • Run the tool, leave the default settings, and press Scan.
  • Zip the logs, FRST.txt and Addition.txt, then upload to a cloud storage service like OneDrive, Google Drive or gofile.io
  • Post the share link.

https://support.microsoft.com/en-us/office/share-onedrive-files-and-folders-9fcc2f7d-de0c-4cec-93b0-a82024800c07

Was this answer helpful?

2 people found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Sobia Khalid 100 Reputation points
    2026-07-11T06:53:42.4633333+00:00

    Why your AV scans aren't catching it

    • Signature-based scanners look for known malicious files. If the actual payload is injected in-memory via MSBuild rather than sitting on disk, there's nothing for a normal scan to flag.
    • Malwarebytes caught this because it monitors network behavior, not just files — which is exactly the right layer to catch this.

    What to do

    1. Don't click "Allow website." Leave it blocked.
    2. Find what's invoking MSBuild. Malware rarely calls MSBuild directly — something else launches it. Check:
      • Task Scheduler (taskschd.msc) for suspicious scheduled tasks
        • Startup apps (Task Manager → Startup)
          • Recently installed programs, especially anything downloaded from cracked software/game sites (the domain name pattern strongly suggests piracy/keygen-site origin)
          1. Run Malwarebytes' full scan (not just real-time protection) — Scan → Advanced scanners → include rootkit scan.
          2. Try a second-opinion scanner that specializes in this: ESET Online Scanner or Kaspersky Virus Removal Tool, both free, both good at catching LOLBin abuse.
          3. Check for a malicious .csproj or .xml file that MSBuild might be pointed at — search for recently modified .xml/.csproj files in Temp, AppData, or Downloads.
          4. If you can, boot into Safe Mode and scan there — this stops the malware process from actively running/hiding.
    3. If you recently downloaded pirated software, a game crack, or a keygen, that's very likely the entry point — worth mentioning if you want more targeted advice.

    Was this answer helpful?

    1 person found this answer helpful.

  2. _AW_ 69,416 Reputation points Volunteer Moderator
    2026-07-11T07:35:22.9966667+00:00
    • Save Fixlist.txt to your Downloads folder.
    • Close any apps with unsaved work.
    • Run FRST64.exe and click "Fix".
    • The computer will reboot to complete the procedure.

    Please upload Fixlog.txt so I can check if any further action is needed.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.