Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Strange issue..


  • Please log in to reply
5 replies to this topic

#1 patey

patey

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Newfoundland,Canada
  • Local time:01:42 PM

Posted 17 April 2015 - 02:30 PM

I was over at tomshardware.com in search of help with this and they directed me here, http://www.tomshardware.com/answers/id-2609615/malware-issue.html .


It started when I noticed my laptop was running pretty slow; I opened up the task manager to see if there was anything suspicious going on and found my cpu,memory and disk usage to be all REALLY high. I ran a spybot and AVG scan, avg found nothing but spybot found/fixed a good amount of threats, but it didn't help so I headed over to tomshardware.


Overall the things I've noticed is that it starts with either a conhost.exe or cmd.exe starting, then random programs start opening in the background and consuming large amounts of system resources (never any one program consuming too much, at times it almost seems evenly distributed across multiple programs), and eventually I get a lot of error windows asking to close tons of cmd.exe instances; occasionally my laptop crashes altogether.


At some point I figured out that the malware (if this even is malware, I still haven't ruled out a legitimately bugged program) doesn't work without an internet connection (or so it seems at least). From there I found that after the cmd starts a bunch of msiexec.exe instances (consuming way more resources than any installer normally would), then typically theres a presentationhost.exe (it's supposed to be a legitimate microsoft program, and I've never seen it on my computer so I'm not sure whether its using mre resources than it should) shortly after, followed by msdtc.exe and theres always a random notepad.exe towards the end (in the background where I can't see it, that's what has me nearly convinced it's malware.) and all the while random cmd or conhost instances open. Occasionally a duplicate of a program that's already open will be created, such as the wmp library sharing service or ctfmon.exe, and strangely even though I have AVG uninstalled theres a random AVG secure-search installer process in the background sometimes.


I've tried multiple scans with a bunch of scanners (excluding avg, one scan with no results while others found plenty wrong was enough for me lol) - spybot, malwarebytes, emsisoft anti malware, virus vault, ccleaner and adwcleaner. they all found some threats and fixed them, but the problem persists.
While running scans I ran into a problem - I malwarebytes won't update, it can't connect to the server, but it works fine on another computer. I tried to get combofix but I couldn't even access the download site.


and to top it all off - I can't even access this site. It's as if the site is down, but seeing as I'm currently writing this post I'm pretty sure it's not lol


anyone know what's going on here? I'm at my wit's end with this, any help at all is appreciated. just let me know if any logs are needed.

*EDIT* I should probably mention I'm running windows 8.1

Edited by patey, 17 April 2015 - 02:56 PM.


BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,710 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:12 AM

Posted 17 April 2015 - 08:02 PM

Please follow the instructions in THIS GUIDE starting at Step 6. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then make a NEW TOPIC and post it HERE. Please include a description of your computer issues, what you have done to resolve them, and a link to this topic.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#3 patey

patey
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Newfoundland,Canada
  • Local time:01:42 PM

Posted 18 April 2015 - 03:40 PM

thanks, I've made a post over in that section now. I'll link it as soon as I can for anyone who may find this topic and need similar help but right now I have to access bleeping computer via proxy :/

#4 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,710 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:12 AM

Posted 18 April 2015 - 05:36 PM

p22003888.gif


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 


#5 patey

patey
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Newfoundland,Canada
  • Local time:01:42 PM

Posted 22 April 2015 - 06:42 PM

Still having trouble with this, no replies in my other thread :(

http://www.bleepingcomputer.com/forums/t/573649/malware-thats-opening-suspicous-programs/?fromsearch=1

#6 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,710 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:09:12 AM

Posted 22 April 2015 - 07:12 PM

You have to be patient.

Those guys are always busy.


My Website

p4433470.gif

My help doesn't cost a penny, but if you'd like to consider a donation, click p22001735.gif


 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users