Stupid Malware...

Serendipity
Serendipity Posts: 6,975
edited October 2009 in The Clubhouse
I don't know what the hell this is, but it's driving me crazy.

Recently I've got some kind of malware/spyware that DOES NOT show any pop-up ads, redirect pages, or make changes to the browser but always hogs my system resources.

In the attached picture, Task Manager shows the CPU usage at 100% with nothing running!! I have tried Kaspersky Antivirus (paid version), Spybot S&D, Malwarebytes, Ad-Aware, and they can't find anything!!

The machine is ridiculously slow too...
polkaudio RT35 Bookshelves
polkaudio 255c-RT Inwalls
polkaudio DSWPro550WI
polkaudio XRT12 XM Tuner
polkaudio RM6750 5.1

Front projection, 2 channel, car audio... life is good!
Post edited by Serendipity on
«13456

Comments

  • bobman1235
    bobman1235 Posts: 10,822
    edited October 2009
    If you look at your processes it should tell you what process is using the CPU, and you should be able to find / kill it from there.
    If you will it, dude, it is no dream.
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Yes, it shows explorer.exe and if I terminate that I lose the taskbar.
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • John30_30
    John30_30 Posts: 1,024
    edited October 2009
    explorer.exe is just that. It's Windows shell. Do a screencap of the Processes Tab in Task Manager (you might have to do a couple to get them all ) and let us gooroos take a gander.
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    John30_30 wrote: »
    explorer.exe is just that. It's Windows shell. Do a screencap of the Processes Tab in Task Manager (you might have to do a couple to get them all ) and let us gooroos take a gander.

    Here ya go:

    I terminated explorer.exe so that the system is at least usable...
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    These are the programs on the system right now, BTW.

    I think I have too many things installed - what can I safely get rid of?
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Face
    Face Posts: 14,340
    edited October 2009
    That's a small list of installed programs.

    Did you try the last two programs I recommended to you?
    "He who fights with monsters should look to it that he himself does not become a monster. And when you gaze long into an abyss the abyss also gazes into you." Friedrich Nietzsche
  • Systems
    Systems Posts: 14,873
    edited October 2009
    Well on the first screenshot you had 25 processes running and 100 percent cpu usage. On that second shot of the tasks it went down to 19 processes with 0 percent cpu usage. What processes did you end?
    Testing
    Testing
    Testing
  • John30_30
    John30_30 Posts: 1,024
    edited October 2009
    appadv wrote: »
    These are the programs on the system right now, BTW.

    I think I have too many things installed - what can I safely get rid of?

    you don't have much on there. Unfortunately, the scan you put up showed 99% system idle. Does it always hang when explorer.exe is running?
    The only app I see that would take up that kind of resources is if Kaspersky was doing a scheduled all-system scan.

    Otherwise, it's possible you got an altered version of explorer.exe. There's a command-line command you can issue that will check system files and replace iffy ones, if you've got your copy of Windows handy.
    Start/Run/ type cmd/ type in the 'dos' window sfc /scannow. With the space.
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Face wrote: »
    That's a small list of installed programs.

    Did you try the last two programs I recommended to you?

    Yes. And I always uninstalled my last antivirus before going to another, i.e. I didn't run both AVG and Kaspersky at the same time.
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    This is what I had installed before the problems occurred:

    Like I said, I recently added a bunch of programs.

    (See attached pic)
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Face
    Face Posts: 14,340
    edited October 2009
    Trend Micro or Spyware Doctor?
    "He who fights with monsters should look to it that he himself does not become a monster. And when you gaze long into an abyss the abyss also gazes into you." Friedrich Nietzsche
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Trend Micro. It kept updating and displayed a dialog box with the percent updated, I got annoyed and clicked cancel...
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Lorthos wrote: »
    Well on the first screenshot you had 25 processes running and 100 percent cpu usage. On that second shot of the tasks it went down to 19 processes with 0 percent cpu usage. What processes did you end?

    I closed the browser (was viewing Club Polk), my Kaspersky antivirus, and explorer.exe.
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • dee1949
    dee1949 Posts: 1,425
    edited October 2009
    ....read some of these....how much drive space is free on hard drive? clean out and defrag......maybe it will help

    http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=bfv&q=Low+System+Resources&btnG=Search&aq=f&oq=&aqi=
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    Okay malware stand for malicious software. What it does is take control of your computer and will not let you do anything until you pay them to release it. Malware bytes is one program you can try. Make sure to install it and run the program wit the internet off and in safe mode. HIjack this is another one that you can try if the malware will not let you run the first program use this and remove some of the things that might be blocking the malware bites from working.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    Also no malware will show up on any anti spyware or ant virus software. Malware bytes is the main one I use.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    dee1949 wrote: »
    ....read some of these....how much drive space is free on hard drive? clean out and defrag......maybe it will help

    http://www.google.com/search?hl=en&client=firefox-a&rls=org.mozilla%3Aen-US%3Aofficial&hs=bfv&q=Low+System+Resources&btnG=Search&aq=f&oq=&aqi=

    The disk is 95% free with 88.81GB remaining. Also, I do a defrag once every few weeks.
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Attached is a result of the disk analysis:
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    Honestly if you are still having trouble and have nothing you need on the drive. Wipe it out and start fresh that is what my teacher recommends for my computer class.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    Honestly if you are still having trouble and have nothing you need on the drive. Wipe it out and start fresh that is what my teacher recommends for my computer class.

    Well, I'm looking for a quick fix and don't want to wipe the drive. Based on what I have installed, is there anything I *should* get rid of?
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    As I said above install malware bytes run it and remove what it finds.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • dee1949
    dee1949 Posts: 1,425
    edited October 2009
    Malwarebytes, for removing stubborn viruses ans trojans.
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    There not viruses it is actually malware. Virus and malware are 2 different things.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • jimmydep
    jimmydep Posts: 1,305
    edited October 2009
    As I said above install malware bytes run it and remove what it finds.

    this always works for me also.^^^^^^^
  • Serendipity
    Serendipity Posts: 6,975
    edited October 2009
    As I said above install malware bytes run it and remove what it finds.

    I tried Malwarebytes and it didn't fix the problem. Is there any other thing I could try?
    polkaudio RT35 Bookshelves
    polkaudio 255c-RT Inwalls
    polkaudio DSWPro550WI
    polkaudio XRT12 XM Tuner
    polkaudio RM6750 5.1

    Front projection, 2 channel, car audio... life is good!
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    Nope that means that there is not a removal for it so your best bet is to wipe out start fresh and make sure to have malware installed when you do. Or try hijack this.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • snow
    snow Posts: 4,337
    edited October 2009
    appadv wrote: »
    I tried Malwarebytes and it didn't fix the problem. Is there any other thing I could try?
    Can you restore your PC to an earlier date than when this problem began?



    REGARDS SNOW
    Well, I just pulled off the impossible by doing a double-blind comparison all by myself, purely by virtue of the fact that I completely and stupidly forgot what I did last. I guess that getting old does have its advantages after all :D
  • sucks2beme
    sucks2beme Posts: 5,601
    edited October 2009
    Sounds more like a program that didn't like something already on your machine. Uninstall the latest programs, and then roll back your system to a restore point back a month or so ago.
    "The legitimate powers of government extend to such acts only as are injurious to others. But it does me no injury for my neighbour to say there are twenty gods, or no god. It neither picks my pocket nor breaks my leg." --Thomas Jefferson
  • bigaudiofanatic
    bigaudiofanatic Posts: 4,415
    edited October 2009
    snow wrote: »
    Can you restore your PC to an earlier date than when this problem began?



    REGARDS SNOW

    Not going to help remove malware.
    HT setup
    Panasonic 50" TH-50PZ80U
    Denon DBP-1610
    Monster HTS 1650
    Carver A400X :cool:
    MIT Exp 3 Speaker Wire
    Kef 104/2
    URC MX-780 Remote
    Sonos Play 1

    Living Room
    63 inch Samsung PN63C800YF
    Polk Surroundbar 3000
    Samsung BD-C7900
  • snow
    snow Posts: 4,337
    edited October 2009
    Not going to help remove malware.
    I never said it would :D Obviously somethinng else is going on other than Malware if he has ran Malware bytes.



    REGARDS SNOW
    Well, I just pulled off the impossible by doing a double-blind comparison all by myself, purely by virtue of the fact that I completely and stupidly forgot what I did last. I guess that getting old does have its advantages after all :D