Where did this come from?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • lti
    Badcaps Legend
    • May 2011
    • 2547
    • United States

    #1

    Where did this come from?

    Last week, my computer suddenly became very slow. When I opened Task Manager, I found a process called setup.exe with 100% CPU usage. When I ended the process, a second GoogleUpdate.exe process started (I have Chrome installed, so one Google Update process is always running). Ending this new GoogleUpdate.exe process ended both processes at the same time, so I thought Chrome was updating.

    Today, I ran Malwarebytes and it found two setup.exe files and a registry key related to the setup.exe file. All were detected as Adware.CNNIC. These were the only three things the scan found. I was using Firefox with AdBlock Plus and NoScript. How did this manage to download?
    Attached Files
  • shovenose
    Send Doge Memes
    • Aug 2010
    • 6575
    • USA

    #2
    Re: Where did this come from?

    Do a full scan not a quick scan and make sure nothing else shows up.

    Comment

    • Evil Lurker
      Warranty Voider
      • Feb 2011
      • 454

      #3
      Re: Where did this come from?

      There is so much crap floating around out there nowadays who knows where it came from.

      I use Microsoft Security Essentials + Malwarebytes + Spybot search and destroy (but not all at the same time) for protection. To keep my temporary file folders and registry clean (seems like these are favorite hiding spots of malware) I use CCleaner.

      Comment

      • lti
        Badcaps Legend
        • May 2011
        • 2547
        • United States

        #4
        Re: Where did this come from?

        A full scan with Malwarebytes and Avast didn't find anything else. The last registry cleaner I used messed up the registry so that no antivirus software would install.

        This computer has done some strange things since I started to connect to the college's wireless network. If I try to open Internet Explorer (the login page for the college's wireless network will only display in Internet Explorer), the window will sometimes close when the home page or login page starts to load.

        Comment

        • retiredcaps
          Badcaps Legend
          • Apr 2010
          • 9271

          #5
          Re: Where did this come from?

          Is your system fully up to date with all the patches?
          --- begin sig file ---

          If you are new to this forum, we can help a lot more if you please post clear focused pictures (max resolution 2000x2000 and 2MB) of your boards using the manage attachments button so they are hosted here. Information and picture clarity compositions should look like this post.

          We respectfully ask that you make some time and effort to read some of the guides available for basic troubleshooting. After you have read through them, then ask clarification questions or report your findings.

          Please do not post inline and offsite as they slow down the loading of pages.

          --- end sig file ---

          Comment

          • Evil Lurker
            Warranty Voider
            • Feb 2011
            • 454

            #6
            Re: Where did this come from?

            Usually when I encounter such problems I just say f-it, reformat the drive, and reinstall the OS to make sure its clean.

            Comment

            • shovenose
              Send Doge Memes
              • Aug 2010
              • 6575
              • USA

              #7
              Re: Where did this come from?

              Got a good Firewall? I would recommend Comodo Firewall. It's free, and very good!

              Comment

              • Agent24
                I see dead caps
                • Oct 2007
                • 4950
                • New Zealand

                #8
                Re: Where did this come from?

                Originally posted by shovenose
                Got a good Firewall? I would recommend Comodo Firewall. It's free, and very good!
                The Defense+ engine is the best part of Comodo, I think.


                Anyway, for virus removal I would also suggest a bootable scanner CD, like Bitdefender's Rescue CD for example, much easier to catch things that way, when they're not active and potentially hiding.

                (http://download.bitdefender.com/rescue_cd/)
                "Tantalum for the brave, Solid Aluminium for the wise, Wet Electrolytic for the adventurous"
                -David VanHorn

                Comment

                • Th3_uN1Qu3
                  Believe in
                  • Jul 2010
                  • 6031
                  • Romania

                  #9
                  Re: Where did this come from?

                  Originally posted by lti
                  If I try to open Internet Explorer (the login page for the college's wireless network will only display in Internet Explorer), the window will sometimes close when the home page or login page starts to load.
                  That sounds like it could be faulty RAM... run memtest and see what you get.
                  Originally posted by PeteS in CA
                  Remember that by the time consequences of a short-sighted decision are experienced, the idiot who made the bad decision may have already been promoted or moved on to a better job at another company.
                  A working TV? How boring!

                  Comment

                  • lti
                    Badcaps Legend
                    • May 2011
                    • 2547
                    • United States

                    #10
                    Re: Where did this come from?

                    If the computer was worth repairing, I would reinstall Windows... after replacing the hard drive, optical drive, battery, keyboard, and touchpad (all need to be replaced).

                    Windows is fully updated, but I am still using Firefox 3.6. I was told that the online portions of my college classes can not be accessed using Firefox 6 or later. I am only using the Windows firewall.

                    I might test the RAM some day.

                    Comment

                    • larrymoencurly
                      Badcaps Veteran
                      • Oct 2004
                      • 960
                      • USA

                      #11
                      Re: Where did this come from?

                      I had one instance where SuperAntiSpyware eliminated a malware, but sometimes none security programs found anything, while free online scans from Symantec, Bit Defender, Trend, Kaspersky, etc., did, although they didn't always provide the solution (had to go elsewhere for that). Also posting a Hijack This log at a computer security forum, like SpywareWarrior.com, can help.

                      Comment

                      • RJARRRPCGP
                        Badcaps Legend
                        • Jul 2004
                        • 6304
                        • USA

                        #12
                        Re: Where did this come from?

                        Originally posted by Evil Lurker
                        Usually when I encounter such problems I just say f-it, reformat the drive, and reinstall the OS to make sure its clean.
                        Soo QFT!
                        ASRock B550 PG Velocita

                        Ryzen 9 "Vermeer" 5900X

                        32 GB G.Skill RipJaws V F4-3200C16D-32GVR

                        Arc A770 16 GB

                        eVGA Supernova G3 750W

                        Western Digital Black SN850 1TB NVMe SSD

                        Alienware AW3423DWF OLED




                        "¡Me encanta "Me Encanta o Enlistarlo con Hilary Farr!" -Mí mismo

                        "There's nothing more unattractive than a chick smoking a cigarette" -Topcat

                        "Today's lesson in pissivity comes in the form of a ziplock baggie full of GPU extension brackets & hardware that for the last ~3 years have been on my bench, always in my way, getting moved around constantly....and yesterday I found myself in need of them....and the bastards are now nowhere to be found! Motherfracker!!" -Topcat

                        "did I see a chair fly? I think I did! Time for popcorn!" -ratdude747

                        Comment

                        • momaka
                          master hoarder
                          • May 2008
                          • 12170
                          • Bulgaria

                          #13
                          Re: Where did this come from?

                          Originally posted by Evil Lurker
                          To keep my temporary file folders and registry clean (seems like these are favorite hiding spots of malware) I use CCleaner.
                          +1
                          Well, I don't use CCleaner much for the registry, but I do use it to delete all of those junk files. I usually run it before shutdown. You can even make it do this automatically. Just create a second shortcut of CCleaner on your desktop, right click it, click on properties, and then in the "Target" box, type " /AUTO /SHUTDOWN" after the ccleaner.exe name. When you double-click this icon, CCleaner will run and then shutdown the computer. Then just use that instead of the shutdown button in Windows.

                          Comment

                          • shovenose
                            Send Doge Memes
                            • Aug 2010
                            • 6575
                            • USA

                            #14
                            Re: Where did this come from?

                            Originally posted by momaka
                            +1
                            Well, I don't use CCleaner much for the registry, but I do use it to delete all of those junk files. I usually run it before shutdown. You can even make it do this automatically. Just create a second shortcut of CCleaner on your desktop, right click it, click on properties, and then in the "Target" box, type " /AUTO /SHUTDOWN" after the ccleaner.exe name. When you double-click this icon, CCleaner will run and then shutdown the computer. Then just use that instead of the shutdown button in Windows.
                            This is a genious idea!

                            Comment

                            • lti
                              Badcaps Legend
                              • May 2011
                              • 2547
                              • United States

                              #15
                              Re: Where did this come from?

                              For me, registry cleaners don't do anything good. Updating drivers or the BIOS also have a negative effect on the computer's performance and stability unless the update fixes a known problem.

                              I just remembered that I can't test the memory because the optical drive is dead. The computer can boot from a USB floppy drive, but I don't know if it can boot from a flash drive.

                              Do you think the hard drive is bad?
                              Last edited by lti; 11-04-2011, 05:36 PM.

                              Comment

                              • Agent24
                                I see dead caps
                                • Oct 2007
                                • 4950
                                • New Zealand

                                #16
                                Re: Where did this come from?

                                Memtest86+ has floppy images, so if you can boot from your USB floppy that should work.
                                "Tantalum for the brave, Solid Aluminium for the wise, Wet Electrolytic for the adventurous"
                                -David VanHorn

                                Comment

                                • momaka
                                  master hoarder
                                  • May 2008
                                  • 12170
                                  • Bulgaria

                                  #17
                                  Re: Where did this come from?

                                  Originally posted by lti
                                  For me, registry cleaners don't do anything good.
                                  Yes, many registry cleaners will pick up things they shouldn't. If you know what to delete and what to leave from the list they give you, they can be okay.

                                  Originally posted by lti
                                  If that utility is correct, then YES, your HD is going bad.
                                  According to the screenshot you posted, your HD has 160 reallocated sectors, 108 that have been registered as reallocated (Reallocated Event Count) and 300 pending to be remapped (Current Pending Sector).

                                  Try HDD Tune and see what it tells you. If it's the same thing, then the hard drive definitely is going bad.

                                  Comment

                                  • Agent24
                                    I see dead caps
                                    • Oct 2007
                                    • 4950
                                    • New Zealand

                                    #18
                                    Re: Where did this come from?

                                    If that's a report from Speedfan then I would say it's accurate.

                                    That many reallocated sectors, your drive has issues. While it doesn't spell immediate doom, it's a good sign.

                                    Backup your data if not already, and get a new drive. Hopefully you can find someone who hasn't heard of the floods in Thailand.
                                    "Tantalum for the brave, Solid Aluminium for the wise, Wet Electrolytic for the adventurous"
                                    -David VanHorn

                                    Comment

                                    • b700029
                                      Banned
                                      • Sep 2010
                                      • 640

                                      #19
                                      Re: Where did this come from?

                                      Ultra DMA CRC Error Rate 200 21
                                      Offline Uncorrectable Sector Count 1 255
                                      Current Pending Sector 100 300
                                      Reallocated Event Count 100 108
                                      Reallocated Sector Count 100 160
                                      With the exception of the first one, my belief is that these should never be nonzero, otherwise the drive is not reliable and should be replaced. The first one may indicate cable problems.

                                      This is an example of a disk in good condition. (It's getting "old" but I wouldn't worry about that because everything else is perfect.)

                                      Comment

                                      • shovenose
                                        Send Doge Memes
                                        • Aug 2010
                                        • 6575
                                        • USA

                                        #20
                                        Re: Where did this come from?

                                        Yes but the one in my bedside PC is really good!
                                        Attached Files

                                        Comment

                                        Related Topics

                                        Collapse

                                        • rive.hafintosh
                                          HP Probook 650 G4 - Lost power?During AMT de-provision process, now I get blackscreen
                                          by rive.hafintosh
                                          First here is how things went down.

                                          I entered the bios and began to de-provision Intel AMT - it began with a reboot and then prompted me to de-provision AMT - proceed Y/N -
                                          I pressed Y and hit enter, and I thought the PC shutdown, but perhaps it actually lost power at this point. I had the power adapter plugged in but apparently the plug from the wall came out of the brick when I wasn't noticing so 1 of two things could have happened…
                                          Something went wrong with the process, or it lost power during the process and corrupted something
                                          I tried making a HP recovery...
                                          10-12-2023, 07:42 PM
                                        • jheunne
                                          MSI A15 B7UCX restart on process of windos installation help
                                          by jheunne
                                          i have msi a15 b7ucx reboots on process of installation of widows 10 or 11 i tried also windows to go still keeps rebooting sad face stopcode error kernel security check failure etc. i already flash latest bios i still cannot install proper windows on my laptop.can someone can help me about this one
                                          05-17-2025, 01:19 AM
                                        • TVAddict
                                          TCL 40S6500A - stuck in boot process
                                          by TVAddict
                                          Hi everyone, i have a TCL 40" that's stuck in the boot process,here's what happens, at first turn on you get the TCL logo after that it goes to the 4 rotating color circles, it does not go beyond this point, the color circles just keep going on, from what i've read and seen on YT apparently it's a firmware/software issue, i'm willing to try a software update via the usb method but have no luck finding a suitable site to download the correct software for my model TCL, i have tried the TCL site with no luck, so the real question is can anyone HELP point me to a reliable source i can download...
                                          10-27-2024, 08:57 PM
                                        • nicktasios
                                          Troubleshooting Apple Multiple Scan 17 Display
                                          by nicktasios
                                          I recently picked up a Quadra with a Apple Multiple Scan 17 Display. The Quadra was not working, it clearly had corrosion from leaking caps so I replaced them and luckily it chimed and worked properly.

                                          The next problem to tackle was the screen. Sometimes it turns on and off multiple times before finally turning on, and then it sometimes turns purple. After waiting some time, without doing anything, it regains all colors. Another symptom is that it sometimes seems to momentarily blink.

                                          Also, not sure if this is related, but sometimes, after experiencing these problems,...
                                          09-17-2023, 03:51 AM
                                        • MahmoudNasser
                                          Dell 7480 problem with freezing during the Windows loading process
                                          by MahmoudNasser
                                          Hello everyone, I wish you a happy day.

                                          I have a Dell Latitude 7480 laptop that has a problem with freezing during the Windows loading process. If it manages to boot up, it becomes very slow and doesn't load anything from the desktop.

                                          Device Data
                                          Model Dell Latitude 7480
                                          CPU:i7-7600U
                                          SN:7T58PL2
                                          MP PartNumper:CAZ20 LA-E131P Rev:1.0 A00
                                          Bios Chips:W25Q128BV

                                          The attempts that have been made to solve the problem have not yielded any results.

                                          1. Changing the M.2 and M.2 Nvme hard drives.
                                          2. Trying...
                                          07-09-2023, 05:04 AM
                                        • Loading...
                                        • No more items.
                                        Working...