Detecting Malware
Page 1 of 1
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Fri, 2nd Jul 2010 02:07    Post subject: Detecting Malware
I'm pretty sure that something is wrong with my windows 7. Via the task manager I'll see how the conhost and cmd got started and all shit and sometimes the computer slows down when I'm not connected to the internet Confused

I did a full scan with security essentials, avira and spybot search and destroy. What else could you recommend?

With msconfig under windows xp I could see every service and exe that got started, but under windows 7 msconfig does not display every program that my computer loads on startup.


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
todd72173




Posts: 2403

PostPosted: Fri, 2nd Jul 2010 02:43    Post subject:
Format and do a clean install. Ive dont that 3x with Windows 7. So far for me, XP is alot more securer than this Windows 7 trash.


RYZEN 5 2600|RADEON 570| |ASRock X370 Killer|DDR4@2800Mhz||Corsair SPEC-05 Case|AOC G2590FX 24.5''144hz 1ms|
Back to top
mag2005




Posts: 611
Location: Any place with air
PostPosted: Fri, 2nd Jul 2010 02:49    Post subject:
I recommend Malwarebytes's Anti-Malware. I've clean all my relatives computers with it, it detect better than MSE in my cases. It has Flash Scan option that does a fast scan for malwares in a minute. You can run it in Safe Mode as well for problematic malwares/viruses.


If you hate it, ignore it.
Back to top
ManMountain




Posts: 793

PostPosted: Fri, 2nd Jul 2010 03:23    Post subject:
Conhost launching up when dropping to the cmd prompt is perfectly normal; conhost is the host for the cmd prompt, ensuring drag / drop works and fixes console drawing bug that existed in previous Windows versions.

Course, that's assuming it's you that is dropping to the command prompt in the first place. Check what's set to autostart when Win 7 loads up. There's lots of utils, a simple one to use one would be Sysinternals Autoruns for Windows v10.01 - http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

You may want to then move onto Process Explorer v12.04 to further investigate as to what's actually running - http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

As for your computer slowing down, if it's not your imagination then a simple way to monitor what's draining resources would be to just use Win 7's built in Resource Monitor.

Oh and todd72173, WinXP's still has it's uses:



Cool Face


Last edited by ManMountain on Fri, 2nd Jul 2010 03:36; edited 2 times in total
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Fri, 2nd Jul 2010 03:29    Post subject:
I'm not opening the cmd. I wouldn't even notice that cmd is starting and closing itself if I wouldn't be looking into the task manager Sad


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Fri, 2nd Jul 2010 03:37    Post subject:
I found a suspicious looking gathernetworkinfo.vbs file in my system32 and it is started trough the task scheduler. Any ideas what that is?

At least it looks like if it is opening the cmd. Can I check if that file is legit or modified?


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
ManMountain




Posts: 793

PostPosted: Fri, 2nd Jul 2010 03:45    Post subject:
gathernetworkinfo.vbs exists on all Win 7 installs, it's used by network / sharing centre.

If your paranoid the file in C:\Windows\System32 has been modified, compare it's hashcode to the secondary copy which should be stored in C:\Windows\winsxs.



Stupid question I know, but have you updated any drivers or installed software around the time you first noticed the problem?
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Fri, 2nd Jul 2010 04:20    Post subject:
No, not really :/ The reason I'm so "paranoid" is, because I had problems with viruses on this computer once and that was the reason why I switched to avira and did a full scan with spybot.

Thanks for the links to the tools!

And I don't know if the problems are related to each other, but when I turn off my wireless adapter on my notebook while playing test drive unlimted the game becomes unplayable and I see the cmd flashing up again in the task manager.


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
todd72173




Posts: 2403

PostPosted: Fri, 2nd Jul 2010 04:27    Post subject:
mag2005 wrote:
I recommend Malwarebytes's Anti-Malware. I've clean all my relatives computers with it, it detect better than MSE in my cases. It has Flash Scan option that does a fast scan for malwares in a minute. You can run it in Safe Mode as well for problematic malwares/viruses.


Microsoft does not consider Malwarebytes a virus app as it does not recognize it installed and still asks for a virus program installed. Also, malwarebytes is not totally accurate - I had a few slip by it. Furthermore, MSE will not update if you have malwarebytes installed as well (I was running both at same time). So now Im stuck with lame MSE.


RYZEN 5 2600|RADEON 570| |ASRock X370 Killer|DDR4@2800Mhz||Corsair SPEC-05 Case|AOC G2590FX 24.5''144hz 1ms|
Back to top
mag2005




Posts: 611
Location: Any place with air
PostPosted: Fri, 2nd Jul 2010 04:36    Post subject:
todd72173 wrote:

Microsoft does not consider Malwarebytes a virus app as it does not recognize it installed and still asks for a virus program installed. Also, malwarebytes is not totally accurate - I had a few slip by it. Furthermore, MSE will not update if you have malwarebytes installed as well (I was running both at same time). So now Im stuck with lame MSE.


Malwarebytes is an on demand app, that's why it's not consider a virus apps by Windows. My MSE update automatically with Malwarebytes installed. So I don't know what you mean by that. For what Malwarebytes does, it's pretty good. Download it from their website and the keys are easy to find.


If you hate it, ignore it.
Back to top
moosenoodles




Posts: 18411

PostPosted: Fri, 2nd Jul 2010 08:51    Post subject:
malwarebytes is worth running, I also use all these for my tools for dealing with suspect os's, for rootkits and disabling running apps that you cant control.

Combofix
avenger
hijack this
procexp
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Applications
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group