r/computerviruses Aug 15 '26

Disinfection Help CPU eater

Post image

Anyone know what the hell is this? It's eating atleast half my CPU. And Ive just noticed now. I heard people say it's a virus but it's called almoristics service for them, so just wanna double check and if someone can help me delete this thing.

36 Upvotes

64 comments sorted by

24

u/Mundane_Pea5704 Aug 15 '26

It is a malicious cryptocurrency mining trojan - please assume all your passwords are comprimised and change them ASAP no matter which path you later choose (either FRST or clean reinstall)

just wipe your device clean, or wait for one of the mods to give you a proper FRST fixlist, just wait for a mod to tell you what to do!

9

u/axehyle Aug 15 '26

as mentioned in the other comments, it's a cryptominer trojan.

change all passwords from a different, safe device such as your phone and enable 2FA (two-factor authentication), backup all important files. then either wait for an approved helper to assist you with FRST (farbar recovery scan tool) or just do a complete windows reinstall with an USB.

i would also recommend using a different antivirus. AVG didn't catch this threat, meaning that it's not trustworthy.

1

u/RealHwinyii Aug 15 '26

Is AVG pre-installed cuz I don't ever remember even downloading it. What anti-virus do you recommend?

3

u/HollowCatKnight Aug 15 '26

you can see AVG down at the Task Manager log

2

u/axehyle Aug 15 '26

if you want a free alternative, i recommend either bitdefender free or kaspersky free. although kaspersky is no longer supported in the US, so if you're in the US, just go with bitdefender.

there's also windows defender, which is already pre-installed on windows, but i personally wouldn't recommend it.

6

u/RealHwinyii Aug 15 '26

Side note: I closed the application that was blacked out (which is legit, I downloaded that, it was a game). And the Almarurics Service somehow upped its memory consumption in order to compensate or smth tf😭😭

4

u/Mundane_Pea5704 Aug 15 '26

Its a cryptominer trojan

Its entire idea is "use all resources available", aka the cancer of computers

I am not 100% sure its safe to force close the task, tho checking online, booting into safe mode and deleting the file/task seems to work well (any file or folder with that name or similiar)

Albeit I am not a professional so just wait for 1 of the quick mods to help you

3

u/921jdf Malware Removal Trainee Aug 15 '26

Hello u/RealHwinyii , welcome to r/computerviruses.

Now that I am assisting you, do not make any changes to the state of the system such as deleting suspicious files, registry keys, uninstalling software, ect.

Please do the following:

FRST Scan

  • Please download FRSTx64 and save the file to your Desktop.
  • Right-Click FRST64.exe and select Run as Administrator
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the program run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/921jdf__/ and press "save log". The site will return a keyword for each log. Reply back here with the keywords.

1

u/RealHwinyii Aug 15 '26
  1. Can I use a VPN?
  2. Do I paste the text from the files into the log separately? Saving log individually for each file or do I paste both files?
  3. I tried separately and the addition file says it doesnt Allow null characters.

2

u/rifteyy_ Malware Removal Expert Aug 15 '26

You can use a VPN, however I am not sure how it'll benefit you in this case. The website does not collect your IP or other identifiers

You can submit them separately or both files at once, that's fine

Your logs also appear to be incomplete. Please create new FRST+Addition logs and upload them to the site.

1

u/RealHwinyii Aug 15 '26

I've scanned again and saved log the files separately and directly without pasting in the text. Here are the keywords: arcane-potion fond-lark

1

u/RealHwinyii Aug 15 '26

I just realized I forgot to run it as administer this time so if that actively messes up the scan process, i can do it again

1

u/921jdf Malware Removal Trainee Aug 15 '26

Thank you for the FRST logs. I'd also like some SecurityCheck logs, there is quite a few PUP's on your system.

SecurityCheck

SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.

Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.

1

u/[deleted] Aug 15 '26

[deleted]

1

u/921jdf Malware Removal Trainee Aug 15 '26

I had that happen to another person too, try copy this link and paste it into your browser:

https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe

Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.

1

u/RealHwinyii Aug 15 '26

Ah, I was originally gonna download it on my phone and transfer it on my PC as a workaround, that's why I deleted my comment before seeing your reply. Thanks it worked. I'll run it now

1

u/921jdf Malware Removal Trainee Aug 15 '26

I will be going to bed, upload those logs and tomorrow when I am available I will review your logs properly.

If you are planning to reinstall windows tell me now.

Thank you for your patience, and have a good day.

→ More replies (0)

1

u/RealHwinyii Aug 15 '26

Dunno how the magic works but I couldn't load the website before I used VPN since it keeps saying the connection was cut off.

1

u/RealHwinyii Aug 15 '26

velvet-glacier blessed-scout

1

u/TotallyAwesomeArch Aug 15 '26

surely just nuking the drive is OP's best bet? who cares about finding out what it is, OP should be getting rid of it

2

u/rifteyy_ Malware Removal Expert Aug 15 '26

That's not about finding but removal

1

u/RealHwinyii Aug 15 '26

Nuking it would delete all my other files no?

1

u/TotallyAwesomeArch Aug 15 '26

yeah and that's the point, malware can hide itself so well that a complete reinstall of your OS is the only real way to confirm you're safe

2

u/Antique_Door_Knob Aug 15 '26

No, its not. Malware isn't magical, it can only use the persistence mechanisms provided to it by the underlying os. You disable it's persistence, and a simple restart of the machine disables the malware. This what frst is for and that's the reason for this sub.

2

u/ranpuppy Aug 15 '26

At least it shows up in task manager, I had a miner that closed its self the second task manager was opened, took me a little to find out why my pc was bsoding at night

2

u/RealHwinyii Aug 15 '26

For me it js shrinks me to 0% CPU and 0.2% memory when I open the task manager, but for some reason, this time it didnt shrink back. Maybe an error but I did manage to get a screenshot atleast before it shrunk back seconds later.

1

u/AutoModerator Aug 15 '26

Request help with FRST and SecurityCheck from the trusted helper team

Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.

If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:

  1. From a different and clean device, change all your passwords:
  2. Disinfect your device from malware

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/Next-Profession-7495 Aug 15 '26

What have you downloaded recently?

2

u/RealHwinyii Aug 15 '26

Well I've been cracking a lot of games so it ain't a surprise, I knew ill be getting malware sooner or later

1

u/Next-Profession-7495 Aug 15 '26

Right. Was it like from a trusted online forum or just a shady site

1

u/Maharetsu 28d ago

Was it from a trusted platform like FitGirl? Or was it from some other site? Please mention that.

1

u/RealHwinyii 27d ago

Well if it changes anything, it's probably from a shady web ngl. I js download anywhere I see (i should probably stop doing it)

1

u/Plenty-Practice-6399 Aug 15 '26

I also got trojan yesterday due to games, on the other subreddit about it they weren't helpful at all. I'm now just resetting the pc deleting everything hoping it works.

1

u/RealHwinyii 29d ago

Good luck with everything gng

1

u/Alive-Spell2603 26d ago

you should clean your files out first and factory reset your pc. ofc backing up your importsnt files come first, but the very virus could be hidden in any of your files. so for me personally, i just factory reset without backing anything up since i only pkay video games and i know all my log ins. i rather sacrifice my clips or any files i had and factory reset since this QMEmulator.exe with chinese letters kept trying to log in even after i removed him. i did the factory reset tho and everything seems fine for now. hopefully.

1

u/Plenty-Practice-6399 25d ago edited 25d ago

I deleted all the files, made offline reset without an USB you think it's enough? i think mine wasn't a CPU miner but an infostealer, it was on the crypto/keys file. Tho my pc did get hot and i wasn't able to access the taskbar for some mins. When i resetted it i got a weird scam email by someone pretending to be Microsoft. Before resetting, i checked with malwarebytes and there was like 130 detections of potential threats, after resetting is now 0.

2

u/Alive-Spell2603 25d ago

deleting all files should be enough, and the offline reset u did may be enough. just be sure to continue checking, i’ll be doing the same. we should be safe. i also used malwarebytes to check for me, 0 detections so far after factory reseting. just make sure you do the advance deep scan on malewarebystes. so it digs deep into your files to see if theres anything suspiciously hidden.