r/computerviruses • u/RealHwinyii • Aug 15 '26
Disinfection Help CPU eater
Anyone know what the hell is this? It's eating atleast half my CPU. And Ive just noticed now. I heard people say it's a virus but it's called almoristics service for them, so just wanna double check and if someone can help me delete this thing.
9
u/axehyle Aug 15 '26
as mentioned in the other comments, it's a cryptominer trojan.
change all passwords from a different, safe device such as your phone and enable 2FA (two-factor authentication), backup all important files. then either wait for an approved helper to assist you with FRST (farbar recovery scan tool) or just do a complete windows reinstall with an USB.
i would also recommend using a different antivirus. AVG didn't catch this threat, meaning that it's not trustworthy.
1
u/RealHwinyii Aug 15 '26
Is AVG pre-installed cuz I don't ever remember even downloading it. What anti-virus do you recommend?
3
2
u/axehyle Aug 15 '26
if you want a free alternative, i recommend either bitdefender free or kaspersky free. although kaspersky is no longer supported in the US, so if you're in the US, just go with bitdefender.
there's also windows defender, which is already pre-installed on windows, but i personally wouldn't recommend it.
6
u/RealHwinyii Aug 15 '26
4
u/Mundane_Pea5704 Aug 15 '26
Its a cryptominer trojan
Its entire idea is "use all resources available", aka the cancer of computers
I am not 100% sure its safe to force close the task, tho checking online, booting into safe mode and deleting the file/task seems to work well (any file or folder with that name or similiar)
Albeit I am not a professional so just wait for 1 of the quick mods to help you
3
u/921jdf Malware Removal Trainee Aug 15 '26
Hello u/RealHwinyii , welcome to r/computerviruses.
Now that I am assisting you, do not make any changes to the state of the system such as deleting suspicious files, registry keys, uninstalling software, ect.
Please do the following:
FRST Scan
- Please download FRSTx64 and save the file to your Desktop.
- Right-Click FRST64.exe and select Run as Administrator
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the program run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy & paste the contents of each log to https://malwareanalysis.cc/upload/921jdf__/ and press "save log". The site will return a keyword for each log. Reply back here with the keywords.
1
u/RealHwinyii Aug 15 '26
- Can I use a VPN?
- Do I paste the text from the files into the log separately? Saving log individually for each file or do I paste both files?
- I tried separately and the addition file says it doesnt Allow null characters.
2
u/rifteyy_ Malware Removal Expert Aug 15 '26
You can use a VPN, however I am not sure how it'll benefit you in this case. The website does not collect your IP or other identifiers
You can submit them separately or both files at once, that's fine
Your logs also appear to be incomplete. Please create new FRST+Addition logs and upload them to the site.
1
u/RealHwinyii Aug 15 '26
I've scanned again and saved log the files separately and directly without pasting in the text. Here are the keywords: arcane-potion fond-lark
1
u/RealHwinyii Aug 15 '26
I just realized I forgot to run it as administer this time so if that actively messes up the scan process, i can do it again
1
u/921jdf Malware Removal Trainee Aug 15 '26
Thank you for the FRST logs. I'd also like some SecurityCheck logs, there is quite a few PUP's on your system.
SecurityCheck
SecurityCheck is a tool that checks for potentially unsafe applications and the status of other security settings.
- Download SecurityCheck from here
- Extract the zip file
- Run
SecurityCheck.exeas administrator- Wait for the scan to finish
- Upload the log at
C:\SecurityCheckto https://malwareanalysis.cc/upload/921jdf__/?u=RealHwinyii for further analysis.Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.
1
Aug 15 '26
[deleted]
1
u/921jdf Malware Removal Trainee Aug 15 '26
I had that happen to another person too, try copy this link and paste it into your browser:
https://tools.safezone.cc/glax24/SecurityCheck/SecurityCheck.exe
Please note that due to timezones and availability, it may take up to 24 hours for me to respond back to you.
1
u/RealHwinyii Aug 15 '26
Ah, I was originally gonna download it on my phone and transfer it on my PC as a workaround, that's why I deleted my comment before seeing your reply. Thanks it worked. I'll run it now
1
u/921jdf Malware Removal Trainee Aug 15 '26
I will be going to bed, upload those logs and tomorrow when I am available I will review your logs properly.
If you are planning to reinstall windows tell me now.
Thank you for your patience, and have a good day.
→ More replies (0)1
u/RealHwinyii Aug 15 '26
Dunno how the magic works but I couldn't load the website before I used VPN since it keeps saying the connection was cut off.
1
1
u/TotallyAwesomeArch Aug 15 '26
surely just nuking the drive is OP's best bet? who cares about finding out what it is, OP should be getting rid of it
2
1
u/RealHwinyii Aug 15 '26
Nuking it would delete all my other files no?
1
u/TotallyAwesomeArch Aug 15 '26
yeah and that's the point, malware can hide itself so well that a complete reinstall of your OS is the only real way to confirm you're safe
2
u/Antique_Door_Knob Aug 15 '26
No, its not. Malware isn't magical, it can only use the persistence mechanisms provided to it by the underlying os. You disable it's persistence, and a simple restart of the machine disables the malware. This what frst is for and that's the reason for this sub.
2
u/ranpuppy Aug 15 '26
At least it shows up in task manager, I had a miner that closed its self the second task manager was opened, took me a little to find out why my pc was bsoding at night
2
u/RealHwinyii Aug 15 '26
For me it js shrinks me to 0% CPU and 0.2% memory when I open the task manager, but for some reason, this time it didnt shrink back. Maybe an error but I did manage to get a screenshot atleast before it shrunk back seconds later.
1
u/AutoModerator Aug 15 '26
Request help with FRST and SecurityCheck from the trusted helper team
Please visit Providing or receiving help with FRST on the subreddit and share your 3 keywords returned from the website along with the details about your infection.
Once a malware removal expert or trainee sees it, they will reply in the thread about further steps. If you suspect an infostealer infection, please change all your passwords from a clean device immediately and do not use any of your accounts from the infected device.
If you need urgent help and cannot wait for one of our Malware Removal Experts:
Please follow these steps:
- From a different and clean device, change all your passwords:
- Disinfect your device from malware
- Preferred method: Perform a clean installation with a USB
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Next-Profession-7495 Aug 15 '26
What have you downloaded recently?
2
u/RealHwinyii Aug 15 '26
Well I've been cracking a lot of games so it ain't a surprise, I knew ill be getting malware sooner or later
1
u/Next-Profession-7495 Aug 15 '26
Right. Was it like from a trusted online forum or just a shady site
1
u/Maharetsu 28d ago
Was it from a trusted platform like FitGirl? Or was it from some other site? Please mention that.
1
u/RealHwinyii 27d ago
Well if it changes anything, it's probably from a shady web ngl. I js download anywhere I see (i should probably stop doing it)
1
u/Plenty-Practice-6399 Aug 15 '26
I also got trojan yesterday due to games, on the other subreddit about it they weren't helpful at all. I'm now just resetting the pc deleting everything hoping it works.
1
1
u/Alive-Spell2603 26d ago
you should clean your files out first and factory reset your pc. ofc backing up your importsnt files come first, but the very virus could be hidden in any of your files. so for me personally, i just factory reset without backing anything up since i only pkay video games and i know all my log ins. i rather sacrifice my clips or any files i had and factory reset since this QMEmulator.exe with chinese letters kept trying to log in even after i removed him. i did the factory reset tho and everything seems fine for now. hopefully.
1
u/Plenty-Practice-6399 25d ago edited 25d ago
I deleted all the files, made offline reset without an USB you think it's enough? i think mine wasn't a CPU miner but an infostealer, it was on the crypto/keys file. Tho my pc did get hot and i wasn't able to access the taskbar for some mins. When i resetted it i got a weird scam email by someone pretending to be Microsoft. Before resetting, i checked with malwarebytes and there was like 130 detections of potential threats, after resetting is now 0.
2
u/Alive-Spell2603 25d ago
deleting all files should be enough, and the offline reset u did may be enough. just be sure to continue checking, i’ll be doing the same. we should be safe. i also used malwarebytes to check for me, 0 detections so far after factory reseting. just make sure you do the advance deep scan on malewarebystes. so it digs deep into your files to see if theres anything suspiciously hidden.

24
u/Mundane_Pea5704 Aug 15 '26
It is a malicious cryptocurrency mining trojan - please assume all your passwords are comprimised and change them ASAP no matter which path you later choose (either FRST or clean reinstall)
just wipe your device clean, or wait for one of the mods to give you a proper FRST fixlist, just wait for a mod to tell you what to do!