Jump to content

what is attrib.exe and why is it running in the background?

Levitatin

okay so when ever i close my task manager and reopen it 3 mins later i see attribute utility (attrib.exe) using almost 100% of my cpu for a couple seconds and goes back down to 4-6%... i installed malwarebytes and ran a scan and i keep seeing this popping up. what do i do?

dmKikBf-SW_x-v9cq0myhA.jpeg

Link to comment
Share on other sites

Link to post
Share on other sites

sounds like somebody installed a crypto miner on your computer.

 delete it immediately

How do Reavers clean their spears?

|Specs in profile|

The Wheel of Time turns, and Ages come and pass, leaving memories that become legend. Legend fades to myth, and even myth is long forgotten when the Age that gave it birth comes again.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Tsuki said:

sounds like somebody installed a crypto miner on your computer.

 delete it immediately

okay how??

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Levitatin said:

okay so when ever i close my task manager and reopen it 3 mins later i see attribute utility (attrib.exe) using almost 100% of my cpu for a couple seconds and goes back down to 4-6%... i installed malwarebytes and ran a scan and i keep seeing this popping up. what do i do?

dmKikBf-SW_x-v9cq0myhA.jpeg

it's an old command from when dos was integrated, it changes attributes of files.. though it may have been compromized by something else and been exchanged with a virus or something.. 
the domain seems to go to some crypto currency mining thing, so it might be mining software.. but attrib should not access the web..

pack it into a zip/rar and delete it.. it isn't vital for windows so it should only disrupt any programs using it or stop any virus using it..

Have you tried to perform a sudden temporary interrupt of the electricity flow to your computational device followed by a re-initialization procedure of the central processing unit and associated components?


Personal Rig Specs

Spoiler

CPU: Intel Core i7-7700K @ 4.8GHZ
Motherboard: Asus ROG STRIX Z270H GAMING
Graphics Card: Inno3D ICHILL GEFORCE GTX 1080 TI X3 ULTRA
RAM: Corsair Vengeance LPX Black DDR4 2x8GB @ 3GHZ
Storage: 2 x Samsung NVMe SSD 960 EVO 256GB in Raid | 2 x Seagate 4TB Expansion Desktop 

(seagates are originally external drives removed from casing and installed internally)
PSU: Seasonic Prime Titanium 850W 
Case: Mission SG GGX 3.5 (same as Rosewill Cullinan or Anidees AI Crystal with other stock fans)
Cooling: Kraken X62 for CPU, Corsair H55 with NZXT Kraken G12 for GPU 

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Tsuki said:

sounds like somebody installed a crypto miner on your computer.

 delete it immediately

yup.. from minergate site

Quote

 

About MinerGate

MinerGate is a mining pool created by a group of cryptocoin enthusiasts.

It is the first pool which provides service for merged mining. This means that while mining on our pool you can mine different coins simultaniously without decrease of hashrate for major coin.

 


seems like someone installed a miner on your system.  to be sure, i would just backup and reinstall windows completely.. who knows what else they have changed..
 

Have you tried to perform a sudden temporary interrupt of the electricity flow to your computational device followed by a re-initialization procedure of the central processing unit and associated components?


Personal Rig Specs

Spoiler

CPU: Intel Core i7-7700K @ 4.8GHZ
Motherboard: Asus ROG STRIX Z270H GAMING
Graphics Card: Inno3D ICHILL GEFORCE GTX 1080 TI X3 ULTRA
RAM: Corsair Vengeance LPX Black DDR4 2x8GB @ 3GHZ
Storage: 2 x Samsung NVMe SSD 960 EVO 256GB in Raid | 2 x Seagate 4TB Expansion Desktop 

(seagates are originally external drives removed from casing and installed internally)
PSU: Seasonic Prime Titanium 850W 
Case: Mission SG GGX 3.5 (same as Rosewill Cullinan or Anidees AI Crystal with other stock fans)
Cooling: Kraken X62 for CPU, Corsair H55 with NZXT Kraken G12 for GPU 

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Changis said:

it's an old command from when dos was integrated, it changes attributes of files.. though it may have been compromized by something else and been exchanged with a virus or something.. 
the domain seems to go to some crypto currency mining thing, so it might be mining software.. but attrib should not access the web..

pack it into a zip/rar and delete it.. it isn't vital for windows so it should only disrupt any programs using it or stop any virus using it..

after i deleted it this kept popping up in 4 windows.

Screenshot_1.jpg

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Levitatin said:

after i deleted it this kept popping up in 4 windows.

Screenshot_1.jpg

reinstall windows and start fresh. don't allow others on your computer unless supervised and be very careful of programs you install and any piggybacked programs that try to slide past in the installation screens

Have you tried to perform a sudden temporary interrupt of the electricity flow to your computational device followed by a re-initialization procedure of the central processing unit and associated components?


Personal Rig Specs

Spoiler

CPU: Intel Core i7-7700K @ 4.8GHZ
Motherboard: Asus ROG STRIX Z270H GAMING
Graphics Card: Inno3D ICHILL GEFORCE GTX 1080 TI X3 ULTRA
RAM: Corsair Vengeance LPX Black DDR4 2x8GB @ 3GHZ
Storage: 2 x Samsung NVMe SSD 960 EVO 256GB in Raid | 2 x Seagate 4TB Expansion Desktop 

(seagates are originally external drives removed from casing and installed internally)
PSU: Seasonic Prime Titanium 850W 
Case: Mission SG GGX 3.5 (same as Rosewill Cullinan or Anidees AI Crystal with other stock fans)
Cooling: Kraken X62 for CPU, Corsair H55 with NZXT Kraken G12 for GPU 

 

Link to comment
Share on other sites

Link to post
Share on other sites

14 minutes ago, Levitatin said:

after i deleted it this kept popping up in 4 windows.

Screenshot_1.jpg

Well you just deleted a system32 file. Which will cause Windows to mess about.. 

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Abdul201588 said:

Well you just deleted a system32 file. Which will cause Windows to mess about.. 

if it's a real system32 file, windows won't allow you to delete it as it should be owned by trustedinstaller (windows), and it sure wouldn't start checkdisk because attrib.exe was missing...

Have you tried to perform a sudden temporary interrupt of the electricity flow to your computational device followed by a re-initialization procedure of the central processing unit and associated components?


Personal Rig Specs

Spoiler

CPU: Intel Core i7-7700K @ 4.8GHZ
Motherboard: Asus ROG STRIX Z270H GAMING
Graphics Card: Inno3D ICHILL GEFORCE GTX 1080 TI X3 ULTRA
RAM: Corsair Vengeance LPX Black DDR4 2x8GB @ 3GHZ
Storage: 2 x Samsung NVMe SSD 960 EVO 256GB in Raid | 2 x Seagate 4TB Expansion Desktop 

(seagates are originally external drives removed from casing and installed internally)
PSU: Seasonic Prime Titanium 850W 
Case: Mission SG GGX 3.5 (same as Rosewill Cullinan or Anidees AI Crystal with other stock fans)
Cooling: Kraken X62 for CPU, Corsair H55 with NZXT Kraken G12 for GPU 

 

Link to comment
Share on other sites

Link to post
Share on other sites

5 minutes ago, Changis said:

if it's a real system32 file, windows won't allow you to delete it as it should be owned by trustedinstaller (windows), and it sure wouldn't start checkdisk because attrib.exe was missing...

yeah i'm reinstalling windows 10 because now i have a process in the back called "helper.exe"

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, Changis said:

if it's a real system32 file, windows won't allow you to delete it as it should be owned by trustedinstaller (windows), and it sure wouldn't start checkdisk because attrib.exe was missing...

i took permission to delete it lol

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×