Jump to content

Today I experience malware on my pc, it looked like Skype but it was like a porn site, no I do not watch porn on here, I have a vpn, avg antivirus and malwarebytes on the pc, on task manager I found several Skype.exe processes which I ended and deleted, scanned and wiped with avg, malwarebytes, HitmanPro and Windows security, I have reinstalled windows as an update, I chose the option to keep personal files and apps. The two possible ways i got the malware were by the two games I installed from the Microsoft Store, Car Mechanic 2018 and Extreme Offroad, don't know which did it but I dont know anywhere else where i got the malware.

 

The problem I have is that I dont know if that did the trick, according to the scans the pc is clean, but in the task manager I see repeated processes, Nvidia Container, COM surrogate, Runtime Brooker, btw I have deleted all of Nvidias software. Did the same for avg due to more processes appearing after a restart.

 

are these repeated processes normal or should I do a format wipe and reinstall of windows? 

 

 

SharedScreenshot1.jpg.b5c8799189683419c30c4cf04ac14686.jpgSharedScreenshot.thumb.jpg.98e246c4763fd1424dc9324abab3f566.jpgSharedScreenshot2.jpg.d297c68d6215b2eb6334103c762dca62.jpg

Link to comment
https://linustechtips.com/topic/1306789-need-help-with-malware/
Share on other sites

Link to post
Share on other sites

you chose to keep your files so some of the aforementioned processes(nvidia etc) could have carried over

gaming system: Intel core I9 12900ks / biostar Z690A valkyrie / 4x8gb corsair Vengeance @3333Mhz ram / RX 7900XTX pulse gpu / Thermalright peerless assassin 140 /Coolermaster Qube 500 case / Be Quiet Dark Power Pro 12 1500w power supply

 

laptop: Dell xps 9510, 3.5k OLED, i7 11800h, rtx 3050 ti, 2x16gb DDR4 @ 3200Mhz, 1TB main drive, 2TB add in ssd

Link to comment
https://linustechtips.com/topic/1306789-need-help-with-malware/#findComment-14491557
Share on other sites

Link to post
Share on other sites

"Runtime Broker" is a Windows process. It manages permissions for Microsoft Store apps. Having that running multiple times is not a clear indication of malware.

 

Likewise "COM Surrogate" is a system process from Windows, that is used to host services. So it is normal to see multiple of these running and it is not a clear indicating of any malware.

Remember to either quote or @mention others, so they are notified of your reply

Link to comment
https://linustechtips.com/topic/1306789-need-help-with-malware/#findComment-14491585
Share on other sites

Link to post
Share on other sites

why would you delete nvidia stuff if you have a nvidia card it won't function properly. 

 

Also that startup screen is a nightmare, so is half of your processes, I would clean install and not install any crap you found on the internet anymore tbh. 

 

- - OK regarding nvidia 

3 hours ago, Voltz said:

I Deleted all of Nvidias software to see if the processes would disappear.

run DDU in safe mode, remove everything nvidia and see if those two processes disappear. if not it's time to fresh install with no carry overs from old system (imo) 

The direction tells you... the direction

-Scott Manley, 2021

 

 

Link to comment
https://linustechtips.com/topic/1306789-need-help-with-malware/#findComment-14491933
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×