Jump to content

so hi,

i downloaded a dodgy file today, and clicked what i thought to be a .txt file but instead it was a minmized windows powershell script?what my friend said(he downloaded the same thing but didnt do anything with it)

it appears everything is using an abnormal amount of ram , i usually get 25% max ram usage 

how can i fix this, ive run malwarebytes and it came up with nothing

unknown.png

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/
Share on other sites

Link to post
Share on other sites

4 minutes ago, KOMTechAndGaming said:

so hi,

i downloaded a dodgy file today, and clicked what i thought to be a .txt file but instead it was a minmized windows powershell script?what my friend said(he downloaded the same thing but didnt do anything with it)

it appears everything is using an abnormal amount of ram , i usually get 25% max ram usage 

how can i fix this, ive run malwarebytes and it came up with nothing

unknown.png

Tried spybot?

 

Ryzen Ram Guide

 

My Project Logs   Iced Blood    Temporal Snow    Temporal Snow Ryzen Refresh

 

CPU - Ryzen 1700 @ 4Ghz  Motherboard - Gigabyte AX370 Aorus Gaming 5   Ram - 16Gb GSkill Trident Z RGB 3200  GPU - Palit 1080GTX Gamerock Premium  Storage - Samsung XP941 256GB, Crucial MX300 525GB, Seagate Barracuda 1TB   PSU - Fractal Design Newton R3 1000W  Case - INWIN 303 White Display - Asus PG278Q Gsync 144hz 1440P

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344325
Share on other sites

Link to post
Share on other sites

1 minute ago, stealth80 said:

Tried spybot?

i shall try

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344329
Share on other sites

Link to post
Share on other sites

Let's all agree to use this as a learning experience. Try looking under details to see if you find something unusual.

Current System: CPU - I5-6500 | Motherboard - ASRock H170M-ITX/ac | RAM - Mushkin Blackline 16GB DDR4 @ 2400mHz | GPU - EVGA 1060 3GB | Case - Fractal Design Nano S | Storage - 250GB 850 EVO, 3TB Barracuda | PSU - EVGA 450W 80+ Bronze | Display - AOC 22" 1080p IPS | Cooling - Phanteks PH-TC12DX_BK | Keyboard - Cooler Master QuickFire Rapid(MX Blues) | Mouse - Logitech G602 | Sound - Schiit Stack | Operating System - Windows 10

 

The OG System: I3-2370M @ 2.4 GHz, 750GB 5400 RPM HDD, 8GB RAM @1333Mhz, Lenovo Z580 Laptop (Ubuntu 16.04 LTS).

 

Peripherals: G602, AKG 240, Sennheiser HD 6XX, Audio-Technica 2500, Oneplus 5T, Odroid C2(NAS).

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344330
Share on other sites

Link to post
Share on other sites

1 minute ago, MrImnotMLG said:

Let's all agree to use this as a learning experience. Try looking under details to see if you find something unusual.

i cant seem to find anything unusual besides notepad being open and using 300mb of ram :/ besides that everything seems fine

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344334
Share on other sites

Link to post
Share on other sites

2 minutes ago, KOMTechAndGaming said:

i cant seem to find anything unusual besides notepad being open and using 300mb of ram :/ besides that everything seems fine

yeah I've done something stupid like this before. i ended up just reinstalling windows because it was too much work to figure it out and the computer was getting a bit cluttered anyways. 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344350
Share on other sites

Link to post
Share on other sites

3 minutes ago, KOMTechAndGaming said:

i cant seem to find anything unusual besides notepad being open and using 300mb of ram :/ besides that everything seems fine

really? everything is using 300mb. even task manager.

it's not normal.

QUOTE/TAG ME WHEN REPLYING

Spend As Much Time Writing Your Question As You Want Me To Spend Responding To It.

If I'm wrong, please point it out. I'm always learning & I won't bite.

 

Laptop:

Lenovo Yoga 7 Air: Ryzen 7840S, 32GiB DDR5

 

Desktop (Old but I never replaced it):

Delidded Core i7 4770K - GTX 1070 ROG Strix - 16GB DDR3 @2000Mhz

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344353
Share on other sites

Link to post
Share on other sites

If it was a powershell script you should easily be able to see what it does. Try posting some code out of it when you open it as a textfile. There are a ton of executables like this that will never get detected by anti-virus. They connect to a control server to punch trough the firewall from the inside out, from thereon they can potentially do anything. You can always try taking a look at your connection log should your router support that. 

 

I had to reinstall a server recently because it was connection to controlservers in Russia and China.... MBAM and Spybot couldn't detect a thing.

There is no such thing as IRL, there is only AFK...

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344355
Share on other sites

Link to post
Share on other sites

4 minutes ago, KOMTechAndGaming said:

i cant seem to find anything unusual besides notepad being open and using 300mb of ram :/ besides that everything seems fine

its hidden and its waiting for right time to strike just reinstall windows.

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344358
Share on other sites

Link to post
Share on other sites

1 minute ago, RadiatingLight said:

really? everything is using 300mb. even task manager.

it's not normal.

i already know i dun fucked up

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344359
Share on other sites

Link to post
Share on other sites

1 minute ago, Terrorjoekel said:

If it was a powershell script you should easily be able to see what it does. Try posting some code out of it when you open it as a textfile. There are a ton of executables like this that will never get detected by anti-virus. They connect to a control server to punch trough the firewall from the inside out, from thereon they can potentially do anything. You can always try taking a look at your connection log should your router support that. 

 

I had to reinstall a server recently because it was connection to controlservers in Russia and China.... MBAM and Spybot couldn't detect a thing.

it ran minimized never saw what it does :/

and it was forced minimized 

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344363
Share on other sites

Link to post
Share on other sites

1 minute ago, KOMTechAndGaming said:

it ran minimized never saw what it does :/

and it was forced minimized 

I'm guessing it was not a powershell script then, powershell scripts can easily be read with any textprocessor such as notepad. A compiled executable will be a whole other story.

There is no such thing as IRL, there is only AFK...

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344377
Share on other sites

Link to post
Share on other sites

1 minute ago, Terrorjoekel said:

I'm guessing it was not a powershell script then, powershell scripts can easily be read with any textprocessor such as notepad. A compiled executable will be a whole other story.

my friend said it was something like that :/ then idk wtf it is, when i double clicked it, windows said do you want to run it-

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344393
Share on other sites

Link to post
Share on other sites

18 minutes ago, KOMTechAndGaming said:

so hi,

i downloaded a dodgy file today, and clicked what i thought to be a .txt file but instead it was a minmized windows powershell script?what my friend said(he downloaded the same thing but didnt do anything with it)

it appears everything is using an abnormal amount of ram , i usually get 25% max ram usage 

how can i fix this, ive run malwarebytes and it came up with nothing

unknown.png

Either reinstall windows (and be very careful what you back up, some of the more sophisticated worms and viruses can infect everything but I've never seen it first hand.) If you want you can quanintine the PC and spend the next million years looking. Maybe try an avast! boot time scan, that can find some of more hidden attacks, but I'm sure windows reinstall is all that'll help.

Yours faithfully

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344405
Share on other sites

Link to post
Share on other sites

1 minute ago, Lord Nicoll said:

Either reinstall windows (and be very careful what you back up, some of the more sophisticated worms and viruses can infect everything but I've never seen it first hand. If you want you can quanintine the PC and spend the next million years looking. Maybe try an avast! boot time scan, that can find some of more hidden attacks, but I'm sure windows reinstall is all that'll help.

i have 760GB of games on a seperate drive, can unplug said drive and reinstall windows and thenredirect steam/origin? 

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344411
Share on other sites

Link to post
Share on other sites

1 minute ago, KOMTechAndGaming said:

i have 760GB of games on a seperate drive, can unplug said drive and reinstall windows and thenredirect steam/origin? 

Yes, you can tell steam where the drive is, while I'm doubtful it could spread that much, it already seems epidemic and well hidden. 

Yours faithfully

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344417
Share on other sites

Link to post
Share on other sites

2 minutes ago, Lord Nicoll said:

Yes, you can tell steam where the drive is, while I'm doubtful it could spread that much, it already seems epidemic and well hidden. 

What ever the two processes are hear 500mb each are i can kill them fine but they keep coming back and they definitely werent there before

IMG_0802.JPG

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344431
Share on other sites

Link to post
Share on other sites

10 minutes ago, Terrorjoekel said:

I'm guessing it was not a powershell script then, powershell scripts can easily be read with any textprocessor such as notepad. A compiled executable will be a whole other story.

powershell scripts can easily be run minimized.

 

12 minutes ago, KOMTechAndGaming said:

it ran minimized never saw what it does :/

and it was forced minimized 

right click the file and if it's a script then select "edit", that should open it in notepad.

 

Also make sure to unhide file extentions in Windows, that will prevent things like this to happen.

If you need help with your forum account, please use the Forum Support form !

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344437
Share on other sites

Link to post
Share on other sites

1 minute ago, KOMTechAndGaming said:

What ever the two processes are hear 500mb each are i can kill them fine but they keep coming back and they definitely werent there before

IMG_0802.JPG

Well they're probably it, try and isolate them, idk if normal windows has any options like that. You'll need to hunt them down, but use an avast boot time scan, but it might take upwards of 5 hours, I once ran it on a server with a RAID 5 array and 12 TB, it took 18 hours.....

Yours faithfully

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344440
Share on other sites

Link to post
Share on other sites

2 minutes ago, KOMTechAndGaming said:

What ever the two processes are hear 500mb each are i can kill them fine but they keep coming back and they definitely werent there before

*snip*

 

right click the process and select "go to detail", that should give you more info on what's going on.

If you need help with your forum account, please use the Forum Support form !

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344444
Share on other sites

Link to post
Share on other sites

reinstall windows. unplug all drives except for the boot drive (or don't, but just don't touch the partitions on the extra drives, which requires you to know the drive numbers.)

QUOTE/TAG ME WHEN REPLYING

Spend As Much Time Writing Your Question As You Want Me To Spend Responding To It.

If I'm wrong, please point it out. I'm always learning & I won't bite.

 

Laptop:

Lenovo Yoga 7 Air: Ryzen 7840S, 32GiB DDR5

 

Desktop (Old but I never replaced it):

Delidded Core i7 4770K - GTX 1070 ROG Strix - 16GB DDR3 @2000Mhz

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344532
Share on other sites

Link to post
Share on other sites

1 hour ago, RadiatingLight said:

reinstall windows. unplug all drives except for the boot drive (or don't, but just don't touch the partitions on the extra drives, which requires you to know the drive numbers.)

 

1 hour ago, wkdpaul said:

 

right click the process and select "go to detail", that should give you more info on what's going on.

 

1 hour ago, Lord Nicoll said:

Well they're probably it, try and isolate them, idk if normal windows has any options like that. You'll need to hunt them down, but use an avast boot time scan, but it might take upwards of 5 hours, I once ran it on a server with a RAID 5 array and 12 TB, it took 18 hours.....

i just reinstalled windows and wiped eveyrthing but my steam drive, eveyrthing seems to be fine now

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9344739
Share on other sites

Link to post
Share on other sites

13 hours ago, Lord Nicoll said:

Well that's good, but sure sucks. Remember to do weekly backups

 

dont have the spare storage to do so :/ i didnt lose anything important/anything i can get back easily

CPU: Intel9-9900k 5.0GHz at 1.36v  | Cooling: Custom Loop | MOTHERBOARD: ASUS ROG Z370 Maximus X Hero | RAM: CORSAIR 32GB DDR4-3200 VENGEANCE PRO RGB  | GPU: Nvidia RTX 2080Ti | PSU: CORSAIR RM850X + Cablemod modflex white cables | BOOT DRIVE: 250GB SSD Samsung 850 evo | STORAGE: 7.75TB | CASE: Fractal Design Define R6 BLackout | Display: SAMSUNG OLED 34 UW | Keyboard: HyperX Alloy elite RGB |  Mouse: Corsair M65 PRO RGB | OS: Windows 10 Pro | Phone: iPhone 11 Pro Max 256GB

 

Link to comment
https://linustechtips.com/topic/736117-halp-plez/#findComment-9347231
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×