Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
High resources lead to me feeling as if i have been hijacked
#1
has anyone came accross the following key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\{7746D80F-97E0-4E26-9543-26B41FC22F79} i noticed my resources increasing while i was just on the main desktop looking at the screen well when id try to do something i noticed it was taking longer than usual so i checked my task manager and sure enough my ram disk and cpu was pretty high so i did some investigating and found this key {7746D80F97E0-4E26-9543-26B41FC22F79} and when id click on it i kept getting an error message saying i dont have the permissions to edit the key so i went into permissions and i found mine and a few other accounts but then i found account uknown     and i also noticed
.png   2016-11-24 06_16_23-TaskManagerMain.png (Size: 35.49 KB / Downloads: 619)  have i been hijacked or whats going on?

System Specs
https://speccy.piriform.com/results/Qg4aXt6nyRxWL4wXYZsZuLQ

Farbar Recovery scan tool Reports

.txt   Addition.txt (Size: 11.86 KB / Downloads: 2)

.txt   FRST.txt (Size: 6.61 KB / Downloads: 3)

.txt   FSS.txt (Size: 5.03 KB / Downloads: 1)

I also ran a full scan of mrt which said i had 2 infections but when the scan completed it said my system is clean and the same goes for mbam and hitmanpro

And i opened process explorer and found the services surrounded by the red rectangle and there something to do with service host
Reply

#2
run a sfc scannow
Reply

#3
I think its something to do with Microsoft, I think it even creates allow firewall rules. Got to be some sort of service, maybe Cortana....who knows.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#4
Check out the tool SysInspector. Doesn't rely on definitions. My techs and I use it at our shop when doing preliminary scans and investigation into whether a PC is infected or not. It has filtering based on levels. Red is almost always for sure a trojan, droppers, etc. It's pretty accurate. In the orange, about level 5, you can see things that are semi-suspicious, and would help you narrow down what corrupt processes are causing those entries.

I would also recommend SFC /ScanNow. And follow up with DISM /Online /Cleanup-Image /RestoreHealth if SFC says "found corruption but was unable to fix some of them."

Event Log can also be very handy when diagnosing issues. Not everything is a hijack or virus. Especially since Windows 8, corruption within the Component Store and other areas of the system can be delicate and can cause all sorts of weird issues.
Reply

#5
I think what happen is that the system was tweak causing the corruption remember windows 10/8,1 is already optimize for performance
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.