Help Please !
Well i was checking out this Process viewing tool today , and i found something very weird :
http://prntscr.com/ab75hd
If you check the screenshot you can see many ie processes , and i havnt used it for over a year maybe.
Also they opened alone suddently all together.
I tried checking the IPs i was connecting to , but couldn’t find anything
Should i worry about anything ?
UPDATE :
I went to task manager , and found that even when closed internet explored is using a lot of DISK …
I got no idea what is happening but i guess its some sort of virus .
Went to uninstall a program to check if theres something weird and found that the IP appearing is the one of Hotspot shield which is from a verified publisher.
Should i uninstall it or try to run Malwarebytes ?
Well, the image actually only shows one process. What you are seeing are all of its open connections, many of which don’t seem that strange (ad networks).
Not sure what you mean by that it is using a lot of “disk” when closed. If it is really closed, it can’t use anything. Also not sure how you found an IP when uninstalling a program.
If you don’t trust it, yes, run antivirus and antimalware. Check your installed programs for anything odd. If IE is running, you might be able to see its parent in the tree view some of these “process viewing tools” have (or by checking its ppid).
I misexplained what i meant:
Here : http://prntscr.com/ab8ih6
IE Was using about 250mb of disk even when closed as you can see its 50mb now , a bit more reasonable cause i ran antimalware and quarantined everything.
And when i went to uninstall a program , i found that the name of the company that shared Hotsport Shield is SOMETHING … And the ip i found in the Proccess viewer corresponded to the SOMETHING .
Anyway if you’re saying its normal than its ok , i just removed over 70 threats of my pc with antimalware :P
Taking pentesting free courses online recently and i had to risk it and download some untrusted softwares.
What do you use for antivirus or antimalware? I’m running Windows Defender rn, soooooo. I need good software, based on the amount of shit i’ve got. Well, I am just now getting Malwarebytes… So yah lol
– BlackVikingPro | blackvikingpro.com
Do not download + install non-trusted softwares ! Or run them into some VM / Unconnected test computer ( if you have old XP computers for example :p )
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
Well i truned out to be in a hell bigger of a problem i think.
I realised that i was using bandwith even when i wasnt using anything , checked the processes again and found something weird :
Medlight.exe
I googled it and found that its a malware but not that dangerous , working on removing it now.
I also realised that svchost was using like 0.4mb/s of download constantly , soo i’m gonna google the problem further tomorrow to check how to know if its a real svchost or a trojan named like that.
If anyone could give advice id be glad
Thanks
And BlackKing i use Lavasoft , and antimalware bites and now im downloading Unhack me ,and im pretty sure i have a few more :P
@Nastyblood**: That’s not disk usage but memory usage.
Don’t see why you’d need to install such things for courses, but if you really need to, do as @Mugiwara27 said, don’t do it on your main system.
My internet is too slow to download the OS for the virtual machine :P
Anw i just succeeded removing Medlight.exe , still got to download some bandwith thing program that will help me limit the bandwith used by svchost .
Damn svchost has used like 1gb in the last hour …
IF i wanted to download a 200mb file it would have took me 3 hours…
Thanks for the help guys , if anyone is facing the same problem :
Download Malware Bytes and run a full scan .
If svc host is using bandwith then download net balancer and limit it’s download and upload rate or just disable it , which is what i did.
Net balancer is a really good program that shows how much every process running is using of your bandwith i suggest it to anyone to keep track of their bandwith usage.
Thanks again :)
Just download the OS for 15 hours ( 1 GB ) and it will be done :)
If you’re that afraid of malware, just reset your computer lol
Also, you shouldn’t be reckless with what you’re doing with Windows’s system process !
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
Well i limited the svchost’s download time to 2am till 6 am and limited the download speed to 10kb/s .
Today i realised it’s still downloading . I’ll google for a solution but meanwhile if anyone of you got any idea anything would help thanks.
+1 for bkth’s idea !
Using Windows will not give you full access to system’s settings
Where as, using an unix distro, you’ll have a full access to everything !
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
So you mean if i disable windows processes using Net Balancer it wont work ?
I Should do it using unix distro ?
I’ve been trying all day and its still using a lot of bandwith
I don’t think using some software will help you with this problem since you’re dealing with main windows’s process
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1
I Did enter something in services through run by entering services something and disabled svchost background intelligence thing , which is the one responsible of the background updates of windows or something like that .
It’s been 2 hours for now and the bandwith usage while everything is closed is 0 for now .
Gonna give it a few days if i still face the problem ill consider resetting my laptop.
If this thing you done succeed, could you post what you done here? So if anyone else have this problem, we’ll just have to redirect him on this thread !
Thanks :)
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘\’‘ at line 1