Operaghost
[H]ard|Gawd
- Joined
- Jun 4, 2004
- Messages
- 1,315
I had installed the latest Utorrent the day before and noticed it added a bunch of toolbar shit to my browsers as well as changed my homepage.
I googled how to remove these things and did so.
I noticed a few days ago when playing a game that I was getting serious FPS lag.So I closed out all my programs and checked task manager.
I noticed that at idle my system was using 30-40% of my 6GB of RAM.
Then I noticed some processes that I'd never seen there before:
1. winlogon.exe
2. csrss.exe
3. nvvsvc.exe
4. nvxdsync.exe
None of these programs have any description, cannot have the properties viewed, nor can they be ended.
So I immediately ran Malwarebytes, Spybot, NOD32. None of them turned up anything and the processes persisted. Then I rebooted, and noticed after logging in that Malwarebytes had not loaded with windows.
I then followed the process found on this forum for removing malware, etc.
I made sure all my anti malware programs were up to date. I ran CCleaner and cleaned thoroughly including registry. I booted into safe mode and ran all Malwarebytes, which came up with 3 threats:
1. Trojan.Utanioz
2. Two instances of PUP.Optional.Conduit.A
I cleaned these items then ran SuperAntiSpyware, which found nothing.
I then ran Spybot which found nothing.
I then ran a full scan with MS Security Essentials, nothing
I rebooted and ran CCleaner again.
Checked Task Manager and found that the processes were still there.
So I decided I would reinstall windows 7.
I downloaded all my drivers, and the newest versions of anti malware programs.
I booted to Win7 disk, went to repair, opened command prompt, cleaned the 2 partitions of my SSD that I had windows installed to. Removed the partitions, created a new partition, formatted it.
Then I booted to disk again, went through Win7 install, formatted the partition again and installed to it.
As soon as I got to my desktop I checked task manager again, and there were the two damn processes again, with no description, no properties and unable to be ended.
1. winlogon.exe
2. csrss.exe
My RAM usage was lower at idle, but still using 10-12%.
Now I don't know how this problem persisted through a clean install of windows but it seems to have found a way.
I installed my drivers including video and I noticed that the other two suspicious un-described processes are back:
1. nvvsvc.exe
2. nvxdsync.exe
And my RAM usage at idle is up to 20% now.
I have 2 other Hardrives in my system that I install 99% of my programs to, including my antimalware programs, games, multimedia programs, etc.
1. Is it possible that the trojan or whatever it is somehow got rooted on one of these other drives, then infiltrates windows from there?
2. Does anyone have any recommendations on how to proceed?
I am going to search my drives for these 2 exe files now and will post pictures of my results.
I googled how to remove these things and did so.
I noticed a few days ago when playing a game that I was getting serious FPS lag.So I closed out all my programs and checked task manager.
I noticed that at idle my system was using 30-40% of my 6GB of RAM.
Then I noticed some processes that I'd never seen there before:
1. winlogon.exe
2. csrss.exe
3. nvvsvc.exe
4. nvxdsync.exe
None of these programs have any description, cannot have the properties viewed, nor can they be ended.
So I immediately ran Malwarebytes, Spybot, NOD32. None of them turned up anything and the processes persisted. Then I rebooted, and noticed after logging in that Malwarebytes had not loaded with windows.
I then followed the process found on this forum for removing malware, etc.
I made sure all my anti malware programs were up to date. I ran CCleaner and cleaned thoroughly including registry. I booted into safe mode and ran all Malwarebytes, which came up with 3 threats:
1. Trojan.Utanioz
2. Two instances of PUP.Optional.Conduit.A
I cleaned these items then ran SuperAntiSpyware, which found nothing.
I then ran Spybot which found nothing.
I then ran a full scan with MS Security Essentials, nothing
I rebooted and ran CCleaner again.
Checked Task Manager and found that the processes were still there.
So I decided I would reinstall windows 7.
I downloaded all my drivers, and the newest versions of anti malware programs.
I booted to Win7 disk, went to repair, opened command prompt, cleaned the 2 partitions of my SSD that I had windows installed to. Removed the partitions, created a new partition, formatted it.
Then I booted to disk again, went through Win7 install, formatted the partition again and installed to it.
As soon as I got to my desktop I checked task manager again, and there were the two damn processes again, with no description, no properties and unable to be ended.
1. winlogon.exe
2. csrss.exe
My RAM usage was lower at idle, but still using 10-12%.
Now I don't know how this problem persisted through a clean install of windows but it seems to have found a way.
I installed my drivers including video and I noticed that the other two suspicious un-described processes are back:
1. nvvsvc.exe
2. nvxdsync.exe
And my RAM usage at idle is up to 20% now.
I have 2 other Hardrives in my system that I install 99% of my programs to, including my antimalware programs, games, multimedia programs, etc.
1. Is it possible that the trojan or whatever it is somehow got rooted on one of these other drives, then infiltrates windows from there?
2. Does anyone have any recommendations on how to proceed?
I am going to search my drives for these 2 exe files now and will post pictures of my results.