Androo Posted April 14, 2022 ID:1511303 Share Posted April 14, 2022 Hello! Recently I've been experiencing some issues with my GPU performance and it seemed to be happening because the latest Windows 11 update (insider build). Yesterday I decided to install and run Malwarebytes and after the initial clean-up 2 executable files (ZoomX.exe and ZoomE.exe) keep popping up regularly and at the same time. There are no other symptoms other than the slight GPU performance decrease so I'm not exactly sure what's happening. I have also attached a screenshot of my GPU clock and memory clock speeds. Has anyone else encountered this? I will provide all the logs and scans needed if it's something worrisome. Link to post Share on other sites More sharing options...
TwinHeadedEagle Posted April 14, 2022 ID:1511304 Share Posted April 14, 2022 (edited) Hi, Those files are indeed suspicious. Please attach MalwareBytes logs and also logs from this topic. I'm infected - What do I do now? - Windows Malware Removal Help & Support - Malwarebytes Forums Someone will take a look and assist you. Edited April 14, 2022 by TwinHeadedEagle Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511315 Share Posted April 14, 2022 (edited) Hello @Androo and My name is MKDB and I will assist you. Like TwinHeadedEagle already said, please attach the MBAM logfile as well as those from Farbar Recovery Scan Tool (FRST). Thank you! I will guide you along on looking for potential malware. Lets keep these principles as we go along. Searching, detecting and removing malware isn't instantaneous, please be patient. Please stick with me until I give you the "all clear". Only run the tools I guide you to. Please don't run any other scans, download, install or uninstall any programs while I'm working with you. Cracked or hacked or pirated programs are not only illegal, but also will make a computer a malware victim. Having such programs installed, is the easiest way to get infected. It is the leading cause of ransomware encryptions. It is at times also big source of current trojan infections. Please uninstall them now, if any are here, before we start the cleaning procedure. Edited April 14, 2022 by MKDB Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511316 Share Posted April 14, 2022 Hello MKDB, here you go. Addition.txtFRST.txtI also ran 2 Malwarebytes scans (a quick and a full scan). As per your request I have only quarantined the malware found. Do I have the green light to delete them? malwarebyte results.txt malwarebyte full scan results.txt Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511318 Share Posted April 14, 2022 Also, there is something odd going on. The ZoomE/X alerts keep popping up at very precise times. Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511322 Share Posted April 14, 2022 Update. Tried running another MWB scan and for some reason it got canceled. It reports some sort of bitcoin miner that was put in quarantine. There is no such file in the 'Quarantined items' section of the program. 302691803_malwarebyteresults.txt Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511323 Share Posted April 14, 2022 This is a scan result from yesterday. Think this might help.scan.txt Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511326 Share Posted April 14, 2022 Thank you very much for the logfiles @Androo. I'm having a look on them now. Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511327 Share Posted April 14, 2022 (edited) The Logfile FRST.txt is incomplete. The first part is missing. Can you please reboot your system and run FRST again and attach the logfiles. Thank you @Androo Step 1 Run FRST again. Do not change any settings. Press the Scan button. FRST will create two logs now (FRST.txt + Addition.txt) in the same directory the tool is run. Please attach these logfiles to your next reply. Edited April 14, 2022 by MKDB Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511328 Share Posted April 14, 2022 Will do as soon as I get back home. Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511329 Share Posted April 14, 2022 That's great, thank you. Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511418 Share Posted April 14, 2022 Here you go. @MKDB Addition.txtFRST.txt Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511419 Share Posted April 14, 2022 Thanks @Androo. Looking into it... Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511421 Share Posted April 14, 2022 Update regarding the malware name. It is now displayed as 'Trojan.BitCoinMiner' Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511430 Share Posted April 14, 2022 (edited) We are running a fix with FRST (Step 1). After that, we do another check with FRST (Step 2). Thanks @Androo. Step 1 Please download the attached fixlist.txt file and save it to the location where you ran FRST from ( C:\Users\Andrei\Desktop\New folder\ ). Note: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work. Close all open programs and save your work. Run FRST again. Press the Fix button only once and wait. Please be patient. If the tool needs a restart, please make sure you let the system restart normally and let the tool complete its run after restart. FRST will create one log now (Fixlog.txt) in the same directory the tool is run. Please attach this logfile to your next reply. Step 2 Run FRST again. Do not change any settings. Press the Scan button. FRST will create two logs now (FRST.txt + Addition.txt) in the same directory the tool is run. Please attach these logfiles to your next reply. fixlist.txt Edited April 14, 2022 by MKDB Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511435 Share Posted April 14, 2022 Don e @MKDB Fixlog.txt FRST.txt Addition.txt Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511440 Share Posted April 14, 2022 Great @Androo. 🙂 Does MBAM still detect this BitCoinMiner? While I'm analyzing your logfiles, please run MSS for me. Thank you again! Step 1 The Microsoft Safety Scanner (MSS) is a free Microsoft stand-alone virus scanner that can be used to scan for & remove malware or potentially unwanted software from a system. The download links & the how-to-run-the tool are at this link at Microsoft. Please let me know the results of this scan. Run a Quick Scan. The log is named MSERT.log. The log will be at%SYSTEMROOT%\debug\msert.log which in most cases is C:\Windows\debug\msert.log Please attach that log with your next reply. It's just after 11:30pm here, I'll be back tomorrow. Link to post Share on other sites More sharing options...
Androo Posted April 14, 2022 Author ID:1511445 Share Posted April 14, 2022 Update. MWB no longer detects any ZoomX or ZoomE. However, each time I open the task manager, for a very brief moment, the gpu load is at about ~30-40% and it quickly goes back to 0. Also the GPU clock and memory clock spikes are still there. Every time I open the task manager a spike appears. We'll talk tomorrow, thanks! 😁 msert.log Link to post Share on other sites More sharing options...
MKDB Posted April 14, 2022 ID:1511448 Share Posted April 14, 2022 Thanks for the feedback @Androo. Please run another scan for me until I can check your newest logfiles. See you tomorrow. You're doing great! Step 1 Please download and run the Kaspersky Virus Removal Tool to remove any found threats. More information here. Let me know if it finds anything or not. You can find a logfile under Report. Link to post Share on other sites More sharing options...
MKDB Posted April 15, 2022 ID:1511494 Share Posted April 15, 2022 Good morning @Androo. After you have run Kaspersky Virus Removal Tool, please run the following fix with FRST. We are going to remove some orphans and check Windows System Files. This may take some time (>15 min), please be patient. You should not run any other application during this fix. Thank you! Step 1 Please download the attached fixlist.txt file and save it to the location where you ran FRST from. Note: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work. Close all open programs and save your work. Run FRST again. Press the Fix button only once and wait. Please be patient. If the tool needs a restart, please make sure you let the system restart normally and let the tool complete its run after restart. FRST will create one log now (Fixlog.txt) in the same directory the tool is run. Please attach this logfile to your next reply. fixlist.txt Link to post Share on other sites More sharing options...
Androo Posted April 15, 2022 Author ID:1511539 Share Posted April 15, 2022 Hello @MKDB. No malware found after a quickscan with Kaspersky. Ran the fix, the GPU issue is still there. I've attached the logs and also ran another scan with Farbar, just in case.Addition.txtFRST.txtFixlog.txt Link to post Share on other sites More sharing options...
Androo Posted April 15, 2022 Author ID:1511541 Share Posted April 15, 2022 Should I run the Kaspersky scan on the system drive as well? Link to post Share on other sites More sharing options...
MKDB Posted April 15, 2022 ID:1511600 Share Posted April 15, 2022 Hi @Androo, thank you for those logfiles. I'm glad that Kaspersky came back clean. Your latest fix ran fine, the newest logfiles look good. There is just one little thing we should look at. You can run Kaspersky on system drive as well. This may take some time. I assume that your GPU problems are based on your latest windows updates. Step 1 Please download the attached fixlist.txt file and save it to the location where you ran FRST from. Note: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work. Close all open programs and save your work. Run FRST again. Press the Fix button only once and wait. Please be patient. If the tool needs a restart, please make sure you let the system restart normally and let the tool complete its run after restart. FRST will create one log now (Fixlog.txt) in the same directory the tool is run. Please attach this logfile to your next reply. fixlist.txt Link to post Share on other sites More sharing options...
Androo Posted April 16, 2022 Author ID:1511678 Share Posted April 16, 2022 Here's the log. Fixlog.txt Let me know if there are any more scans/steps left to do. Link to post Share on other sites More sharing options...
Solution MKDB Posted April 16, 2022 Solution ID:1511690 Share Posted April 16, 2022 Hello @Androo ! Thank you for your cooperation, we're done. Final Step Right-Click on FRST64 and choose Rename. Rename FRST64 into Uninstall. Run Uninstall. FRST and it’s files/folders will be deleted. If the tool needs a restart, please make sure you let the system restarts normally. A few final recommendations: Recommend using a Password Manager for all websites, etc. that require a password. Never use the same password on more than one site.https://www.howtogeek.com/240255/password-managers-compared-lastpass-vs-keepass-vs-dashlane-vs-1password/ Make sure you're backing up your files https://forums.malwarebytes.com/topic/136226-backup-software/ Keep all software up to date - PatchMyPC - https://patchmypc.com/home-updater#download Keep your Operating System up to date and current at all times - https://support.microsoft.com/en-us/windows/windows-update-faq-8a903416-6f45-0718-f5c7-375e92dddeb2 Further tips to help protect your computer data and improve your privacy: https://forums.malwarebytes.com/topic/258363-tips-to-help-protect-from-infection/ Please consider installing the following Content Blockers for your Web browsers if you haven't done so already. This will help improve overall security Malwarebytes Browser Guard Google Chrome: https://chrome.google.com/webstore/detail/malwarebytes-browser-guar/ihcjicgdanjaechkgeegckofjjedodee Microsoft Edge: https://support.malwarebytes.com/hc/en-us/articles/4413298736787-Install-Malwarebytes-Browser-Guard-on-Microsoft-Edge-browser Mozilla Firefox: https://addons.mozilla.org/en-US/firefox/addon/malwarebytes/ uBlock Origin Google Chrome: https://chrome.google.com/webstore/detail/ublock-origin/cjpalhdlnbpafiamejdnhcphjbkeiagm Microsoft Edge: https://microsoftedge.microsoft.com/addons/detail/ublock-origin/odfafepnkmbhccpbejgmiehpchacaeak Mozilla Firefox: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin Further reading if you like to keep up on the malware threat scene: Malwarebytes Blog https://blog.malwarebytes.com/ Hopefully, we've been able to assist you with correcting your system issues. Thank you for using Malwarebytes. Link to post Share on other sites More sharing options...
Recommended Posts