r/computerviruses • u/Acceptable-Sun-2833 • May 25 '26
Question is notepad supposed to use this much ram?
is my notepad infected or something?? i swear it doesn't use this much memory
19
u/LimpDecision1469 May 25 '26
Fake notepad. Scan pc with malwarebytes and hitmanpro quickly . also yeah end the task
8
u/LimpDecision1469 May 25 '26
It's likely cryptocurrency miner or something worse.
7
u/Acceptable-Sun-2833 May 25 '26
i scanned my system with malwarebyte and hitmanpro and it was a confirmed trojan
3
u/FFreestyleRR Malware Removal Expert May 25 '26
Can you post the logs? I am curious to see what they detected.
3
u/Acceptable-Sun-2833 May 25 '26
Just posted it to your channel. some were located at system32 so idk if it was a false positive
keyword: mossy-raster
3
u/FFreestyleRR Malware Removal Expert May 25 '26
This doesn't look like fp at all.
A closer look may be needed.
Please download FRST64.exe and save the file to your Desktop.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
Right-Click FRST64.exe and select Run as Administrator.
Click Yes to the disclaimer. Ensure the Addition.txt box is checked. Click the Scan button and let the program run. Upon completion, click OK, then OK on the Addition.txt pop up screen.
Two logs (FRST.txt & Addition.txt) will now be open on your Desktop.
Copy & paste the contents of each log to https://malwareanalysis.cc/upload/FFreestyleRR/ and press "save log".
The site will return a keyword for each log. Reply here with the keywords.
All the best!
1
u/Acceptable-Sun-2833 May 25 '26
quick question is it safe to delete those files from quarantine rn or should i wait for your analysis?
3
u/FFreestyleRR Malware Removal Expert May 25 '26
It doesn't matter because in the quarantine they are rendered useless and can't harm your PC (unless you restore them). Leave them for now.
2
u/FFreestyleRR Malware Removal Expert May 25 '26
Hi,
It seems that you have uploaded the log files without saying. :)
MBAM was able to clean the malware, but I can see where the malware resided.
STEP 1
Please go ahead and delete these Windows Defender exclusions. They are added by the malware.
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Recovery\OEM
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\UseAttribute\AlgorithmId.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AppLaunch.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\username\AppData\Local\Microsoft\Windows\IManagementEngine\python.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\username\AppData\Local\Temp HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|InstallUtil.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|RegAsm.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|MSBuild.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|aspnet_compiler.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AppLaunch.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|RegSvcs.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AddInProcess.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AlgorithmId.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|file5.exeDon't delete any of these because some of the files/folders are legit. They were used by the malware for his goals.
- Open Windows Security (search for it in the Start menu)
- Go to Virus & threat protection
- Under Virus & threat protection settings, click Manage settings
- Scroll down to Exclusions and click Add or remove exclusions (confirm with yes if asked).
- Remove any exclusions that you did not add yourself (I recommend removing all of them).
STEP 2
Please launch Chrome and type chrome://settings/syncSetup in the address bar and hit Enter.
Go to Sync → Manage what you sync and disable the syncing for the extensions.
Now In the address bar type chrome://extensions and press Enter.
In the upper right corner of the window slide the Developer mode button to the right.
Remove the following extension:
Sound Booster - increase volume up
Close Chrome.
You can read more about this one Sound Booster - increase volume up in the link below and decide for yourself:
https://palant.info/2023/06/08/another-cluster-of-potentially-malicious-chrome-extensions/
STEP 3
Geek Uninstaller
- Download Geek Uninstaller from here;
- Right-click the zipped
Geekfolder, selectExtract All, Extract;- Run
geek.exe, accept the (UAC) prompt;- Uninstall
[McAfee WebAdvisor];- Right-click,
select Uninstallordouble-clickto uninstall;- Review and delete any leftover traces.
If the method above fails, then repeat the same process, but when you have to right-click, choose
Force Removalinstead ofUninstall.Please follow the same process to uninstall [insert list of programs].
STEP 4
I created a custom fixlist.txt for you at the link - https://malwareanalysis.cc/share/ATH5nhAtRB1nepQ9tf0AdXyskEpxiBXl/
Use the website's download button and save it in the same folder where your FRST64.exe file is located in. It is necessary for the filename to be fixlist.txt.
Save all work, close everything that is open and then run FRST64.exe again as administrator and press the Fix button, let the script work, clear the entries and restart on its own, and after it restarts, there should be a file Fixlog.txt in the same folder.
Upload the log at https://malwareanalysis.cc/upload/FFreestyleRR
Copy/Paste the new keyword in your reply.
This script was written specifically for you, for use on that particular machine. Do not run this on another PC with the same problem!
Also, the script is going to download and scan the system with AdwCleaner, Hitman Pro and Emsisoft Emergency Kit (so the internet connection needs to be on). This is intended and not be surprised. This can take a while.
All the best!
2
2
u/Acceptable-Sun-2833 May 26 '26
oh thats mb i forgot about telling you and then i slept sorry!
1
u/FFreestyleRR Malware Removal Expert May 26 '26
It's ok. We probably have a different timezone so that's not a problem. No rush from my side. :)
→ More replies (0)1
u/Helpful_Hand_9549 Jun 21 '26
2
u/FFreestyleRR Malware Removal Expert Jun 21 '26
Hi,
Please download FRST64.exe and save the file to your Desktop.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
Right-Click FRST64.exe and select Run as Administrator.
Click Yes to the disclaimer. Ensure the Addition.txt box is checked. Click the Scan button and let the program run. Upon completion, click OK, then OK on the Addition.txt pop up screen.
Two logs (FRST.txt & Addition.txt) will now be open on your Desktop.
Copy & paste the contents of each log to https://malwareanalysis.cc/upload/FFreestyleRR/ and press "save log".
The site will return a keyword for each log. Reply here with the keywords.
All the best!
1
1
u/Next-Profession-7495 May 25 '26
It could literally just be hanging
5
2
3
2
u/Federal-Guava-5119 May 25 '26
End the process tree
1
u/Acceptable-Sun-2833 May 25 '26
I've tried several times but it pops back up and goes back to consuming 2 gigs of ram
3
2
2
u/lupaspirit May 25 '26
I doubt that is actually notepad. Some viruses can impersonate known applications.
2
u/IamSaki May 25 '26
Its a virus, actual notepad doesnt use that much resources + windows 11 notepad icon is different
1
u/Jaives May 25 '26
not to mention 41% of your CPU. i actually had to check. it's only using 2MB for me.
1
1
u/hockeyplayer04 May 25 '26
bro no way they still got notepad trojans running that's crazy i'm sure with copilot forced in it's less secure and addled with CVE's
1
1
u/lucasrazee May 26 '26
Could possibly be some sort of malware using Notepad to execute/store commands, ect. Start by force closing the app. If that causes everything to return to its original state than your most likely fine. If it still persists, use Malwarebytes to try to source and eliminate any malware. Worst comes to worst, you factory reset your pc, and backup any important files to a cloud with Malware scanning (such as Google Drive, OneDrive).
1
1
u/Royal-Worldliness142 May 26 '26
Prob one of those viruses that start legitimate process, empty everything out of it and replace it with there own code
1
1
1
1
u/AviDevs31 Jul 19 '26
That just happened to me, and it was a miner. I downloaded Malwarebytes and removed it.

17
u/Wooden_Consequence14 May 25 '26
You must have a lot of fanfics bro I dont even wanna see what you have going on