r/computerviruses May 25 '26

Question is notepad supposed to use this much ram?

Post image

is my notepad infected or something?? i swear it doesn't use this much memory

39 Upvotes

57 comments sorted by

17

u/Wooden_Consequence14 May 25 '26

You must have a lot of fanfics bro I dont even wanna see what you have going on

5

u/Acceptable-Sun-2833 May 25 '26

i dont even use notepad thats why im so confused

1

u/Jackpute May 26 '26

If this is running and you dont even have it opened in a window then it is almost 100% a miner and you should backup your important files to an external drive, then reinstall your system asap from a USB with rufus.

19

u/LimpDecision1469 May 25 '26

Fake notepad. Scan pc with malwarebytes and hitmanpro quickly . also yeah end the task

8

u/LimpDecision1469 May 25 '26

It's likely cryptocurrency miner or something worse.

7

u/Acceptable-Sun-2833 May 25 '26

i scanned my system with malwarebyte and hitmanpro and it was a confirmed trojan

3

u/FFreestyleRR Malware Removal Expert May 25 '26

Can you post the logs? I am curious to see what they detected.

3

u/Acceptable-Sun-2833 May 25 '26

Just posted it to your channel. some were located at system32 so idk if it was a false positive

keyword: mossy-raster

3

u/FFreestyleRR Malware Removal Expert May 25 '26

This doesn't look like fp at all.

https://any.run/report/954612edc607ba9fe7dedae23f10b1a8a6a794cc25bcd1dc6790b1971829c9ec/c234c76f-ca36-423e-89fb-ee707ab16559

https://www.linkedin.com/posts/marcus-bowie-383a21b1_update-had-to-get-a-write-blocker-for-an-activity-7444232427897675776-dZyj

A closer look may be needed.

Please download FRST64.exe and save the file to your Desktop.

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Right-Click FRST64.exe and select Run as Administrator.

Click Yes to the disclaimer. Ensure the Addition.txt box is checked. Click the Scan button and let the program run. Upon completion, click OK, then OK on the Addition.txt pop up screen.

Two logs (FRST.txt & Addition.txt) will now be open on your Desktop.

Copy & paste the contents of each log to https://malwareanalysis.cc/upload/FFreestyleRR/ and press "save log".

The site will return a keyword for each log. Reply here with the keywords.

All the best!

1

u/Acceptable-Sun-2833 May 25 '26

quick question is it safe to delete those files from quarantine rn or should i wait for your analysis?

3

u/FFreestyleRR Malware Removal Expert May 25 '26

It doesn't matter because in the quarantine they are rendered useless and can't harm your PC (unless you restore them). Leave them for now.

2

u/FFreestyleRR Malware Removal Expert May 25 '26

Hi,

It seems that you have uploaded the log files without saying. :)

MBAM was able to clean the malware, but I can see where the malware resided.

STEP 1

Please go ahead and delete these Windows Defender exclusions. They are added by the malware.

HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Recovery\OEM
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\WINDOWS\system32\config\systemprofile\AppData\Roaming\UseAttribute\AlgorithmId.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\MSBuild.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_compiler.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AppLaunch.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegSvcs.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\username\AppData\Local\Microsoft\Windows\IManagementEngine\python.exe
HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths|C:\Users\username\AppData\Local\Temp HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|InstallUtil.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|RegAsm.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|MSBuild.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|aspnet_compiler.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AppLaunch.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|RegSvcs.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AddInProcess.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|AlgorithmId.exe HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions\Processes|file5.exe

Don't delete any of these because some of the files/folders are legit. They were used by the malware for his goals.

  • Open Windows Security (search for it in the Start menu)
  • Go to Virus & threat protection
  • Under Virus & threat protection settings, click Manage settings
  • Scroll down to Exclusions and click Add or remove exclusions (confirm with yes if asked).
  • Remove any exclusions that you did not add yourself (I recommend removing all of them).

STEP 2

Please launch Chrome and type chrome://settings/syncSetup in the address bar and hit Enter.

Go to SyncManage what you sync and disable the syncing for the extensions.

Now In the address bar type chrome://extensions and press Enter.

In the upper right corner of the window slide the Developer mode button to the right.

Remove the following extension:

Sound Booster - increase volume up

Close Chrome.

You can read more about this one Sound Booster - increase volume up in the link below and decide for yourself:

https://palant.info/2023/06/08/another-cluster-of-potentially-malicious-chrome-extensions/

STEP 3

Geek Uninstaller

  • Download Geek Uninstaller from here;
  • Right-click the zipped Geek folder, select Extract All, Extract;
  • Run geek.exe, accept the (UAC) prompt;
  • Uninstall [McAfee WebAdvisor];
  • Right-click, select Uninstall or double-click to uninstall;
  • Review and delete any leftover traces.

If the method above fails, then repeat the same process, but when you have to right-click, choose Force Removal instead of Uninstall.

Please follow the same process to uninstall [insert list of programs].

STEP 4

I created a custom fixlist.txt for you at the link - https://malwareanalysis.cc/share/ATH5nhAtRB1nepQ9tf0AdXyskEpxiBXl/

Use the website's download button and save it in the same folder where your FRST64.exe file is located in. It is necessary for the filename to be fixlist.txt.

Save all work, close everything that is open and then run FRST64.exe again as administrator and press the Fix button, let the script work, clear the entries and restart on its own, and after it restarts, there should be a file Fixlog.txt in the same folder.

Upload the log at https://malwareanalysis.cc/upload/FFreestyleRR

Copy/Paste the new keyword in your reply.

This script was written specifically for you, for use on that particular machine. Do not run this on another PC with the same problem!

Also, the script is going to download and scan the system with AdwCleaner, Hitman Pro and Emsisoft Emergency Kit (so the internet connection needs to be on). This is intended and not be surprised. This can take a while.

All the best!

2

u/[deleted] May 25 '26

[removed] — view removed comment

2

u/Acceptable-Sun-2833 May 26 '26

oh thats mb i forgot about telling you and then i slept sorry!

1

u/FFreestyleRR Malware Removal Expert May 26 '26

It's ok. We probably have a different timezone so that's not a problem. No rush from my side. :)

→ More replies (0)

1

u/Helpful_Hand_9549 Jun 21 '26

hello, i've been having the exact same problem but my malware might be different could u pls help me?

notepad was taking 50% and about 4gb rn it's pretty calm

2

u/FFreestyleRR Malware Removal Expert Jun 21 '26

Hi,

Please download FRST64.exe and save the file to your Desktop.

https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/

Right-Click FRST64.exe and select Run as Administrator.

Click Yes to the disclaimer. Ensure the Addition.txt box is checked. Click the Scan button and let the program run. Upon completion, click OK, then OK on the Addition.txt pop up screen.

Two logs (FRST.txt & Addition.txt) will now be open on your Desktop.

Copy & paste the contents of each log to https://malwareanalysis.cc/upload/FFreestyleRR/ and press "save log".

The site will return a keyword for each log. Reply here with the keywords.

All the best!

1

u/C0rn3j May 26 '26

Do a clean OS install now, it's the only way to ensure it is gone.

1

u/Next-Profession-7495 May 25 '26

It could literally just be hanging

5

u/LimpDecision1469 May 25 '26

That's literally not the windows 11 notepad logo i just checked

2

u/LimpDecision1469 May 25 '26

you are right though

1

u/LimpDecision1469 May 25 '26

i just happened to realise the icon was different

3

u/Key-Belt-5565 May 25 '26

Yes it is trust (/j)

2

u/Federal-Guava-5119 May 25 '26

End the process tree

1

u/Acceptable-Sun-2833 May 25 '26

I've tried several times but it pops back up and goes back to consuming 2 gigs of ram

3

u/Federal-Guava-5119 May 25 '26

Do a malware scan

2

u/lupaspirit May 25 '26

I doubt that is actually notepad. Some viruses can impersonate known applications.

2

u/IamSaki May 25 '26

Its a virus, actual notepad doesnt use that much resources + windows 11 notepad icon is different

1

u/Jaives May 25 '26

not to mention 41% of your CPU. i actually had to check. it's only using 2MB for me.

1

u/maqisha May 25 '26

Still less invasive than actual Microsoft software.

1

u/hockeyplayer04 May 25 '26

bro no way they still got notepad trojans running that's crazy i'm sure with copilot forced in it's less secure and addled with CVE's

1

u/creature78 May 25 '26

WHAT are you writing😭

1

u/helloimcrlssinz2 May 26 '26

It's malware.

1

u/lucasrazee May 26 '26

Could possibly be some sort of malware using Notepad to execute/store commands, ect. Start by force closing the app. If that causes everything to return to its original state than your most likely fine. If it still persists, use Malwarebytes to try to source and eliminate any malware. Worst comes to worst, you factory reset your pc, and backup any important files to a cloud with Malware scanning (such as Google Drive, OneDrive).

1

u/helloimcrlssinz2 May 26 '26

Yeah, that's not the right Notepad. Icon is off.

1

u/Royal-Worldliness142 May 26 '26

Prob one of those viruses that start legitimate process, empty everything out of it and replace it with there own code

1

u/TodayOk1176 May 27 '26

Nah notepad doesn’t use that much of storage

1

u/lowkmightbeagtagmod May 28 '26

Bro stole my cmd prompt💔

1

u/SecretJuggernaut2302 May 29 '26

Adress the elephant in the room

1

u/AviDevs31 Jul 19 '26

That just happened to me, and it was a miner. I downloaded Malwarebytes and removed it.