Upvote Upvoted 1 Downvote Downvoted
Potential malware?
posted in Off Topic
1
#1
0 Frags +

Just today I've been suffering from frame drops every couple seconds. I checked my process just now to find busdbxxmuoh.exe multiple times and as I try to end them, more start up.

http://i.imgur.com/wVzWbAw.png

I've tried using spybot but it doesn't seem to fix this. Any suggestions for what I should do?
(I don't even use google chrome...)

Just today I've been suffering from frame drops every couple seconds. I checked my process just now to find busdbxxmuoh.exe multiple times and as I try to end them, more start up.
[img]http://i.imgur.com/wVzWbAw.png[/img]
I've tried using spybot but it doesn't seem to fix this. Any suggestions for what I should do?
(I don't even use google chrome...)
2
#2
0 Frags +

definitely malware

reformat

definitely malware

reformat
3
#3
2 Frags +

Right click one and select 'open file location'. This should open up the folder where the file is located. Also, use a program like Process Explorer to find out what started them, so you can kill that.

Right click one and select 'open file location'. This should open up the folder where the file is located. Also, use a program like Process Explorer to find out what started them, so you can kill that.
4
#4
-1 Frags +

I can't delete it without ending all of the processes which keep popping up.

I can't delete it without ending all of the processes which keep popping up.
5
#5
0 Frags +

its like porn popups

its like porn popups
6
#6
-1 Frags +
GeknaiirI can't delete it without ending all of the processes which keep popping up.

Where is the file located? What process started them? Try something like Unlocker or use the command line to force delete the file.

[quote=Geknaiir]I can't delete it without ending all of the processes which keep popping up.[/quote]
Where is the file located? What process started them? Try something like Unlocker or use the command line to force delete the file.
7
#7
0 Frags +

I can't delete it with command line. It's located in appdata>locallow>a bunch of random folders

Does anyone know what this does too?

I can't delete it with command line. It's located in appdata>locallow>a bunch of random folders

Does anyone know what this does too?
8
#8
0 Frags +
GeknaiirI can't delete it with command line. It's located in appdata>locallow

Does anyone know what this does too?
AppData contains 3 specific folders with everyone having it’s specific purpose.
This layout has something to do with Roaming Profiles but I think you get the idea with the short version:
AppDataLocal … userdata to big to roam or machine specific
AppdataLocalLow … as above but for low level acces (e.g. protected mode of IE)
AppdataRoaming … userdata that are capable of being “roamed”
As for “LocalLow” it is about protection for the user. For example when you run IE in protected mode you don’t want it to access any of your userdata. So instead of giving it access to those Windows will only grant access to the “LocalLow” folder to store and read data from.

- Source

Check if you have any adware Extensions and disable / delete things as you see fit
And I mean, if you don't use Chrome, uninstall it...unless you mean you don't even have Chrome installed, then nevermind.

[quote=Geknaiir]I can't delete it with command line. It's located in appdata>locallow

Does anyone know what this does too?[/quote]
[quote]AppData contains 3 specific folders with everyone having it’s specific purpose.
This layout has something to do with Roaming Profiles but I think you get the idea with the short version:
AppDataLocal … userdata to big to roam or machine specific
AppdataLocalLow … as above but for low level acces (e.g. protected mode of IE)
AppdataRoaming … userdata that are capable of being “roamed”
As for “LocalLow” it is about protection for the user. For example when you run IE in protected mode you don’t want it to access any of your userdata. So instead of giving it access to those Windows will only grant access to the “LocalLow” folder to store and read data from.[/quote] - [url=http://www.makeuseof.com/answers/type-data-stored-local-locallow-roaming-folders-userappdata-windows-7/]Source[/url]

Check if you have any adware Extensions and disable / delete things as you see fit
And I mean, if you don't use Chrome, uninstall it...unless you mean you don't even have Chrome installed, then nevermind.
9
#9
0 Frags +

I don't even have chrome installed...

I don't even have chrome installed...
10
#10
0 Frags +
GeknaiirI can't delete it with command line. It's located in appdata>locallow>a bunch of random folders

Does anyone know what this does too?

Tried 'del /F busdbxxmuoh.exe' from an administrator cmd?

[quote=Geknaiir]I can't delete it with command line. It's located in appdata>locallow>a bunch of random folders

Does anyone know what this does too?[/quote]
Tried 'del /F busdbxxmuoh.exe' from an administrator cmd?
11
#11
0 Frags +

Download hijackthis and remove any entries referencing the executable so it won't reappear on reboot

Download hijackthis and remove any entries referencing the executable so it won't reappear on reboot
12
#12
0 Frags +

Can you help me on steam? I added you.

Can you help me on steam? I added you.
13
#13
1 Frags +

go post here, you'll get more and better help.

https://forum.avast.com/index.php?board=4.0

go post here, you'll get more and better help.

https://forum.avast.com/index.php?board=4.0
14
#14
0 Frags +

download malware bytes anti malware, install, update and re-boot ur computer into safe mode and run it. it should clear out anything like that you have

download malware bytes anti malware, install, update and re-boot ur computer into safe mode and run it. it should clear out anything like that you have
15
#15
0 Frags +

Malwarebytes didn't work for me. I spent an hour with mr64bit and managed to delete the program and the folders that came with it.

Thanks mr64bit, you're a god :)

Malwarebytes didn't work for me. I spent an hour with mr64bit and managed to delete the program and the folders that came with it.

Thanks mr64bit, you're a god :)
16
#16
0 Frags +

didnt work or didnt find anything? if it didnt work thats probably not good

didnt work or didnt find anything? if it didnt work thats probably not good
17
#17
0 Frags +

Oh I couldn't find anything, my bad. I ended up using unlocker and then rebooting in safe mode to delete all of the stuff.

Oh I couldn't find anything, my bad. I ended up using unlocker and then rebooting in safe mode to delete all of the stuff.
18
#18
4 Frags +

boot in safe mode and run this http://www.reddit.com/r/sysadmin/comments/2jxqxs/tron_v370_20141022_add_verbose_shutdown_flags_add/

boot in safe mode and run this http://www.reddit.com/r/sysadmin/comments/2jxqxs/tron_v370_20141022_add_verbose_shutdown_flags_add/
19
#19
0 Frags +

Ooh, thanks hooli, I'll have to add that to my toolkit.

Ooh, thanks hooli, I'll have to add that to my toolkit.
Please sign in through STEAM to post a comment.