Nainstalovat Steam
přihlásit se
|
jazyk
简体中文 (Zjednodušená čínština)
繁體中文 (Tradiční čínština)
日本語 (Japonština)
한국어 (Korejština)
ไทย (Thajština)
български (Bulharština)
Dansk (Dánština)
Deutsch (Němčina)
English (Angličtina)
Español-España (Evropská španělština)
Español-Latinoamérica (Latin. španělština)
Ελληνικά (Řečtina)
Français (Francouzština)
Italiano (Italština)
Bahasa Indonesia (Indonéština)
Magyar (Maďarština)
Nederlands (Nizozemština)
Norsk (Norština)
Polski (Polština)
Português (Evropská portugalština)
Português-Brasil (Brazilská portugalština)
Română (Rumunština)
Русский (Ruština)
Suomi (Finština)
Svenska (Švédština)
Türkçe (Turečtina)
Tiếng Việt (Vietnamština)
Українська (Ukrajinština)
Nahlásit problém s překladem
Just get a good antivirus/antispyware...
there's a few other threads going around which seem to think it's something else, i've tried to divert them to this post. In my case, my "steam" cpu usage was always hovering at 30% useage
Noticed how crazy hot the room my PC is in was getting. Used GPU-Z to see what's happening and noticed it had 90% load all the time!
Checked with Process Explorer (had to download this tool) and this showed that nothing was using GPU load. This told me an invisible process was using the GPU.
Finally I used various tools to find and get rid of the malware. At tool called RKILL found and stopped the coin miner malware. I verified this by checking in GPU-Z that the GPU load was now 0%. I used this thread I found, to very good effect:
http://forum.cheatengine.org/viewtopic.php?t=578889&sid=14b6c06dac68db54a3ec3128f588005b
Not everything was the same as what they talk about there, but it helped me find the malware, and also find the Task it created in Task Scheduler (was different but had the word STEAM in it). So far so good.
It needs to be manually removed by YOU.
Step 1: Start up an application like HW monitor to check for two things: 1) GPU utilization 2)GPU temp. You will see that these two things are not normal.
Step 2: If Steam (the actual steam client that you use for gaming) is running, shut it down.
Step 3: Open up TASK MANAGER. Go to "Processes" and if need be, scroll down to find "Steam * 32" or something that says Steam. If you read Step 2, you'll know why I said to shut down Steam game app first.
Step 4: Right-click on this "Steam*32" or whatever name it is under, and select "open file location." It will take you right to the source. Delete it.
For me, it was in Appdata/Roaming/Shadow of Mordor
Step 5: Also, delete the "Steam file" in the System32/Tasks folder. You should find one file with the name Steam in it. DELETE it.
A lot of the advice in this thread and others are good, but they're all over the place. I thought I'd make it easier for you guys. Cheers.
The easier the way you clean a virus, the less effective it is.
`
Also you are aware that a single infection can act different each time?
Be aware that you will also have a task to auto re-download this ♥♥♥♥♥ each time you reboot. Carefully scan your tasks that are not from a known source and you'll find it easy.
Click Start, type "Task Sceduler" in the search box and click the link, a quick read of your active tasks will tell you most/all are from legit sources - if you got hit by this ♥♥♥♥♥, one wont - it's set to run at boot, and differs for all. Disable the likely candidate and reboot, if your GPU temp is normal you got it :)
Only stopping its auto launching will simply just remove the auto launch, yet you're still infected.
It's absurd that so many think simply deleting one file or doing one thing remove an infection, no wonder why it keep infecting people.
I ran through this thread and found the folder in C:\Users\<user>\AppData\Roaming\Dropbox\CODEXi
I then proceeded to delete that folder.
One trick I learned is that when the program is running, you can actually just right click on it and go to properties and you'll see the directory the file is located in. I also found the file int he system32/tasks folder and deleted it as well. I do hope i don't get this thing again.
This thread is NOT the solution. you don't clean a virus with a simple folder delete xD.