My computer is infected but AV software does not find anything


Anixx

Well-known member
Member
VIP
Local time
11:29 AM
Posts
504
OS
Windows 11
My computer seemingly got infected.

The symptoms include:
* Multiple processes crss.exe and 5 open Windows sessions after boot (normally should be only Session 0 and Session 1, I have sessions 0-4)
* After boot, there is conhost.exe running, several dllhost.exe and occasionally, powershell that starts conhost.exe. Also, several processes RuntimeBroker
* After some time after boot, the keyboard stops auto-repeat keypresses and/or disappears sound.
* dllhost.exe processes are run by Wlanext.exe. Internet says that this process is tyucally used by malware Guloader. Dllhost starts with commandline "processid:{133eac4f-5891-4d04-bada-d84870380a80}". Wlanext.exe is run by svchost.exe.
* At boot, for a short time appears a console window.
* Rebooting computer instead shuts the computer down.

What I did:

* Rolled back the system to the oldest save point possible (for sure at the time I had no symptoms). During the rollback happened BSOD. After reboot the system said, it was successfully rolled back. Still the infection symptoms remained.
* Renamed wlanext, dllhost, conhost and powershell.exe files
* Renamed registry key {133eac4f-5891-4d04-bada-d84870380a80}
* Installed Malwarebytes antivirus. It did not install successfully but after partial install I was able to run it and make scan. It reported only torrent client and some Windows customization software. Nothing else.
* Used Microsoft's Malware removal tool with full scan. It found nothing.
 

My Computer

System One

  • OS
    Windows 11
I don't think your computer infected, but you can check those processes with Process Explorer.

This guide explains how to use Process Explorer, to spot malicious software running on a computer.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
I don't think your computer infected, but you can check those processes with Process Explorer.

This guide explains how to use Process Explorer, to spot malicious software running on a computer.
I wrote in my post what findings I found with ProcessExplorer.
 

My Computer

System One

  • OS
    Windows 11
Multiple processes crss.exe
Should be 2 by default.
Windows sessions after boot (normally should be only Session 0 and Session 1, I have sessions 0-4)
Download Process Monitor - Sysinternals add column, Command Line, and make printscreen of it. And can be more sessions, if some applications uses that... make printscreen of those other sessions, + there exe's and path.
* After boot, there is conhost.exe running, several dllhost.exe and occasionally, powershell that starts conhost.exe. Also, several processes RuntimeBroker
Also make printscreen, processes could be normal, or legit apps can trigger it. Show also with column; command line. For examle i have also programs running that uses a powershell window to let the application function correctly.
* At boot, for a short time appears a console window.
Download Autoruns - Sysinternals and show printscreen, of what starts at boot. Could be a program that uses some bat script for legit things. (However not as good programming, as it could be done differently)

Wlanext.exe
Upload to VirusTotal and share the report.
dllhost.exe
This is a legit process. However could be misused, see qoute before this one.


So reading it all, it might be nothing, but still want to see the printscreen and totalvirus report.

Also in Process Monitor, turn on the option under Option -> TotalVirus.com --> Check TotalVirus.com to scan all your running exe's against 70+ virusscanners.

Also View Process Monitor, on - > View "Show Process Tree" to see what exe's run sub processes.
Looks like this:
1740161461960.webp i have conhost,powershell also running for legit app.
 
Last edited:

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Sorry i mean in Process Explorer. Always confuse with those 2 apps.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
I wrote in my post what findings I found with ProcessExplorer.
Did you use Process Explorer scan functions for the processes, did you followed my guide on the video?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
Sorry i mean in Process Explorer. Always confuse with those 2 apps.
Seemingly, this option does not work for me.

But here is some further development.
I rebooted the system, and was asked if I want to keep autorization by fingerprints or I want to change the authorization method. But I have never used fingerprints. In the process list there is now Credential Enrollment Manager, and I cannot terminate it.

Also, when I went to Youtube, it shows in history, as the most recently viewed, a video on how to disable password request after waking up from sleep. But I have never watched this video, and this can be proven by the browser history. So, someone logged on to Youtube with my browser profile and watched it!
 

My Computer

System One

  • OS
    Windows 11
Did you use Process Explorer scan functions for the processes, did you followed my guide on the video?
I wish Process Explorer would scan 'functions' for the processes. ;-) As i would normally need to decompile them to see the processes it's internal functions. I love the NSA tool Ghidra for that.
After rereading i guess you mean the TotalVirus scan option for the processes. =)
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Seemingly, this option does not work for me.

But here is some further development.
I rebooted the system, and was asked if I want to keep autorization by fingerprints or I want to change the authorization method. But I have never used fingerprints. In the process list there is now Credential Enrollment Manager, and I cannot terminate it.

Also, when I went to Youtube, it shows in history, as the most recently viewed, a video on how to disable password request after waking up from sleep. But I have never watched this video, and this can be proven by the browser history. So, someone logged on to Youtube with my browser profile and watched it!
Any apps you resently downloaded or installed?
Maybe a cookie hijack, i would log out all devices from google, and change password / setup 2factor authentication.
Are you using a microsoft account on machine? Credential Enrollment Manager is a per User-Service and is normal to be running in some conditions.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
Any apps you resently downloaded or installed?
Maybe a cookie hijack, i would log out all devices from google, and change password / setup 2factor authentication.
Are you using a microsoft account on machine? Credential Enrollment Manager is a per User-Service and is normal to be running in some conditions.
No, I am using offline account. No Microsoft account.
 

My Computer

System One

  • OS
    Windows 11
* Rebooting computer instead shuts the computer down.
For this check if any of these options help:
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
I wish Process Explorer would scan 'functions' for the processes. ;-) As i would normally need to decompile them to see the processes it's internal functions. I love the NSA tool Ghidra for that.
After rereading i guess you mean the TotalVirus scan option for the processes. =)
Also, Very image signatures function will help.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion
    CPU
    AMD Ryzen 7 5700G
    Motherboard
    Erica6
    Memory
    Micron Technology DDR4-3200 16GB
    Graphics Card(s)
    NVIDIA GeForce RTX 3060
    Sound Card
    Realtek ALC671
    Monitor(s) Displays
    Samsung SyncMaster U28E590
    Screen Resolution
    3840 x 2160
    Hard Drives
    SAMSUNG MZVLQ1T0HALB-000H1
For this check if any of these options help:
Part of the symptoms disappeared after I rolled back the system to a previous date. Including not rebooting, extra sessions, keyboard not repeating and disappearing of sound.
 

My Computer

System One

  • OS
    Windows 11
So, the conhost is started by wlanext.exe. And wlanext.exe is started by different services.

First, by service of push-notifications. I disabled it, it became started by the web security service. I disabled it, it became started by WLAN helper service.
 

My Computer

System One

  • OS
    Windows 11
This is a description of the RAT
 

My Computer

System One

  • OS
    Windows 11 Home 24H2 26100.3194
    Computer type
    PC/Desktop
    Manufacturer/Model
    HP Pavilion TP01-2xxx
    CPU
    AMD Ryzen 3 5300G
    Memory
    8gb
    Graphics Card(s)
    Radeon Graphics 4.00GHZ
    Monitor(s) Displays
    ViewSonic
    Keyboard
    HP
    Mouse
    wireless Microsoft
    Browser
    FireFox
    Antivirus
    Avira
This is a description of the RAT
I need to disable vbscript and powershell. How to do this?
 

My Computer

System One

  • OS
    Windows 11

Latest Support Threads

Back
Top Bottom