Help With A Virus

enigma_st

Prominent
Dec 17, 2017
3
0
510
So, I've got virus that I've been battling with for a few days and it's been driving me crazy. It slows my computer down by an insane amount and at any given time, almost all of my 4GB of RAM is being used even if I have nothing else open. It's also redirecting all of my Google searches through "extensions.citypage.today" and just shows a Bing search if whatever it is I looked up. And yet, I don't see any installed extensions like that. Also, when I check the Processes tab in Task Manager, there are 5 instances of Windows Process Manager but it's called "cshzamn.exe" Those 5 instances alone, are somehow utilizing more than half of my available memory. If I try to open it's location, Windows tells me "Access is denied." It's located in "C:/users/name/AppData/Local/serniwo" I've tried changing permissions in that "serniwo" folder only to get the same "Access is denied" message. I've tried multiple Antivirus programs but, none of them detect the folder as anything dangerous. I've also tried going through safe mode to see if I can do anything from there but, I encountered the same Access issue. Any help with this would be absolutely great.
 
Solution
Based on what you describe, it sounds like this infection may have multiple processes -- and in fact you may have multiple infections.

Your best bet in this case, since the machine is already infected, would be to restore to a known good restore point, or wipe and re-image from backup, and make sure you have protection in place to help prevent future attacks.

If you don't have a backup, you should definitely try a boot-time scan. Malware like this that gets its fingers into everything can often re-propagate itself even if you quarantine a part of it. Isolating the computer from the net and running one or more boot-time scans may help clean things up. https://support.avast.com/en-us/article/132/

Major_Trouble

Distinguished
Jun 25, 2007
57
0
18,610
You could try Unlocker to delete stubborn files.
https://unlocker.en.softonic.com/

What happens in Task Manager when you End Task on the instances of cshzamn.exe that are running? I can't find anything about that .exe so it's rather suspicious.
 

enigma_st

Prominent
Dec 17, 2017
3
0
510


When I try to end any instance of it, I simply get the same "Access is Denied" notifications that I get whenever I try to enter the folder that it's inside of. Also, I seem to have issues installing Unlocker. It doesn't even want to launch. I'll try to find a similar program.

Update: I got Unlocker to work and i still wasn't able to delete the previously mentioned folder. I tried a similar program called UnLock IT and I still had no luck with that one either.
 

enigma_st

Prominent
Dec 17, 2017
3
0
510


I have tried running MalwareBytes as well. I have also tried running the MalwareBytes Tool-Kit and unfortunately, neither of those had any results either.
 

Major_Trouble

Distinguished
Jun 25, 2007
57
0
18,610


Try again in Safe mode.
 

Avast-Team

Estimable
Mar 3, 2017
225
1
5,165
Based on what you describe, it sounds like this infection may have multiple processes -- and in fact you may have multiple infections.

Your best bet in this case, since the machine is already infected, would be to restore to a known good restore point, or wipe and re-image from backup, and make sure you have protection in place to help prevent future attacks.

If you don't have a backup, you should definitely try a boot-time scan. Malware like this that gets its fingers into everything can often re-propagate itself even if you quarantine a part of it. Isolating the computer from the net and running one or more boot-time scans may help clean things up. https://support.avast.com/en-us/article/132/
 
Solution