Could this be malware?


Recommended Posts

1 hour ago, devnulllore said:

Yes I am logging into my Microsoft Account. Mi licence is valid as far as I know. The registration is in my bios.

The lag, yes but Explorer has not crashed since I got rid of the insiders build.

I think others may have already mentioned it but are you able to take a video of this happening, either using OBS or simply recording the screen with a camera?

I was just monitoring the processes while trying to get it to repeat and suddenly 'chrome - software reporter tool' showed up 6 times and pegged my CPU and the power usage level went to very high stayed there for a few seconds then stopped. Could this be a suspect? As for getting a video I have never tried it.

16 minutes ago, devnulllore said:

Here is what I was talking about with Chrome and the software reporting tool.

taskmanager.jpg

Possible, I've seen that process bring some systems to it's knees. I've removed chrome from a few of my machine's because of it. That software reporter tool uses a ridiculous mount of cpu.

32 minutes ago, devnulllore said:

I was just monitoring the processes while trying to get it to repeat and suddenly 'chrome - software reporter tool' showed up 6 times and pegged my CPU and the power usage level went to very high stayed there for a few seconds then stopped. Could this be a suspect? As for getting a video I have never tried it.

I doubt it because you said in a previous post it was happening on a clean install with nothing else yet installed.

47 minutes ago, Vince800 said:

I doubt it because you said in a previous post it was happening on a clean install with nothing else yet installed.

No, you are correct I had not thought of that. Either way I disabled the tool to see if it helps.

Yeah I am curious as well why yours is showing 32..

 

I just fired chrome up.. And it showing as 64 on my system

chrome.thumb.png.26aa2514f939f67084b8aa91ee8441c8.png

 

What version of chrome are you running?

Google Chrome is up to date

Version 76.0.3809.100 (Official Build) (64-bit)

47 minutes ago, BudMan said:

Yeah I am curious as well why yours is showing 32..

 

I just fired chrome up.. And it showing as 64 on my system

chrome.thumb.png.26aa2514f939f67084b8aa91ee8441c8.png

 

What version of chrome are you running?

Google Chrome is up to date

Version 76.0.3809.100 (Official Build) (64-bit)

I am using the 64 bit version. copy and paste from Chrome: Version 76.0.3809.100 (Official Build) (64-bit)

 

I'd try uninstalling chrome for a while see if it clears up. As an alternative to Chrome I'd recommend Brave.

 

Brave is still chromium based but without some of googles bloat and with a built in adblocker and a few other nice things. It can still use extensions from the chrome web store too

 

https://brave.com 

  • Thanks 1

The time you have spent on this even at 10$ an hour you could of prob bought whole new machine ;)

 

You got something really odd going on - if you say your system is 64bit, and you install 64 bit software and its running as 32bit?  Why would that chrome software reporting show its running 32?  Had you installed multiple copies of chrome?  You say your doing a clean install, but then we come to find out you have xyz installed.. Clean would be NOTHING but the OS..

 

Are you running anything that is putting stuff in compatibility mode?

 

Run it like that.. Do you have any problems before you install software X... Run it like that for a while, do you see the issue?  If not then move on to installing software Y..

 

Also noticed you EVGA X server something running - so this again points to not being actually "clean" install.  Don't use your MS account when you install it... Just install it pure clean..

It is the 64 bit version of Chrome and I had already eliminated my graphics software before installing it. The issue began again before I even installed new drivers so I was in the process of installing the software to see if anything exacerbated the situation. Chrome did that.

So I updated all my drivers as I usually would and am still having the issue. Windows Explorer CPU usage spikes, system lags for a second or two them stops and Windows Explorer crashes my desktop every now and then.

 

Does this now sound more hardware related? Where do I go from here? I checked my MB temps and they are all ok.

Need to drill into the processes to really see.  I don’t know. I can’t do it for you.  I gave you the tools.  

 

For errors to not show in event cower is odd if it is a hardware issue.  If it were a big hardware issue you would get blue screens....is you computer locking up to where you have to reboot it?   The issue you were having was high drive usage, has this changed?   Are you now seeing high cpu usage?  Os is it crashing?

Oh sorry I completely forgot to check the event log since the new install. I have a bunch of errors and warnings. The first error is DistributedCOM 10010. There are dozens of these all in about 10 minute increments. The second error is Service Control Manager 7009, 7023, 7031 and 7034. Then I have Bits Client 16392, volmgr 46 and KernalPNP 225. There are also dozens of warnings if you want me to list them. That's where I am so far. Let me know if you need any more info.

I really think that it would be helpful if you could record a video of this happening as it may be an easy answer if we could actually see what you're getting here. You could even record the screen using a camera or phone if you're not familiar with OBS etc.

 

Just as thought, are you sorting folders by date? I've found that on Windows if you have a large number of files in a directory and it's sorted by date, it will take a few seconds to sort itself on first access sometimes.

Well you should prob look into the details of each error/warning and look to correct stuff that is not correct.

 

I'm not seeing any dcom 10010 errors, but in mine I see some 10016, which I have just corrected.  Decom permissions can be adjusted..

 

Volmgr 46, points to crash dump file not there? Not created?

http://www.eventid.net/display-eventid-46-source-volmgr-eventno-10647-phase-1.htm

 

Are you disabling swap?? ie your pagefile?

On 8/7/2019 at 8:05 AM, devnulllore said:

Untitled-1.thumb.jpg.d07831a3535fc348ebe747ec2ac6b686.jpg

I ran the rescue disk and deleted the boot folder but still accesses the drive and causes hitching (system pauses) when it does.

TL;DR 6 pages, so sorry if it's been addressed already, but you are missing lots of unallocated space there, ~ 46GB.

I hadn't noticed that screenshot before.. I would agree 46GB of SSD space is nothing to sneeze at ;)  If had to guess, I would say its setting for over provisioning... Would have nothing to do with this issue.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Micron reveals AI companies are spending billions to lock up its memory years in advance by Karthik Mudaliar The demand for more memory is far from over, and Micron is turning the AI-driven memory shortage into a much more predictable business. The company has revealed that it has signed 16 strategic supply agreements backed by roughly $22 billion in customer deposits and other financial commitments. The contracts cover DRAM and NAND deliveries over several years, with some running through 2030. With the AI boom, demand for high-bandwidth memory (HBM) has grown so quickly that large customers are now prepared to help finance future production in exchange for a guaranteed supply. According to Micron’s latest financial results, the company received commitments worth about $22 billion across its new agreements. Around $18 billion is expected to arrive as cash deposits, while the rest will come through other financial arrangements. Micron says the agreements could generate approximately $100 billion in future contracted obligations. They cover around 20% of its expected DRAM shipments and one-third of its NAND shipments during their respective terms. It should be noted that although AI infrastructure is the main force behind the current shortage, not all 16 agreements with Micron involve AI companies. Micron said the customers also include consumer electronics and automotive businesses, two sectors that increasingly compete with data centers for the same manufacturing capacity. HBM is consuming an increasing share of that supply. Unlike conventional desktop or server RAM, HBM stacks multiple memory dies vertically and places them close to an AI accelerator. This gives GPUs and other AI chips access to data at much higher speeds, but it also requires more complicated manufacturing and packaging. Micron says its 12-layer HBM4 memory is now shipping in high volume for a lead customer, with samples also supplied to other companies. The chipmaker has already generated more than $1 billion in HBM4 revenue and says the product is ramping twice as quickly as its earlier HBM3E generation. Samsung has similarly warned that the memory shortage could continue into 2027 and beyond. Consumer memory companies have also had to address sharp increases in DDR5 pricing, suggesting the effects are already reaching beyond the data center. For consumers, that could mean the AI memory crunch lasts longer than expected, even as manufacturers invest heavily in new production.
    • XnConvert 1.112 by Razvan Serea  XnConvert is a cross-platform batch image-converter and resizer with a powerful and ease of use experience. All common picture and graphics formats are supported (i.e. JPG, PNG, TIFF, GIF, Camera RAW, JPEG2000, WebP, OpenEXR) as well as supporting over 500 other image formats. Also available within the batch operations include rotating, adding of watermarks, adding of text along with many image-adjustment features such as brightness, shadows and more. Among the features included are: Batch adding of files and folders Support for drag and drop of files Batch rotating, cropping, resizing and more Adding of photo masks Preserving or removing image metadata in conversions Multipage image file support (i.e animated GIF, APNG, TIFF) Command line integration via NConvert Filters - such as 'Blur', 'Gaussian Blur', 'Emboss', "Sharpen' and much more Effects - such as 'Old camera' and much more Download: XnConvert 64-bit | Standalone | ~30.0 MB (Freeware) Download: XnConvert 32-bit | Standalone Links: XnConvert Website | Screenshot | Release Announcement Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft updates Visual Studio Code with chat cost tracking and multi-agent chats by Paul Hill Microsoft has just launched Visual Studio Code 1.126, its latest weekly release. This time, the company has focused on letting you see the total cost of chat sessions to spot expensive conversations; enabling multiple chats per session that run side-by-side in one agent host Copilot session; and letting you browse new folders safely in restricted mode. We have now reached the stage where free AI in IDEs is coming to an end. To help you keep track of your costs, VS Code now lets you see the entire cost of a chat session, rather than just individual turns. This should give you more transparency about which sessions consume the most credits, so you can better manage your usage over time and spend less. For those of you using the Agents window, you know it is possible to run and manage multiple agent sessions at once. In this update, a Copilot session started from an agent host can hold several chats at once. Explaining how this feature works, Microsoft writes: Finally, from this update forward, Microsoft will remove the pop-up when opening an untrusted folder. When you open a new folder now, it will automatically open in Restricted Mode. You will see a banner that lets you manage the trust level of the folder. Microsoft has made this change so that it’s easier to start inspecting code without giving it trust right away. If you have VS Code, you can check for updates within the app now to get this new version. Otherwise, you can download it from the Visual Studio Code website.
    • Anthropic accuses Alibaba of using 25,000 fake accounts to copy Claude's capabilities by Karthik Mudaliar Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from Claude on a huge scale. According to a report from Reuters, Anthropic told US lawmakers that operators linked to Alibaba and the company’s Qwen AI team generated 28.8 million exchanges with Claude between April 22 and June 5, 2026. That is a lot of Claude conversations, but Anthropic says this was not ordinary chatbot use. The company believes the accounts were part of a coordinated effort to collect answers that could help train or improve rival AI systems. The alleged campaign reportedly focused on some of Claude’s most valuable skills, including software development, multi-step reasoning, and agentic tasks. In practical terms, that means getting an AI model to plan and complete work across several stages rather than simply answering a single question. This is called 'distillation,' where AI companies use outputs from a larger model to train a smaller and cheaper one. The smaller model learns to imitate useful parts of the more capable system without needing the same amount of computing power. The distillation process isn't automatically suspicious, but the problem comes when one company gathers another provider's outputs without permission and at an industrial scale. Also, this does not mean Alibaba obtained Claude’s source code, model weights, or original training data. Instead, Anthropic claims the accounts repeatedly asked Claude carefully designed questions and collected the answers. Those answers could then be used as training material for another model. Anthropic has made similar accusations against DeepSeek, Moonshot AI, and MiniMax earlier this year. As Neowin previously reported, Anthropic said those three companies collectively generated more than 16 million Claude exchanges through roughly 24,000 accounts. Anthropic says the new campaign produced almost twice as many exchanges in a matter of weeks. Anthropic reportedly told lawmakers that the campaign could help Chinese AI developers approach the capabilities of its Mythos Preview model. Mythos is focused on advanced cybersecurity work, including finding and exploiting complex software vulnerabilities. via Reuters | Photo via DepositPhotos.com
    • An Indian manufacturer that assembles roughly one-third of Apple's iPhones and supplies semiconductor components to Tesla confirmed Monday that attackers had stolen and publicly published a 630-gigabyte cache of confidential files — including engineering blueprints stamped "TRADE SECRET," a 52-page quality inspection document for iPhone circuit board components, and cryptographic certificates that security experts say could be weaponized in follow-on attacks. https://www.techtimes.com/articles/319019/20260624/apple-tesla-supplier-tata-electronics-confirms-630-gb-data-theft-iphone-specs-dark-web.htm
  • Recent Achievements

    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      441
    2. 2
      +Edouard
      176
    3. 3
      PsYcHoKiLLa
      133
    4. 4
      Michael Scrip
      79
    5. 5
      Xenon
      77
  • Tell a friend

    Love Neowin? Tell a friend!