Hi, I am Sam.
I recently started encountering this trouble where everytime I started up my pc, and connected it to internet, it would start an instance of cmd.exe that would take up a chunk of my Memory (~2GB). I saw this problem reported by three more fellas on this community and one dude on a reddit. A dude on that reddit post claimed that this is a cryptocurrency trojan that uses up your computer resources to mine cryptocurrency. That would explain the need for an active internet connection to kickstart the process. Also, once the process is closed, it doesn't commence automatically on any condition unless the pc is restarted. Now, I tried what the dudes in those threads attempted and some other things.
1.Yeah it's the authentic Command Processor application from System32 directory.
2.The Process Explorer showed , once that is was started by a NVIDIA Web Helper parent process, and other time it was started by Explorer parent process/program.
3.I ran a Quick and a Full scan from Windows Defender and Malwarebytes and a Microsoft Offline Scan, which all yielded no threats.
3.5.I even ran an FRST scan and it generated nothing suspicious to be actionable.
4.I also tried a clean boot. The problem still persisted.
I have already disabled all startup items, but still checked them, and rebooted. The problem still persisted.
I checked all the possible task schedules in Task Scheduler Library that might cause this, and disabled all Nvidia related tasks and all the tasks that had a trigger of 'Start on reboot'. The problem still persisted.
5.The latest program installed after which it all started happening, although not immediately after, was Google Chrome. There are no malicious extensions or programs or files downloaded from there onwards. So, I don't believe it's related to Chrome Installation. And yeah, it was an official installation from official website.
My Windows Version is 11, and it's an ASUS laptop with Intel CPU and Nvidia GPU. I am not sure if that helps but, can't hurt either to say.
I was about to do a Factory Reset but decided to come here first and kept the reset as a last resort.
I would like some further insight and if possible a solution into this problem.
Hopefully before I turn for the inevitable.
And thanks for reading till here!
Standing by,
Sam.