Help identifying process

James661

New member
Hi i'm paranoid i got a keylogger or malicious software in my computer for something i did, but the Antivirus did not detect anything wrong, also got recently Zemana antilogger just to be safe and seems everything is okay my question is:

found two processes i don't know what they are or what they do can you guys tell me if they are safe or dangerous? should i leave them or disable them? both are startup processes

hehkkhuf.exe > this one doesn't have description or anything it is located on C:\ProgramData\hehkkhuf.exe i googled and can't find the source it's strange the file is hidden can't find it where is located

csrss.exe > this one seems part of windows but i'm not sure

winlogon.exe > same as the one above

Help me please i'm paranoid
 

My Computer

OS
Windows 7 Home Premium 64 Bit
hi James661, and welcome to sevenforums,

csrss and winlogon are a part of windows - nothing to worry about there.

this hehkkhuf looks very suspect though - do disable it in msconfig, so it won't autostart at each boot, and also download and run the free version of malwarebytes to give your system a good clean.
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
hi James661, and welcome to sevenforums,

csrss and winlogon are a part of windows - nothing to worry about there.

this hehkkhuf looks very suspect though - do disable it in msconfig, so it won't autostart at each boot, and also download and run the free version of malwarebytes to give your system a good clean.

I couldn't disable hehkkhuf at first it wouldn't let me then

I did what you told me and malwarebyte removed 2 files:

1- RiskwareTool
2- Trojan.Agent

minutes later the Norton Sonar removed the hehkkhuf.exe i restarted the computer and the file was gone completely so i think i fixed it still i'll be changing passwords of accounts just to be safe thanks :party:

weird the Antivirus did not detect hehkkhuf yesterday when i got it last night and Zemana Antilogger did not detect suspicious activity so dunno what was that for..
 

My Computer

OS
Windows 7 Home Premium 64 Bit
happy to help :)
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
Back
Top