dslreports logo
 
    All Forums Hot Topics Gallery
spc
Search similar:


uniqs
1269

The Penguin
join:2001-07-31
45 South

The Penguin

Member

Setup.exe

Recently my pc became very slow and unresponsive with the hard drive working. I checked Task Manager and saw that something called 'setup.exe' in 'System' was taking up huge amounts of cpu/memory.
I was not installing or uninstalling anything at the time. I eventually rebooted to get my pc back to normal speed. Does anyone know what this would be and if it is a legit file, is it necessary?
Thanks for any advice.

VikingBob
Go Jets Go!
Premium Member
join:2004-06-05
MB Canada

1 edit

VikingBob

Premium Member

That could be pretty much anything, legit or not. There are plenty of different files out there called setup.exe... Do a search on your hard drives, and see what comes up. Submit to virustotal if you feel the need.

If you could have run Sysinternals Process Explorer while it was running, you could have found out where the file is/was located.

Juggernaut
Irreverent or irrelevant?
Premium Member
join:2006-09-05
Kelowna, BC

Juggernaut to The Penguin

Premium Member

to The Penguin
End that process, and see how the computer reacts. If it restarts automagically, you may have a problem. Finding out what it is, is the first step.

The Penguin
join:2001-07-31
45 South

The Penguin

Member

Thanks for the replies VikingBob and Juggernaut.It hasn't kicked in again yet, but when/if it does I'll see if I can pin down where it's located. In the meantime I've run Malwarebytes and that found nothing.

Snowy
Lock him up!!!
Premium Member
join:2003-04-05
Kailua, HI

Snowy

Premium Member

said by The Penguin:

Thanks for the replies VikingBob and Juggernaut.It hasn't kicked in again yet, but when/if it does I'll see if I can pin down where it's located.

Something named "Setup.exe" would create folders/files you'd think.
I'd do a file search for all the folders/files created today (or whatever date the unknown process was seen) looking for something out of the norm.

The Penguin
join:2001-07-31
45 South

The Penguin

Member

Did a search and found 'setup.exe' in...
C/Windows/System32
C/Windows/System32/Dll cache

Also several in C/Program files/Installshield Installation Information
(type: setup launcher)

As the 'user' in Task Manager when it was running was 'system' I'm picking it might have been the one in the system32 folder.
Its size is 22.5kb and type is 'Windows NT setup executable'
Can't think why it would run for no apparent reason though.

Dustyn
Premium Member
join:2003-02-26
Ontario, CAN

2 recommendations

Dustyn

Premium Member

You could try uploading that individual file to VirusTotal?

Snowy
Lock him up!!!
Premium Member
join:2003-04-05
Kailua, HI

Snowy to The Penguin

Premium Member

to The Penguin
said by The Penguin:

Did a search and found 'setup.exe' in...
C/Windows/System32
C/Windows/System32/Dll cache

You should upload it as Dustyn See Profile suggests.

*If* setup.exe was malware it may not be searchable after execution, so I'd actually pay more attention to any files or folders that were created.
Have you looked at event viewer for any entries that could explain it?

The Penguin
join:2001-07-31
45 South

The Penguin to Dustyn

Member

to Dustyn
Ok. Just uploaded and no detections.
Looks like it may be a legit file, but now wondering if it is a necessary one if it 'freezes' the computer when running.
The Penguin

The Penguin to Snowy

Member

to Snowy
Just checked 'event viewer' system log and all 'system' user events are listed as either 'Service Control Manager' or a few as DCOM (source) 'error'.

Snowy
Lock him up!!!
Premium Member
join:2003-04-05
Kailua, HI

Snowy to The Penguin

Premium Member

to The Penguin
said by The Penguin:

Ok. Just uploaded and no detections.
Looks like it may be a legit file, but now wondering if it is a necessary one if it 'freezes' the computer when running.

Send it over to a sandbox for an analysis.
»www.threatexpert.com/submit.aspx

The Penguin
join:2001-07-31
45 South

The Penguin

Member

Analysis: Something about host being Internet Systems Consortium?
Nothing else.

norwegian
Premium Member
join:2005-02-15
Outback

norwegian

Premium Member

It could have been a corrupted installer, poorly coded program etc, an endless loop because of it etc. Setup.exe is a standard installer file.

You need to monitor your task manger and the memory/cpu components of performance and also cpu and memory columns of the processes tab. Please use also (check box); view-select columns-select PID

If you can see something is high on usage and the networking tab shows high usage - and you are not downloading, you may need to run:
cmd (under admin)- type netstat -ano - the PID will match so we can link the IP addresses to the process. I can go into detail but with such limited info to start with, at least operating system etc to help be more specific in replies.

ZZZZZZZ
Premium Member
join:2001-05-27
PARADISE

ZZZZZZZ to The Penguin

Premium Member

to The Penguin
»www.nirsoft.net/utils/co ··· iew.html

Use this to see what triggered it or Windows cleanup utility,too.

The Penguin
join:2001-07-31
45 South

The Penguin

Member

Thanks for the advice. Setup.exe hasn't cut in again as yet but have d/loaded 'LastActivity' and will run it if it does. (and if I can!)

Windows XP
Firefox

ZZZZZZZ
Premium Member
join:2001-05-27
PARADISE

ZZZZZZZ

Premium Member

It's a standalone app that doesn't need installing!

The Penguin
join:2001-07-31
45 South

The Penguin

Member

But doesn't it need to be activated from its exe file when required? (When setup.exe was running, my pc 'froze' and I couldn't get to anything)

ZZZZZZZ
Premium Member
join:2001-05-27
PARADISE

ZZZZZZZ

Premium Member

Just double click the program exe........if nothing happens then you've got other problems.