High Cpu & Memory Usage When At Idle - Logs Attached

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axlmastr, Nov 24, 2016.

  1. axlmastr

    axlmastr Private E-2

    Machine (laptop) is slow. Friend asked me to look at it.

    High CPU & Memory usage at idle. Cooling fan never stops. AV was removed prior to running scans.

    Logs attached
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Those logs are clean of malware. However, doubling the installed RAM of this machine would be beneficial.
    ____________________________


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Go to add/remove programs and uninstall HijackThis.
    5. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  3. axlmastr

    axlmastr Private E-2

    You make a valid point about RAM but the logs are clean and my symptoms are still there. I am very very familiar with cleaning these machines and if it really stumps me I'll post logs here for review just in case I missed something.

    The machine is literally sitting, from the time of booting to the desktop to a couple of hours idling, at 100% CPU and high memory usage no matter how much RAM is installed. I posted a screenshot of Process Explorer to show the affected svchost.exe and it's dependents as a visual. The fan is always on. I know something is holding this machine hostage because it should be quiet with nothing open and as you stated "clean logs". I tried to run Combofix at one point prior to posting, as I know you can see in the logs, but it remained stuck on Stage 48 for over 6 hours on multiple attempts so I know something is wrong.

    I know Combofix is a serious program and the warnings are always given to not use it without assistance form one of the malware experts, but on more than one occasion I would run it without an scripts added to it and it would root out whatever possessed the troubled machine I was working on and things were back to normal. This machine will not run it. Please advise.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Replying to your points first, then we'll go further:
    • I would expect some sluggishness using Win 7 + 2.2GHz Single Core processor + 2GB RAM (660MB available)
    • Configure Process Explorer differently to aid tracing processes and handles
      • Once opened, select Options
      • Put ticks by "Verify Image Signatures", VirusTotal.com > Check VirusTotal.com, Confirm Kill
      • At the far right you will see the VirusTotal column showing scan returns of running processes
    • It is not unusual to hear that Combofix won't run on some particular machine... have had reports of this in my threads and have experienced it myself.
    _____________________________________

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
    Next, please download and run Zemana AntiMalware.
    When the scan is completed, view my attachment for how to retrieve the log. (Click the icon high-lighted by the arrow, mouse-click the latest System scan then click on the "Open Report" radio button). Upload that log also, please.

    Question: Has the owner had problems with Windows Updates possibly failing lately?

    Zemana reports.png
     
    Last edited: Dec 1, 2016
  5. axlmastr

    axlmastr Private E-2

    I know what you mean about the hardware constraints, but this machine has been in better shape. I've cleaned it twice before and it didn't have this issue afterward.

    I too have read threads on Combofix hanging but hadn't experienced it until this machine this time around. I've heard of running it in Safe Mode but not sure how well that would do if it doesn't have everything loaded in as in Normal mode.

    I followed your steps on the Process Explorer. I've not ever used it the way you described. Learned something new.. thanks. What was I accomplishing by changing the settings as described? What was I looking for when the items in blue showed up along the right column?

    The owner wouldn't know if he was or wasn't receiving windows updates so to answer the question about them failing..... he likely wouldn't notice.

    The logs are attached from Farbar and Zemana. I was going to run Zemana, but I didn't get to it before posting. Good reminder from you to do so.
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Under the far right column under VirusTotal, those numbers in blue are the results of each process being evaluated by the VirusTotal scan engines.
    0/56-57 means not infected​

    Here are a couple of links for your reference:
    http://www.howtogeek.com/school/sysinternals-pro/lesson2/
    https://blog.malwarebytes.com/101/2016/05/process-explorer-part-2/

    *After running the attached Farbar FRST fix, I'll send you off to our Software Forum where help is waiting for your topic. (Thanks, satrow! ;))

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right-click FRST(x32/64) and select Run as Administrator.
    • Click the FIX button once.
    • Wait while FRST processes fixlist.txt
    • A report should pop up named Fixlog.txt, I really don't need to review it.
    _____________________________
    It is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If running Vista, Win 7/8/10 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Go to the C:\MGtools folder and find the MGclean.bat file. Double-click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds