Computer is slow on start up, and uses 100% cpu usage on M.silverlight applications

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Help-is-needed-quickly, Mar 29, 2011.

  1. Hi,
    My computer is running slower and slower,
    and uses 100% cpu usages from time to time. Especially when watching videos online (using Microsofts Silverlight applications. Also svchost.exe files are taking up all resources..

    what to do?


    Have done all the tests required (or at least tried to)..

    SASlog.txt log from SuperAntiSpyware. ATTACHED
    Malwarebytes Anti-Malware log ATTACHED
    ComboFix.txt (normally C:\ComboFix.txt) Can't load from Desktop:
    in other words it starts loading, with the green bar. but after that stops and does nothing.

    RRlog.txt (from RootRepeal) when trying to open it: says ERROR: attempt to write to addresss 0x014ac000

    MGlogs.zip - normally it is C:\MGlogs.zip
    Have run this, but the program kept saying that it couldnt write to C:\MClog.

    Im attaching from the MCtools folder the HiJackthis.log (Logfile of Trend Micro HijackThis v2.0.4-in lack of something better)..

    What to do now???


    Am runining a Sony Vaio Z-31 laptop
    Win 7 home premium
    SP 1
    Intel core 2 Duo CPU 2,66ghz ..
    4gb ram
    32-bit

    thank you for your help and assistance. highly appreciated.

    Regards,
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Did you set the below proxy yourself?
    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Make sure that MGTools.exe is directly in the root folder of your Windows Boot drive, usually C:\ (Do not have it to your desktop)

    Run the new C:\MGTools.exe and attach the C:\MGlogs.zip that it produces.
     
  3. Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Thank you for your reply..
    No - i havent set any proxies .......!!!!!

    Tried to do as you sugested. Ran the MGtools from C:\ but no log was created.
    This is what was written after the analysis:
    (i have typed it out of the cmd file that ran.)
    ---------------------------------------------------

    Found and zipping C:\Qoobox\Quarnatine\Registry_Backups
    zip warning: name not matched: C:\Qoobox\Quarnatine\Registry_Backups\*.*

    Zip error: Nothing to do! (C:\MGlogs.zip)
    Finsihed Zipping CF Registry Backups

    Zipping filelog.txt
    adding filelog.txt (172 bytes secuirty) deflated 79%
    Finished zipping filelog.txt


    Scanning comlete - your log file is C:\MGlogs.zip ***


    Thank for your assistance.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Do you now have a log on the C:\ drive?

    If NOT then you must complete the next step:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
    Last edited: Mar 30, 2011
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    According to the below quoted from your message, the log as created. And the hijackthis.log file attached in message # 1 was created from running MGtools. Did you look in the right location? The MGlog.zip file is not located in the C:\MGtools folder. It is is located at C:\MGlogs.zip

     
    Last edited: Mar 30, 2011
  6. Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Hi Kestrel13! ,
    thank you very much. followed your instructions and now it works.
    I now have not only the 2 files you asked for but the entire zip folder.
    Will attach that.
    I also did what you said about fixing the following ín HJT:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 82.103.133.114:8080

    please review the attached file at your convenience.

    THANKS IN ADVANCE
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    So you did this after running MGTools? If not then it is still there and you will need to do the below: (also need to fix other item I shall list)


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    What is the contents of this folder?

    C:\Program Files\F‘lles filer

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    • Right-click OTM.exe And select " Run as administrator " to run it.
    • Paste the following code under the [​IMG] area. Do not include the word Code.
    Code:
    
    :files
    C:\Users\Nicolai Audon\AppData\Local\{084DACD9-11DB-4FD0-B14E-311137E4E8A6}
    C:\Users\Nicolai Audon\AppData\Local\{08657F63-9042-4EB6-8A4A-D47DEADEEADB}
    C:\Users\Nicolai Audon\AppData\Local\{0E1849C0-086E-4E75-B2E9-06B339A23B32}
    C:\Users\Nicolai Audon\AppData\Local\{0E654CF8-8959-41B9-8F8F-41C8CB576FAC}
    C:\Users\Nicolai Audon\AppData\Local\{10AEB4D4-B9CD-4D3A-A7E9-9732887F11BD}
    C:\Users\Nicolai Audon\AppData\Local\{134AB564-ED5B-4912-9910-4A8B7D6D8C49}
    C:\Users\Nicolai Audon\AppData\Local\{13A649CA-78F6-48B7-BCFF-8A6A1D22EEA7}
    C:\Users\Nicolai Audon\AppData\Local\{1509B1D6-5C5E-4FFA-8B8A-0410A7541B36}
    C:\Users\Nicolai Audon\AppData\Local\{1B9A1EFD-EA34-4AF0-9D4C-112ECA7EBFF3}
    C:\Users\Nicolai Audon\AppData\Local\{1E35759E-330F-4439-89B1-C6BBAE8F259A}
    C:\Users\Nicolai Audon\AppData\Local\{20D1CAE2-EA67-46BF-9E25-CB1E74BD4286}
    C:\Users\Nicolai Audon\AppData\Local\{2BEC9C9A-B06C-4B4B-8606-1EC6BBC2417B}
    C:\Users\Nicolai Audon\AppData\Local\{2C29D2DB-F3B7-459B-B306-B5077246DB32}
    C:\Users\Nicolai Audon\AppData\Local\{2CC3E6C3-715F-4C17-8E61-AD8C69FACAAE}
    C:\Users\Nicolai Audon\AppData\Local\{2F0AE622-FCD0-44D8-9EED-29265254696B}
    C:\Users\Nicolai Audon\AppData\Local\{3A34F083-DAE6-47CF-A05D-726B39021608}
    C:\Users\Nicolai Audon\AppData\Local\{3D8B0F37-B6AF-405E-B797-45F8D17F1947}
    C:\Users\Nicolai Audon\AppData\Local\{40EE71FC-3057-473E-84B8-379BCA24287A}
    C:\Users\Nicolai Audon\AppData\Local\{4402885B-0495-4053-BAF8-9DE7F4EFBCAE}
    C:\Users\Nicolai Audon\AppData\Local\{47C089A2-B529-4F13-98BE-6AAD52BEB766}
    C:\Users\Nicolai Audon\AppData\Local\4DA988AB-153A-428B-875C-4650F4CA1E01}
    C:\Users\Nicolai Audon\AppData\Local\{52139BDA-6F40-4307-BDD4-859FDCE3B75B}
    C:\Users\Nicolai Audon\AppData\Local\{53AD41F7-F839-4F0D-85CE-5502FE93793E}
    C:\Users\Nicolai Audon\AppData\Local\{5467CAFB-1C4C-4BD0-BFB0-97235B3686EA}
    C:\Users\Nicolai Audon\AppData\Local\{635F3E9E-E2E3-4EA0-85A9-03D4E21D7403}
    C:\Users\Nicolai Audon\AppData\Local\{6775D4F3-1DA9-4E41-BCF5-7F931746E3BC}
    C:\Users\Nicolai Audon\AppData\Local\{690D5137-48B5-4453-B8FF-2D838A4A07ED}
    C:\Users\Nicolai Audon\AppData\Local\{6B47A693-FDA0-4126-9BDC-03F6D2CFBE06}
    C:\Users\Nicolai Audon\AppData\Local\{6EFEAFC0-A884-4A43-8AA0-534B0F4B4422}
    C:\Users\Nicolai Audon\AppData\Local\{73178B7F-18C3-4EA7-BCFC-27C91635A1ED}
    C:\Users\Nicolai Audon\AppData\Local\{7612BB53-BB53-4991-9909-B6FEDFFD2338}
    C:\Users\Nicolai Audon\AppData\Local\{7A167B54-E837-4F2B-9A33-7374D48BAB27}
    C:\Users\Nicolai Audon\AppData\Local\{842ED8BB-9F03-4E44-9675-3E41DC42EF2A}
    C:\Users\Nicolai Audon\AppData\Local\{8C11E521-2423-45B4-855F-F4058BA3AB3C}
    C:\Users\Nicolai Audon\AppData\Local\{8CCAF8CF-3D01-4820-A35B-F4B7A59A304E}
    C:\Users\Nicolai Audon\AppData\Local\{90538E7A-0EE0-457D-AD63-5FDA203CBB5B}
    C:\Users\Nicolai Audon\AppData\Local\{91AFB5FE-690A-42FD-9DA0-1EED5320EDE5}
    C:\Users\Nicolai Audon\AppData\Local\{92C0B8E5-40B0-4C6A-BE0C-8D815C3895A1}
    C:\Users\Nicolai Audon\AppData\Local\{9885D663-027F-451C-B67F-BAD52ADC4C00}
    C:\Users\Nicolai Audon\AppData\Local\{989C5D8F-A73E-4824-B449-0097828EF832}
    C:\Users\Nicolai Audon\AppData\Local\{9B74BF09-4626-4F27-AEFF-A00C18713987}
    C:\Users\Nicolai Audon\AppData\Local\{9B854CFF-8851-4FD9-B2FC-2F26C0BD0A15}
    C:\Users\Nicolai Audon\AppData\Local\{A1831325-8D3F-4A7B-81F3-2BCDC5457151}
    C:\Users\Nicolai Audon\AppData\Local\{A1BCCB75-580C-48D8-A57A-063DB8344A03}
    C:\Users\Nicolai Audon\AppData\Local\{AC71E4E8-2A7C-4A69-9366-0F8CF5B1630B}
    C:\Users\Nicolai Audon\AppData\Local\{AC8501A0-C3F2-4247-8AB2-C64A970C11D8}
    C:\Users\Nicolai Audon\AppData\Local\{B3A5D0FD-B781-4620-8CD7-F1A5404A315E}
    C:\Users\Nicolai Audon\AppData\Local\{BB0A6235-1D93-44C1-A52E-AD268B553083}
    C:\Users\Nicolai Audon\AppData\Local\{BE9DCBD9-1B5E-4C9D-8256-E8FDAA6F3A6F}
    C:\Users\Nicolai Audon\AppData\Local\{C38A1247-7237-4A49-9331-F6E3C4EC834D}
    C:\Users\Nicolai Audon\AppData\Local\{C9902147-7528-4AAE-A038-2D5C56FDAB32}
    C:\Users\Nicolai Audon\AppData\Local\{C9926E42-BB8A-46A3-A64E-5AC0861F0435}
    C:\Users\Nicolai Audon\AppData\Local\{CC66E06E-BA8C-4EF2-8ABC-9B7CF6A85E62}
    C:\Users\Nicolai Audon\AppData\Local\{CD0E5BF5-70AB-4219-B878-9C64785F792D}
    C:\Users\Nicolai Audon\AppData\Local\{CDF128B4-7B7A-4BD0-A904-6CAA2201A7BD}
    C:\Users\Nicolai Audon\AppData\Local\{CF07E791-13AA-49C6-A3C7-5CBDF4F4E9C0}
    C:\Users\Nicolai Audon\AppData\Local\{CFBFF01B-7FE9-49F1-B3F6-A114D74E023D}
    C:\Users\Nicolai Audon\AppData\Local\{D54D9F93-033E-4AF9-ABD4-5F3BA7E69F05}
    C:\Users\Nicolai Audon\AppData\Local\{D6A5C6D8-6572-4E76-851A-FA8D035058D4}
    C:\Users\Nicolai Audon\AppData\Local\{D877ADD1-5F31-4847-984E-29F8D1FF1382}
    C:\Users\Nicolai Audon\AppData\Local\{E2BAB2F4-8556-40FF-B493-2B8AD965CCA5}
    C:\Users\Nicolai Audon\AppData\Local\{E4E0BA1A-F458-4784-B5A5-7E9BAA025BD7}
    C:\Users\Nicolai Audon\AppData\Local\{EC7F2B62-4AB1-4F80-BB82-E29A986905AD}
    C:\Users\Nicolai Audon\AppData\Local\{F427B305-02DE-4BC0-AF78-9F7B9F52677D}
    C:\Users\Nicolai Audon\AppData\Local\{F7C3D4BA-50C1-4B3B-9CAC-9C49A42B97B2}
    C:\Users\Nicolai Audon\AppData\Local\{F838DD3D-81FE-40B5-BC01-ADB17F86BAE8}
    C:\Users\Nicolai Audon\AppData\Local\{FC54EC44-F264-42A8-A8FE-8EC992A93F83}
    C:\Users\Nicolai Audon\AppData\Local\{FC8E7353-6984-4178-B30E-A6A00B149C16}
    C:\Users\Nicolai Audon\AppData\Local\{FDE9E562-25E5-470C-8FE0-87B9A4124EB7}
    C:\Program Files\Ask.com
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large [​IMG] button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    How are things running for you now?
     
  8. Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Thank you for your good instructions.

    I ran MGtools again.
    R1 was already gone from last time
    I now deleted 02 as well.
    Attached to this messege.

    C:\Program Files\F‘lles filer
    fælles filer = is shared files
    For some reason it is resricted. when trying to open it it says:

    C\program files\fælles filer is not accessible
    Access denied.???


    Have attached the OTM file and the zip.files from MGtools .

    hope things are better now. When you have time I would appreicate if you explain the situation. what have you guided me through?? :) and was the issue severe. Virus/malware ?????

    thanks again for your support.
     

    Attached Files:

  9. Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    FYI:
    when running internet videos using Microsoft Silverlight or other video applications.
    you-tube, video on demand etc etc. my computer still uses 100% cpu.

    Internet explore.exe then consumes all the resources, making the computer slow and sometimes it will even freeze as well.

    Any ideas??
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    that you recognize I presume?

    Delete these folders by using windows explorer:

    C:\Users\Nicolai Audon\AppData\Local\{4DA988AB-153A-428B-875C-4650F4CA1E01}
    C:\Users\Nicolai Audon\AppData\Local\AskToolbar

    So far a proxy was set which we removed and also took out a bunch of folders which I suspect were all either empty or contained garbage.

    Now, I am interested to know before we wrap up whether combofix will now run or not. Can you double click its icon on your desktop (right click and run as admin if using win7 or vista) and once it has finished its scan please attach the C:\combofix.txt
     
  11. Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Have deleted the two files you mentioned.
    and now the combot fix seems to work
    have attached it below..


    whats your verdict now??? :)
     

    Attached Files:

    • log.txt
      File size:
      23.9 KB
      Views:
      1
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re: Computer is slow on start up, and uses 100% cpu usage on M.silverlight applicatio

    Looks good to me ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds