Instant savings app, high cpu usage, trojan.agent/gen-nullo short possible virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Corm, Nov 27, 2013.

  1. Corm

    Corm Private E-2

    Hi guys,

    Hopefully someone can help me. I'm not great with computers, but someone recommended your forum to me. I think my laptop may be infected by a virus, but I'm not completely sure. I had a thing called instant savings app, which I think I managed to remove, but then started having problems with svchost.exe using up 100% of my cpu usage - that turned out to be the wuauclt.exe file, although i'm not sure entirely what that is, although turning automatic windows updates off seems to have worked. I've run malawarebytes which didn't find anything, but i've just run SAS and its found trojan.agant/gen nullo (short). Is my system infected?

    Can anyone help?

    Thanks guys,

    Corm
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. Corm

    Corm Private E-2

    cool, thanks Tim, sorry, I should have done that first. Just running the scans now and will post logs. Thanks again for your help. :)
     
  4. Corm

    Corm Private E-2

    Ok, I've followed all of that, and the logs are attached below. Computer still seems a little sluggish, and chrome seems to be sucking up a little more CPU usage than normal. Also, still have a problem with svchost.exe and the wuauclt.exe process when i have automatic updates enabled sucking up 100% cpu power. If automatic updates are disabled, or I kill the process in process explorer, cpu usage immediately drops.

    Is it likely my system is still infected?

    Thanks in advance guys, I really appreciate your help.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you explore your issues in the software forum.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.


    After doing the above, you should work thru the below link:

     
  6. Corm

    Corm Private E-2

    Tim thank you so much for your help. I'll have a read of that link you posted now, and get myself better protected. Thank you so much again, I really appreciate it.
     
  7. Corm

    Corm Private E-2

    should i also complete step 4 - toggle system restore from the windows xp malware removal thread?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, don't toggle system restore until you have fixed your other issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds