Malware problems - did RRMF, attached logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by snickerdoodle, Apr 20, 2013.

  1. snickerdoodle

    snickerdoodle Private E-2

    Hi:

    I have an emachines t6410 running Windows XP SP3.

    I have been having issues with my computer for nearly a week now, after recently having upgraded my memory (now 2G) and installed a video card with memory on board (1 G: formerly had integrated graphics and only 3/4 of a gig of memory!).

    Ironically, I started having difficulties right away after the upgrade and hardware installation with getting my new MS updates to download correctly, particularly the Microsoft .NET, and I don't know if it was coincidental or not, but things seemed to settle down for aro 2 weeks, when I all of a sudden started getting MAJOR slowdowns after having had a nice, speedy "grace" period once I got everything sorted out with the new memory and hardware. I downloaded Iobit Malware, and it detected Funmoods in the registry entries, but that was it. I deleted them and then rebooted, did an Avast bootscan, and everything looked all right, but it was still slow. Decided to try one system restore to see if it was as a result of the driver updates and new programs I had installed for the upgrades, but that didn't help. Another scan with Iobit then showed Misleading.SystemRestore in the malware list, so then I started the R&RMF and the downloads. At first I could not get the RogueKiller to install (Message said it was not a valid Win32 application, so i proceeded to the MBAM install, which caused the computer to crash. Upon reboot it never brought up my start up programs, so I eventually used task manager to get it to shut down, where it hung for over an hour or more before I forced a shut down and did a safeboot. I ran the MB onward, and then decided to try to redownload Rogue Killer again from MG's, installed, and this time it worked. Ran that scan after the process had been completed, so I hope it doesn't effect the outcome too much?

    Attached are the logs for the scans.... everything else proceeded normally.
     

    Attached Files:

  2. snickerdoodle

    snickerdoodle Private E-2

    My apologies: I tried to edit my response above to add my MBAM report, because the initial scan did show malware, but it didn't delete it or ask me to restart (and once I did, my computer is so slow I was timed out of the editing :cry). I reran the scan to be sure it COULD be deleted, and both logs are now attached here.

    Thanks in advance for your time and assistance!
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: DefaultTabBHO - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Documents and Settings\Owner\Application Data\DefaultTab\DefaultTab\DefaultTabBHO.dll
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKUS\S-1-5-21-4040081491-1042395676-2837990558-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Mommy.)')
    O4 - HKUS\S-1-5-21-4040081491-1042395676-2837990558-1007\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User 'Mommy.)')
    O23 - Service: DefaultTabUpdate - Unknown owner - C:\Documents and Settings\Owner\Application Data\DefaultTab\DefaultTab\DTUpdate.exe

    After clicking Fix, exit HJT.

    Now uninstall the below software:
    DefaultTab
    J2SE Runtime Environment 5.0 Update 2
    Software Version Updater
    Viewpoint Media Player

    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Please download OTM by Old Timer and save it to your Desktop.
    • Run it by double clicking on it (Note: if using Vista, Win7, or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Services
    DefaultTabUpdate
     
    :Files
    C:\Documents and Settings\Owner\Application Data\DefaultTab
    C:\WINDOWS\Tasks\AmiUpdXp.job
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "NeroFilterCheck"=-
    "RemoteControl"=-
    "Adobe ARM"=-
    "Reminder"=-
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Funmoods]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Funmoods]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Microsoft\Internet Explorer\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7}]
    [-HKEY_USERS\S-1-5-21-4040081491-1042395676-2837990558-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Make sure that you do the below from Normal Boot mode. Safe mode logs do not allow us to properly help you.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Apr 21, 2013
  4. snickerdoodle

    snickerdoodle Private E-2

    Ran MG tools analyse.exe, but was unable to check these two items because they no longer appeared in the register:
    O4 - HKUS\S-1-5-21-4040081491-1042395676-2837990558-1007\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Mommy.)')
    O4 - HKUS\S-1-5-21-4040081491-1042395676-2837990558-1007\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User 'Mommy.)')

    When I deleted the software items listed, Software Version Updater did not appear in the Add or Remove Programs list, so I did a search for it and found the icon listed in the Orbit downloader file and deleted it (I don't make a habit of using Orbit downloader other than when my dancing daughter was downloading things she needed for her major in dance, just to keep things as safe as possible.... never used it to update my software, I always waited to be prompted by the distributor of the software itself).


    Sun Java did not "validate" online after several attempts even after restarting and trying again, so I am going to go back now and see if I can get it to validate and if not, I may uninstall and reinstall to see if it will now work. Please let me know if you would advise otherwise?

    Other than that, everything proceeded as you set out. Things are not looking any better yet - the computer is still being very slow and acting glitchy even after the last reboot. Is there a need for me to deactivate one of the malware programs I had to install during the procedure? I have Avast Free version, and now Iobit Malware and Malware Bytes Malware running on boot, so if that is part of the problem I can either stop one or both of them, or delete as you recommend.

    Thanks again, Chaslang!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to be much more descriptive. B]Please explain what operations are slow! For example answer the below:[/B]
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow? If yes, also answer the below sub-questions
      • What type of connection to the internet do you use ( DSL, Cable, FIOS,etc)?
      • What browser are you using? Have tried more than one?
    • Is downloading slow?
    • Is running any/every application?
    • Is it also slow in safe boot mode?
    • Also are any processes showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?

    We did not ask you to install IoBit Malware Figher. You installed that on your own. Try uninstalling it to see if that helps. You were not really having true malware problem. It was just junkware.
     
  6. snickerdoodle

    snickerdoodle Private E-2

    I am so sorry for the big delay. Things have gotten crazy and I have not had the time to actually do your questions any justice by really playing with my computer to see what was working better and what wasn't. Some things seem to be running a bit more quickly again, but it still does not seem back to normal....

    Boot up (and shut down) is now looking better, but the time from the start page to utilizing email or browser (I am running Firefox, but both that and IE were painfully slow, somewhat improved since I followed your recommendations) is long and it is still slow to open those programs and respond to prompts. I timed it and it is taking about 5 minutes to get things loaded on my desktop, and then open my email which took another few minutes, and then I finally opened Firefox, and it is now almost 20 minutes later and things are just starting to run a little more smoothly. It seems if I don't shut down or restart, and keep just utilizing my word/email and browser, search functions, etc that things almost seem okay, but it is really rough and slow in the beginning. Task Manager is currently reporting 85-95% CPU usage right now, 20 or so minutes in, with most of the memory usage being Outllook, IE, FIrefox, Avast, and one of the svchost entries, of course, accompanied by taskmanager... so was Malwarebytes, but I temporarily exited that to try to help speed it up.

    Things were about the same in Safe Mode.

    For that short period from the time I noticed problems and prior to taking the abovementioned actions, the computer was vvery slow to load anything, do anything, and anything I tried to move, click on, etc., took forever (it seemed) to respond: you know, where you move a prompt or page and it looks like you spread a deck of cards across the screen? It would take so long to respond to a mouseclick I sometimes clicked again (which or course made it worse) because minutes would pass and nothing would happen or a program would not open. The scans I tried to run were taking hours and seemed to be scanning one item a second, pulsing like a heartbeat at 60bpm, instead of flying along. At least that is much better, but not "normal" for my computer prior to the morning I awoke to face all of this trouble.

    We are on cable, using a wired router.

    As I booted this morning, I decided to run the bootscan again (Avast) because while I was under the impression I may have picked up a virus, I had difficulty getting Avast registered (I had, at that time. 11 days left to register, and when I tried to register it, it would not allow me to do it from the direct link, I had to request the code and enter it). Even then, it was being very slow to scan - on that first day it took over 10 hours to scan on boot). Well, though I had started to think we had things under control after following your steps, when I rebooted and did a boot scan, it took 6-1/2 hours to scan 80% of the files, before I gave up and exited to get back on and respond to your questions to help shed some light on the difficulties I am having.

    "We did not ask you to install IoBit Malware Figher. You installed that on your own. Try uninstalling it to see if that helps. You were not really having true malware problem. It was just junkware. "

    Sorry, didn't mean to imply that YOU had asked me to download Iobit, it was what I turned to based on recommendations on MG's when I was afraid that my Avast and Spybot might not be finding malware, so I downloaded that and it reported the Fungames and Misleading.System Restore, as previously mentioned. I just was inquiring whether they would be causing each other to slow down, and so deleted Iobit once I got your response.

    I am relieved you have not found any malware, and am assuming the fungames is the junkware you are referring to (which, I am afraid, may have been downloaded with an update, because I cant figure out how it got on my computer and I am USUALLY the only one who does the updates). I am, alas, the most informed user (thanks to Geeks), but that just means I try to be cautious, not that I am foolproof!

    I hope I provided the details you needed?

    It is now almost an hour since I booted, and the CPU usage is still in the 90's.... something is not right :( I was hoping after things got going it would settle down.

    Thanks for your patience.....
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What process or processes are showing as using high CPU time? Do not report memory use. I want to know CPU usage.
     
  8. snickerdoodle

    snickerdoodle Private E-2

    Firefox, taskmanager, system idle process are currently
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please answer the specifics of my question. I want to know values of CPU usage. But based on you saying Firefox and Taskmanager, it would appear that you have nothing eating up CPU time.

    However note that System Idle is not a process. Is is a measure of the free time your CPU has? Normally when you are not clicking on anything and no scans are running, no pages are being loaded,...etc then System Idle will be anywhere from 92 to 97 %.

    You will most likely have to work your performance issue in the software forum.
     
  10. snickerdoodle

    snickerdoodle Private E-2

    Sorry, I didn't realize you needed to know the values since they are constantly fluctuating. When I was on last night, Firefox was utilizing aro 50 with task manager using aro 25-30 and system idle at 20-25 but now system idle has been fluctuating between 60-99 and taskmanager roughly aro the remainder of that (5-25 or so) with flickers showing IE, avast, or firefox, since I just got in here and haven't clicked on anything else this morning until now, so firefox is now at 50 and above with the others taking up the rest of that total in constant fluctuation.

    Oh, and I forgot to add that my cable connection is DSL.

    Should I submit my issue to the software forum, and need I mention the clean up we just did? Do I need to follow any steps to remove things we used for the prior steps, or the folder on my desktop that was created to remove potential malware/junkware? It is very strange that everything slowed down again after doing the avast bootscan, when it had started to look close to normal.... :(
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try the following ( print if necessary because I don't want any browsers to be opened after the reboot):
    • reboot your PC
    • do not open up any Firefox sessions
    • do not open any other browsers ( like IE )
    • just open Task Manager and observe the CPU usage of running processes. Be sure to select view processes from all users.
    • Do not move your mouse! Do not run any other programs! Just watch for a few minutes. And see how System Idle looks.
    • Then you can open up IE and only IE with only ONE tab (close any other tabs if they open). Monitor again and see how IE and System Idle CPU use look
    • Then exit IE and open Firefox with only ONE tab (close any other tabs if they open). . Monitor again and see how Firefox and System Idle CPU use look
    When I say monitor, it means just watch. Do not move your mouse, click on anything or run anything else. ;)
     
  12. snickerdoodle

    snickerdoodle Private E-2

    Followed your steps, and hope that I am not providing TMI, but want to be thorough, bolded the figures you actually asked for ;) :

    Used Admin Acct because "view processes from all users" was grayed out on my user acct.

    On reboot 30 processes initially opened, went up to 36 without browsers and CPU usage was at 91-99% (Constant fluctuation) until soundman, jusched, QTTask, ctfmon, CCC.exe and MOM.exe loaded (what is MOM.exe - I noticed that only recently?) where the processes fluctuated only between explorer, avastSvc., task mgr, and system idle process (I monitored for over 12 mins).

    During that time: taskmanager ranged from 18-22% for the most part, occasionally blipping higher, with system idle splitting the difference other than VERY occasional second-or-two-long interruptions for AvastSvc or System, or explorer.exe. At around 10 mins(!!) a pop-up message for MBAM interrupted to remind me that the trial period is now expired. CPU usage stayed in the mid to high 90's with an occasional blip into the 80% range. So, system idle stayed somewhere around 60-90+% for the most part swinging largely back and forth with task manager.

    Opened IE (first attempt of double clicking rendered nothing after 6 mins so I tried again) Monitored for more than 18 minutes. 38 processes running now. Took almost 2 minutes to open a page. Monitoring showed the task manager initially ranging from 30-50% then settled down to more like 13-32%, with system idle process ranging from 63-99% to split the difference with tskmgr and IE, which just occasionally registered at 8, 11, and 25% for the most part, sometimes just flashing for a second or two and then returning to 00, and sometimes several changing flashes around those values, and then 30secs-1min later returning to 00. (there were only very occasional one or two second long interruptions from lsass.exe, AvastSvc.exe) IE was very quiet after a few minutes, with CPU usage by the end of that period looking more like 85-99%.

    Closed IE and opened Firefox, 37 processes running now. Monitored for about 15 minutes when my computer went to sleep (was following directions not to use my mouse!) Firefox took less than one minute to open on the first doubleclick (which is pretty typical right now) and initially Firefox.exe (swinging between 25-99%) , AvastSvc.exe and task mgr were running (no system idle process) and CPU usage was 100%. 2 minutes in and task manager was registering ranges of 20-25% ( a little later it was more like 10-33%) and Firefox was registering occasional blips at 17, 20, 29 and 33% so system idle process swung between 57-99% for the most part AFTER things settled down in that 2 minute plus period of time. CPU usage was staying at 88-97% for the most part during that time after the initial 2 minutes. (Very occasional interruption for IE, system, jqs.exe.or lsass.exe).

    NOTE: I did not shut down my computer yesterday so that I could see if things settled down after awhile, and they did. I did not see my CPU usage over something like 25-45% all day yesterday until I rebooted today even with several tabs open in Firefox, and Outlook also running. That means that from the time I booted up and posted to you the night before (aro 8pm), until somewhere midafternoon yesterday (but not by 8am when I responded to your post) things returned to somewhere reasonable, and i was able to browse and email and update within a pretty typical (for my old overloaded computer), reasonable amount of time. I don't know if that brings any illumination, because there were not other processes running that I could see to explain WHY it takes so long for my CPU usage to drop after a boot up (though I was on my user acct and the view processes from all users prompt IS grayed out)..

    Just took one last peek at my task manager, and things look about the same now that I am only using Firefox with one tab open to respond to this post.

    Hope this helps!?
    Thanks for your patience.... you guys rock!:heart
     
  13. snickerdoodle

    snickerdoodle Private E-2

    Okay, had to edit this in case it is relevant: Just logged off admin act and logged on to user acct (since rebooting seems to render it so slow). Am currently running firefox with four tabs open, and have Outlook open as well, and my current CPU usage is at 4-21% max (more like 4-11%) and the system idle process is wavering between 80% and 90-something% and things are running as quickly as they normally do for my computer when it IS NOT having any difficulties. (the remainder being split of course between firefox and task manager with figures in the SINGLE digits).
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even with Firefox open, when not doing anything, your System Idle CPU Usage should show 95 to 99 % Typical would be 99%. See the below snapshot from one of my Win XP SP3 systems with both Firefox and Internet Explorer running.

    CPU_USE.jpg

    You can double click the thumbnail image to expand.

    This is taken after the system has started up and all automatic updates format Windows, antivirus, antispyware, and browsers have completed. If any software is being updated, this System Idle CPU use would be significantly lower because the PC would be busy with other things.

    Perhaps it is time to try a couple things. The first I would recommend is to uninstall all of the below:

    Avast
    IObit Malwarefighter
    Malwarebytes' Anti-Malware

    Then reboot your PC. How does it perform now?

    Also so that I can see the effect of the uninstall, please continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
    Last edited: May 12, 2013
  15. snickerdoodle

    snickerdoodle Private E-2

    Perhaps it is time to try a couple things. The first I would recommend is to uninstall all of the below:

    Avast :eek
    IObit Malwarefighter
    Malwarebytes' Anti-Malware



    I had already deleted IObit upon your earlier recommendation, so I downloaded some MS updates that came up (while I still had antivirus) and then followed your instructions to uninstall MAM and Avast. Unfortunately, CPU usage remained practically at 100% with almost NONE of it system idle as I proceeded through those steps, and after uninstalling Avast. Attached logs as you directed. Will be eagerly awaiting your next instruction because I dont want to be using my computer for email and stuff that I really need without any AV installed :)

    Can't wait to find out why after a fairly lengthy period of time my usage finally looks more like yours, but it sure is slow getting to that point!

    Hope you are able to enjoy Mother's Day with your family today. Thanks so much!
     
  16. snickerdoodle

    snickerdoodle Private E-2

    Sorry: should have verified that the zipfile actually had a chance to attach before I sent my reply.... sheesh this thing is so slow.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like everything uninstalled but I still do not want you to reinstall anything.

    I still don't think your problem is due to malware. One observation is that I see the Windows Installer service running and this should not normally be running. This would only be running when some software ( including Windows ) in being installed or updated.

    Also I see the WMI Performance Adapter Service running and it is also not normally running.

    Let's try two things.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.



    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now just to check a little deeper for infections, I want to run ComboFix per the below.



    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder.
    • Then double click on it to run it. Do not disturb it by clicking in the window that opens or it may stall.
    • After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
    • If after running Combofix you discover none of your programs will open up because you receive the following error:
      • Illegal operation attempted on a registry key that has been marked for deletion
    • Then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: May 12, 2013
  18. snickerdoodle

    snickerdoodle Private E-2

    Ran and attached the files as requested (I believe combofix is attached with MGlogs but attached it separately just in case?) CPU usage is around 88-99% and the system idle is swinging between 00 and 80something right now, with lasass, system, taskmanager and firefox being the other values.... not really seeing an improvement, but I am not opening browser pages or email to test it since I am unprotected from virus right now.... Thanks again for your help.
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will not see any improvement based on what I seeing in all your logs because this does not appear to be a malware problem. I want to collect one more log to look at. Use Internet Explorer to do the below download and have Firefox closed. Just keep Internet Explorer opened while doing the below scan.


    Download ProcessExplorer
    • Unzip it to its own folder somewhere you can locate it.
    • Now run procexp.exe by double clicking on it.
    • Let's configure some options first:
      • Click View and select Show Lower Pane. And where it says "Lower Pane View" make sure DLL's is checked.
      • Now click on iexplorer.exe.
      • Now also under the View menu choose "Select columns" and put a check mark on "Image Path".
    • Now click on File and then Save As. And save the process list.
    • Post it back here as an attachment.
    Now reinstall your protection software. I would just install Avast for now and not IObit Malwarefighter.
     
  20. snickerdoodle

    snickerdoodle Private E-2

    Attached file as requested.... about to go install my Avast. Curious to hear what you are finding since it is not malware.... thanks!
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log shows

    Interrupts 85.71 0 K 0 K n/a Hardware Interrupts and DPCs

    85.71% of your CPU was being use for Hardware Interrupts. This is not a malware problem but rather a Windows problem you really should be addressing in the Software Forum. It may be related to the below below topic:

    http://winhlp.com/node/10

    http://support.microsoft.com/kb/817472


    See how it solved some user's problems here:

    http://forums.cnet.com/7723-6142_102-235347/90-100-cpu-time-by-hardware-interrupt/
     
  22. snickerdoodle

    snickerdoodle Private E-2

    Thanks chaslang.... I will post in the software forum after I finish reading the links you provided (I already checked my IDE port and it is set to DMA) to see what I can do about the Hardware Interrupts. Is it appropriate to link to this thread or quote your last response on this thread?

    Also, should I do clean up now from the malware removal process? I still have all of the programs, logs, etc., on my Admin desktop in case we were to need them again.

    I have been considering doing a clean reinstall of my computer in June, just wanted to complete reorganizing my voluminous music files and backing them up as well as a last ditch effort to take an Outlook file from an earlier restore and attempting to recover some lost email contacts before I do an overhaul. Would that help with this problem too? If so, perhaps I should just back up the files and try to restore that old outlook file first, and start over?

    Thanks for all of your help!
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes.

    Yes. Instructions down below.

    A reinstall could help if it is a software/driver conflict of some sort, but if it is really some kind of hardware issue, it may not help or could only be short lived..

    Restoring outlook files has nothing to do with fixing your problem so this is you decision.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds