Resources are Burning Busy...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ct1069, Aug 14, 2007.

  1. ct1069

    ct1069 Private E-2

    Malware has gotten me again. I was doing mundane stuff on Sunday afternoon when I got "Not enough virtual memory" warning from windows. I was running nothing and the computer has 1 gig of memory. A quick check of CPU said 95%. When I reboot in normal mode, something takes ahold of the processor and sends it on a trip -- 100% and nothing else will run -- I have no internet access because I can't get DSL started. I'll went to the library to get the "Read and Run this First" guide which I will get started with tonight. Hopefully someone here can help me get control of my computer again.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It would be a lot more helpful if you could give more specific information.

    1. What process or processes are using all of your CPU time?
    2. Does it happen in safe mode?
    3. What do you mean you can't get DSL started? Do you mean that is separate problem or are you saying it is related to the CPU useage problem?
    Please do as much of the READ & RUN ME as is possible given your problems and attach the requested logs. Even if you have to run everything in safe mode (including things like GetRunKey, ShowNew and HJT) it is better that nothing. The more logs you provide, the greater the chance we can help you. If all you provide is a HijackThis log, we may not be able to help you. There is a good chance that these problems are not due to malware.
     
  3. ct1069

    ct1069 Private E-2

    Sorry for the cryptic, unfinished message. I posted that message at the public library with only a couple more minutes of use available to me for the computer I was using.

    My computer: (Gateway Tower - P4 2.53Ghz - Windows XP Home - 1GB RAM) The trouble began when I rebooted after getting a “Low Virtual Memory” Error from windows; I got the sign-in screen and then, once the desktop wallpaper showed up, the icons took forever to come up. The mouse/cursor would move around the screen but trying to grab anything in the tray (including Start) would give me an hourglass. It wouldn’t let me select any icons on the desktop either (or if it did, once or twice, the resultant window would freeze). The task manager showed 40+ processes running and the CPU was pegged at 100%. I tried shutting down what appeared to be causing the CPU load but I got “Access Denied”.

    I couldn’t get (Earthlink’s Total Access – my provider) Internet software to work in Safe Mode so I went to a friend’s house and printed your “Read This First Guide” and downloaded the tools that it said I needed. I went home and got started. I couldn’t get Counterspy to run – I did get AVG Anti-spy and the log is attached. I tried numerous times to get anything to run in normal mode but to no avail. I figured that since Hijack This and your two programs Getrunkey and Shownew are small and probably execute quickly, even though I couldn’t do a scan from Bitdefender or Panda, maybe if I showed you what I had, you could suggest a way to get me some functionality back under Normal mode. I started shutting down all the processes running under task manager and I shut down some part of Norton and it gave me an error (something about ‘illegal call’ and then a warning about a 60 second shutdown which somehow either directly or indirectly interrupted the processor hijack). I ran Hijack This and got a logfile. On the next reboot, I clicked on ‘owner’ login and then got the Task Mgr. up and waited for the ‘crap’ to start loading. When a svchost.exe file looked like it wanted 90%+ of the processor I canned it and lo and behold I “got some of my computer back.” I was able to log onto the Internet and ran the Bitdefender Scan that found 2 Trojans and a Haxdoor and removed them – don’t know if they were the problem. I tried to scan from Panda but for whatever reason, the website is not giving scans – tried several times. I went back and did a new Getrunkey and Shownew log and a new Hijack This log as well.

    I’m scared as hell to shut anything down because I hate that feeling of fighting the beast to get it back up and running. Could you take a look and see if there is anything else glaring that could be waiting to bite or worse, reinfect?
     

    Attached Files:

  4. ct1069

    ct1069 Private E-2

    The other files I have. (I couldn't get Panda)

    Thanks for your help.
     

    Attached Files:

  5. ct1069

    ct1069 Private E-2

    P.S. One more thing -- My Norton 2006 IS expired last week. I am thinking of changing to PC-Cillin from Trend. Do you have any suggestions or opinions or advise?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I definitely don't recommend Norton and if Trend Micro is going to be an Internet Security Suite, I don't recommend it either. All internet security suites are massive resource hogs and they are not worth the money since you can great protection from free tools that are not so resource hungry.

    First uninstall the below old Sun Java version which is a security risk:
    J2SE Runtime Environment 5.0 Update 8



    Download haxfix.exe and save it to your desktop.
    • Double click on haxfix.exe to install haxfix. (standard installation path is c:\program Files\haxfix)
    • Checkmark "Create a desktop icon"
    • Click "Next"
    • When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed
    • Click "Finish"
    A red "dos window" (dos box) will open with options:
    1. Make logfile
    2. Run auto fix
    3. Run manual fix
    E. Exit Haxfix
    • Select option 2. Run auto fix by typing 2 and then pressing Enter
    • If an infection is found, you'll get a message to close all other open windows.
    • Close all open windows except the red dos window from haxfix and then press Enter
    • The computer will reboot
    • After reboot a logfile will open > (c:\haxfix.txt)
    Now Download this file - combofix.exe
    1. Double click combofix.exe & follow the prompts.
    2. When finished, it will produce a log ( C:\combofix.txt ) for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now install the current version of Sun Java from: Sun Java Runtime Environment


    Now attach the below new logs and tell me how the above steps went.

    1. c:\haxfix.txt
    2. C:\combofix.txt
    3. GetRunKey
    4. ShowNew
    5. HJT
    Make sure you tell me how things are working now!
     
  7. ct1069

    ct1069 Private E-2

    Computer works but that svchost.exe still starts up and sets the process to working on whatever.
     

    Attached Files:

  8. ct1069

    ct1069 Private E-2

    Thank you.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    svchost.exe is a required system process and you will always see several of them running. Certain ones will use much more memory than others. Killing certain ones will cause your PC to crash. They are not your problem.




    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. Avenger
    2. GetRunKey


    Make sure you tell me how things are working now!

    If you still have problems, I suggest you uninstall all Norton/Symantec software. Then run the below since Norton rarely uninstalls properly.

    Norton Removal Tool (SymNRT)


    You can replace Norton with free tools given in the below:

    How to Protect yourself from malware!
     
  10. ct1069

    ct1069 Private E-2

    Still have the "runaway process". I rebooted after running Avenger before running 'Getrunkeys' but it seems that the process: Svchost.exe takes all available unused processor access -- I know you said it isn't the problem but rather a symptom. 'Getrunkeys' window came up but it couldn't complete the scan for keys with that process running. I had to shut down the runaway Svchost.exe. I tried changing the priority to Low but it denied me access so I shut it down which it let me do. Next, I will, as you suggested, get rid of my expired Norton IS 2006 (hungry crap -- it wouldn't run on my laptop -- 500 Meg was not enough memory I guess - ha -- and try some of your suggestions hoping that it may be the cause of the problem. That wouldn't surprise me in the least.
     

    Attached Files:

  11. ct1069

    ct1069 Private E-2

    Oooops. Sorry, I forgot to run CC. I will first.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs are clean! Continue on with the removal of Norton.

    Also uninstall Windows Defender as a test too!

    Make sure you reinstall and antivirus (like AVG) and a firewall from the list in the How to protect link I gave you.

    Attach new logs from ShowNew and HJT after doing all of this and also tell us if you are still having problems.
     
  13. ct1069

    ct1069 Private E-2

    I downloaded AVG Free and A-squared to my desktop. I already had Zone Alarm for a firewall. I checked for Windows updates and installed the few that were there. Then, I uninstalled Norton IS 2006 by their method (windows program uninstall from control panel); then I ran the Norton Uninstaller 'helper'; then I rebooted. Rogue process still there -- I shut it down. Then I uninstalled Windows Defender; then I rebooted. Rogue Process still there -- I shut it down. Then I installed AVG Free and checked for updates. Then I installed A Squared and checked for updates. Then I rebooted. Rogue process still there -- I shut it down. Then I ran A squared scan -- wow! still found a bunch of stuff all of which I quantantined. I saved a file that I am attaching. Then, I rebooted. Rogue process still there -- I shut it down. I shot two digital photos (instead of screen shots cause I didn't want to disturb anthing) that I will attach -- the rogue process is always in the same approximate location in the list of processes which would appear to be about 6th or so from the bottom which I would assume to be 6th loaded. Any suggestions?
     

    Attached Files:

  14. ct1069

    ct1069 Private E-2

    Here es a photo of the task manager with the svchost.exe (rogue process) at full tilt. The other shot shows the history bar for cpu usage -- unlike the past where it went to 100%, there are several spikes before it goes into orbit.
     

    Attached Files:

  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    The process in your image "svchost.exe" is a valid system process. That it completely normal.

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If you used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If you used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If you used SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If you used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If you used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If you had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If you had you run Avenger, you can delete all files related to Avenger now.
    8. If you had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  16. ct1069

    ct1069 Private E-2

    Thanks You For All Your Help! You Guys Are Terrific! :cool

    I still have to shut down the one svchost.exe each time I boot my computer or I have absolutely no functionality so even though it may be a 'normal process' it is not acting normally.
     
  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Based on the picture you attached, it appears your OS hasn't finished loading fully.

    Is that during the initial boot or is that after it's been running a while?
     
  18. ct1069

    ct1069 Private E-2

    The photo I sent was taken a couple of minutes after rebooting. Today, as an experiment, I booted up, brought task manager up and left everything else alone. When I got back. everything was as I left it. The 'rogue' svchost.exe was running at 100%. This was about seven hours later. I shut it down and I was back in business.
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    I've never seen one stay at 100%, usually it goes back and forth.

    Let's try this one scan just to confirm it's nothing malicious.

    Running Kaspersky Online Scanner
     
  20. ct1069

    ct1069 Private E-2

    I set up Kapersky to scan last night. Attached is the log as requested. Also, I had forgotten that AVG also scheduled to scan last night and removed two files: patches containing Trojan-PSW Online Games-FIY. that were attached in a patch to extend a trial version of Proshow Producer (no opportunity produce a file to show you). Thanks for your continued support.
     
  21. ct1069

    ct1069 Private E-2

    Kapersky scan.
     

    Attached Files:

  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Locate and delete the folder C:\avenger.

    Everything looks good, I don't think this is malware related.

    I would post this in the Software Forum.
     
  23. ct1069

    ct1069 Private E-2

    I very much appreciate your help.
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds