E-Machines 100% CPU looks like malware

Discussion in 'Malware Help (A Specialist Will Reply)' started by jerrygl, Aug 27, 2012.

  1. jerrygl

    jerrygl Private E-2

    I have been having problems with this machine for some time now and have done extensive cleaning of old programs etc. It runs really slow and usually the culprit is MsMgEng.exe from MSE. However, almost anything I do on the computer seems to peg the cpu at 100% and slows it to a crawl. Tonight I ran yet another malware scan on the machine, this time doing it per your instructions and lo and behold there are some possible infections to be had. I am trying to clear this up and get the machine back to running normal. Attached are the required logs.
     

    Attached Files:

  2. jerrygl

    jerrygl Private E-2

    E-Machines 100% CPU looks like malware pt.2

    Sorry about the second post but I messed up with one of the scans and got tow log files which exceeded my 5 file limit. So here is the last log you require
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It does not appear that you are having malware problems. Your logs are all clean but some logs are missing from MGtools. Not sure why but seems msinfo32.exe did not run.

    How much memory is installed in this PC?
     
  4. jerrygl

    jerrygl Private E-2

    I have 1.5 gig of ram, I am completely baffled by this behaviour. Could it be possible there is some type of hardware conflict causing the slow down, like a ram mismatch or bad chip?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly!. But it could also be from tweaking what does not need to be tweaked. I see the below which I would remove
    Code:
    O4 - HKLM\..\Run: [SystemBoosterXP] C:\Program Files\DiskTrix\SystemBooster2\SystemBooster.exe
    O4 - HKLM\..\Run: [ProcessLassoManagementConsole] C:\Program Files\Process Lasso\processlasso.exe
    O4 - HKLM\..\Run: [ProcessGovernor] C:\Program Files\Process Lasso\processgovernor.exe
    O4 - Global Startup: eBoostr Control Panel.lnk = C:\Program Files\eBoostr\eBoostrCP.exe
    Have you also been using registry cleaners?
     
  6. jerrygl

    jerrygl Private E-2

    Thanks for the reply,
    Those programs were all put there one at a time and from good past experience to try and rectify the slowdown that occured. I did not notice that both process lasso and process governor were active together. I will disable all of these and see if there is any type of improvement.
    And unfortunately, I confess I have used several registry cleaners on the machine. This was done in the attempt to remove all the left over registry entries that preventred me from installing Microsoft Security Essentials. I had tried several other AV programs after the default one messed up that came with AOL version 9. That program is gone now and it too wouldn't uninstall properly. What a problem program that was.
    Do you think there is any hope?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would stop all of them including eboostr to see what effetc it has . In fact, uninstalling may be better as you may be using up more of your system memory and you really already have less than what I recommend for Windows XP.

    Frequently these can cause more harm then good. We don't recommend them unless an expect tells you to use one and then tells you exactly what to remove with it.

    Well there is nothing for us to do here as it is not a malware problem. As stated, I would uninstall those items point out as a test. Also is the below ArcSoft software still installed? Is seems you have a dead service?

    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - - (no file)

    If you don't have this anymore, the below should be able to remove it.


    Open a command prompt window by clicking Start, Run, and enter cmd and click OK. If the window opens type each of the below commands in. Follow each by the enter key. Note there are spaces after the sc and after the stop and after the delete.

    sc stop ACDaemon
    sc delete ACDaemon
     
  8. jerrygl

    jerrygl Private E-2

    OK, removed ArcSoft service. I believe it came bundled with a Kodak camera installation or something like that.
    I downloaded the program, autoruns and ran it thinking that I would be able to just stop the eboostr and other programs in question. WOW, what a mess in there. I noticed several entries highlighted "file not found" and most of them were in the windows\system32 folder... That is an important one I know. What stumps me is that I ran the system file checker several times on this machine, with NO problems found... So what is all that about and more importantly, how should I go about correcting the problems?
    I am afraid that I am seeing the results of the registry programs handiwork
    :(
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would have to be much more specific or attach a log from AutoRuns. Many times it is just due to various items having been uninstalled and these may not really be issues. But this is a topic you can post about in the Software Forum. We are too busy removing malware here to work on non-malware issues.

    Software Forum.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
     
  10. jerrygl

    jerrygl Private E-2

    Ok, Done, all the tools used were removed. I went through the recommendations you made and will be readusting my security software based on some of the results of the testing. Thank you for all your help and patience in this matter. I will be posting in the software forum next to help me with the autoruns situation, as I feel there is still a problem causing the large cpu usage.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds