Help after Read & Run Me First

Discussion in 'Malware Help (A Specialist Will Reply)' started by chad-roscoe, Nov 3, 2013.

  1. chad-roscoe

    chad-roscoe Private E-2

    Hello folks~
    I went through the Read & Run process yesterday, and I think I still have something "hidden" running on my computer, though the process did seem to find some trojans.
    My computer gets hung up, and when I access the Task Manager, if I have only 1 Google Chrome window open, it will show 5 or 6 as open. If I have IE open, it will show each IE window using like 580,000 (but I don't know what the units are, but they show the letter K :-o). It also has about 8 svchosts running at any given time, and one of them is usually using about 150,000 units, and cannot be shut down. Now, also, the anti-malware from the Read & Run called Malwarebytes is always "running" and shows 50,000 to 150,000 Ks.
    What happens is that my computer fan starts getting really loud, and then everything slows down, or stops. I used to play a little music from YouTube while my daughter was falling asleep while checking FB or sending email, but the YouTube immediately stops, and the fan starts, and everything get hung up. The "Performance" tab will sometimes show my CPU @ 100%, even if I only have one Chrome window open, say for FB, or Amazon. :confused
    A lot of the processes that Task Manager shows as running will have *32 next to them.
    I have Windows 7 on a 64 bit Samsung laptop. Two stickers on the laptop say that it has NVIDIA Geforce with CUDA and intel COREi7.
    I am attaching those Read & Run logs that I can figure out how to attach.
    Please let me know if you need more info., or if I am missing anything.
    Thanks so much for your help.
    Chaddie~
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Normal. It is a tabbed browser and the more tabs you have, the more processes will show. Same for IE, Firefox...etc.

    Normal

    Normal. It runs a service to allow allow users of the PC to use it. You did not attach the log requested from Malwarebytes.

    Normal. Every process does not run in 64 bit mode.

    Run Hitman Pro again and this time allow it to fix the Malware, Malware Remnants, Potential Unwanted Programs, and the Repairs. The reboot your PC. After reboot, run a new scan with Hitman Pro and attach the new log.
     
  3. chad-roscoe

    chad-roscoe Private E-2

    Thank you Chaslang!
    On the Chrome tabs vs windows... the only objection I have to that is that I do not use tabs. I don't like them. I only use windows, so I see multiple Chromes running when I only have 1 page open (in one window, no tabs).
    The rest sounds great, and if there was no log it was because I cannot locate it on my PC, but I will take your directions and reply ASAP.
    Thank you so very much for your help!
    Chaddie
     
  4. chad-roscoe

    chad-roscoe Private E-2

    Chaslang, attached are the other logs.
    Thanks!
    Chadster
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    That's normal for Chrome. The number of Chrome.exe processes seen is not equal to the number of tabs. For example, I see 5 Chrome.exe processes with one tab open. And for 12 tabs open I see 17 Chrome.exe processes. Hence it seems Chrome always number of tabs + 5 processes running.

    You need to finish what I requested in my last message which stated the below
     
  6. chad-roscoe

    chad-roscoe Private E-2

    Hi Chaslang~
    I ran the Hitman Pro again, and allowed it to fix the trojans and etc.
    Then I rebooted, and ran it again.
    The second time the log had ZERO. Nothing to report. (I am also attaching here.)
    Right now I have one Chrome window open (no tabs) and
    7 IE windows open (no tabs), and 1 WORD doc open, and on my Task manager it shows 89 processes and 74% of my memory being used. The CPU usage is jumping around between 5 and 40. It just changed to 90 processes, though I have opened nothing else.
    Though there is one Chrome page open, and no tabs on that page, it shows 6 Chrome running.
    There are 2 of a lot of things running, like two Java update schedulers, and two Nvidia Driver Helper Services. Malwarebytes has three things running, one called scheduler, one called service, and one called mbamgui.
    Of course, I don't know my butt from my head on this stuff, but still, my computer fan seems to go into overdrive, and the computer will get hung up, and it is a relatively new thing (past few weeks), so I just think (in my "here be dragons" way) that too much is running. With some things, like the Malwarebytes, I can't turn them off. And then the browser windows seem to suck up a lot of juice. My IE is using about 1.5 million Ks right now, and my Chrome about 750,000K.
    I don't mind if you tell me I'm an idiot, and apologies for taking up your time if I am.
    Just want to check if this is normal, and if I should just leave it alone.
    Thanks so much for your help~
    Chad
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should post these kinds of questions in the SOftware Forum. These are not malware problems. They are normal behavior when you open browsers. I strongly suggest that if you only open one browser. Having both IE and Chrome open will have a significant impact on memory use. Using one browser with tabs is the most efficient way to go.

    The above being said, there was some other junk to cleanup other than what we had Hitman Pro fix. So let's work on that and see if it also helps with some of the other problems you see.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Program Files (x86)\OtShot
    C:\ProgramData\WinClon
    C:\Windows\TEMP\*.*
    C:\Users\David\AppData\Local\Temp\*.*
    
    :Reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "OtShot"=-
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "OtShot"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 6, 2013

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds