Combofix stall and 100% CPU

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bax1231, Jul 6, 2011.

  1. bax1231

    bax1231 Private E-2

    I've had a problem with my computer it will every so often hit 100% CPU every 1-5min for 30 seconds, I was advised by a friend to use Combofix for this problem which I've used before in the past on this same computer for another problem which it cleared up but now after Combofix starts scanned it would stall (even after a 12 hour scan) it would not budge

    Other things I tried:
    Malwarebytes (nothing found)
    Kapersky virus remover tool (found some stuff in my TEMP folder but still no effect)
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. bax1231

    bax1231 Private E-2

    Thank you for the reply, just woke up... will be running the programs and giving you logs asap
     
  4. bax1231

    bax1231 Private E-2

    Running a fresh Malwarebytes log now
     

    Attached Files:

    Last edited by a moderator: Jul 6, 2011
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  6. bax1231

    bax1231 Private E-2

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No worries. :) Attach the rest of the requested logs when ready. I'll review them as soon as I can but it is getting late here now.
     
  8. bax1231

    bax1231 Private E-2

    Alright!
    RootRepeal is not responding when trying to scan Files
    I was able to get a Drivers log
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now finally the C:\MGLogs.zip.
     
  10. bax1231

    bax1231 Private E-2

    You got it
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode

    Please prevent Bittorrent from running at startup whilst I am helping you to remove malware. Thanks. :)

    Uninstall the below.

    • Conduit Engine
    • Java(TM) 6 Update 21
    • Java(TM) SE Development Kit 6 Update 21


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}\NoExplorer]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{FBF5129C-1925-491B-8753-60150F99ED35}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{FBF5129C-1925-491B-8753-60150F99ED35}]
    
    :files
    C:\Windows\Tasks\IFPIJNWBF.job
    C:\Windows\Tasks\NRZQQMALWS.job
    C:\Users\Owner\AppData\Local\Temp\904D57F61A9D7FE5185C01B47D54C2FB
    C:\Users\Owner\AppData\Local\Temp\CE4CF87733651BF1F44DD1E02FC1A8E8
    C:\Windows\System32\ifsutilxr.dll
    C:\Windows\System32\CBSRAK.DLL.del
    C:\Windows\System32\tmp.reg
    C:\Windows\System32\tmp.txt
    C:\Windows\winstart.bat
    C:\Users\Owner\AppData\Roaming\GetValue.vbs
    C:\Users\Owner\AppData\Roaming\SetValue.bat
    C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates\Mh3jm32txN
    C:\ProgramDataViewpoint
    
    :Commands
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  12. bax1231

    bax1231 Private E-2

    Thanks for the help!!
    I figured out what caused my CPU problem it was because my laptop was overheating, though I still have this redirect issue with google and it seems to keep coming back, Its called catchme.sys and stores in my temp folders; I keep deleting it but it keeps coming back after a while or so.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you have your Vista install disc? If not:

    Vista and Win7 Recovery disc



    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe, and then press ENTER.

    Then you can do this:

    Bootrec.exe /fixmbr
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not malware!! It is part of GMER and is used with ComboFix. I think what you do have is called an MBR infection.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds