Computer Using 84% Ram With 1 Window Open

Discussion in 'Malware Help (A Specialist Will Reply)' started by msidea, Feb 18, 2019.

  1. msidea

    msidea Private First Class

    Hi,

    So high RAM usage is why I decided to check for malware. The computer seem so to be running better now, but I'm attaching the logs because they did find some things that I'm not sure if I should delete. Also, MGTools gave me an error message which I have not seen before and that I didn't find as one discussed in the instructions.

    Thanks ahead of time for your help!

    Lissy
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use Hitman to remove these items:
    Potential Unwanted Programs _________________________________________________

    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine.1.0\ (BoxoreOU)
    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine\ (BoxoreOU)

    Reboot, rescan with Hitman, attach the log and tell me how things are running. ( This is the most common reasons for issues over the last few months.)
     
  3. msidea

    msidea Private First Class

    Hi Tim,

    I did what you said. So am I in the clear? Now, do I go back and reactivate UAC and whatever else the instructions say?

    My teen son who is very interested in cyber security looked up BoxoreOU. He's thinking that it's a legit virus that has been described online as a PUP because of the "OneClickProcess" in the name that is associated with AVG. Do you have a link or other information that you can send me to scratch his geek curiosity on this topic?
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     
  6. msidea

    msidea Private First Class

    Thank you so much Tim! Enjoy the rest of your day!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.
     
  8. msidea

    msidea Private First Class

    Hi Tim,

    The craziest thing just happened. For about 30 minutes, my keyboard stopped working. I thought it was the keyboard itself. I got a bluetooth keyboard that I know works. I was having the same issues. Certain letters, backspace and enter would not work on either the installed or the bluetooth keyboard. So, ok. That's weird. It must be a driver/system issue. I tried using the onscreen keyboard. The same exact issues.

    Then I figured that I would use the speech input, ease of access function. As I was trying to figure out how to give access to Cortana and the mic and all that, the keyboard started working again. Since just yesterday, I had some virus/malware issues, I figured that I'd reach out and ask you if these seems to you like it could be something malware related or whether I should be looking elsewhere for answers.

    I work on my computer. It's how I make a living so this is a huge deal for me. I'm trying to avoid buying a new computer as this one works fine for my purposes, except for the issues that I've had lately.

    By the way, it's working fine from a speed standpoint. It's just as slow as was before the RAM issue that you helped me fix.

    Any insight would be appreciated.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Humm......please do this:
    Please go here > https://www.zemana.com/Download
    their program is no longer free, but you can use the demo version for this cleaning.

    It auto updates, and you click scan. After it's finished, click on the icon that looks like Cell phone strength bars. High-light the report (by date log was produced) and click on the "Open Report" icon. (looks like a folder). That notepad.txt can then be copied/pasted into another .txt doc and saved. Upload that, please.
     
  10. msidea

    msidea Private First Class

    Hi Tim,

    I downloaded it, and I received these error messages which I am attaching in a screenshot. Before I disable my antivirus, which I think that I use Defender, I wanted to check with you. Also, I reconnected, or however you say it, the UAC and followed those steps.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Obviously it does run on windows. This is the first I have seen this. OK....a different route:
    Please download the latest version of FRST the below link.
    Farbar Recovery Scan Tool and save it to your Desktop.


    Note: Make sure you download the proper version ( 32 bit or 64 bit ) for your PC. Only one will run, the correct one. So it you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  12. msidea

    msidea Private First Class

    So I clicked out of the last red screen, and then this one popped up. I didn't click "yes". It's still up. Also, note what's on the notification bar. I don't know if this could have anything to do with it. It started showing up after I turned off UAC, but last I checked yesterday, UAC was back on.

    I needed to scan a document before I ran the new scan that you suggested. When I opened up the utilities, the computer asked for my Admin password. As a safety measure, my main account does not have Admin privileges. I entered it, though I found it odd. Then, it wanted me to restart my computer before it would allow me to scan. I did not as I know that some malware will deceive a user into restarting precisely so that it can install.

    Also, my son showed me that Windows Defender is recommending a "Fresh Restart". It says that it will keep my personal files and some apps, but that it will basically reinstall Windows.

    Would you like me to follow your previous instructions for Farbar tool still, do the Fresh Start, or do something else?
     

    Attached Files:

    Last edited: Feb 20, 2019
  13. msidea

    msidea Private First Class

    My son looked at the Task Manager and noticed that nothing said "Zemana" or anything similar, even though the window is open. Also, he said that the error message seems to attach to any window that is opened meaning that it opens up but doesn't appear on the task bar. He says that it looks "sketch". lol

    Anyway, I hope that helps.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run Farbar.
     
  15. msidea

    msidea Private First Class

    Here they are.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please rerun this under the administrator account...children.
     
  17. msidea

    msidea Private First Class

    Ok and logs attached.

    It didn't seem to be downloading, so my son downloaded it on a flash drive. We transferred it to my desktop. He deleted the volume on his flash drive btw for good measure.

    In any case, the red pop up window telling me that Zemana couldn't be installed on Windows popped up. The crazy thing is that I didn't try to install Zemana. I'm quite sure that I didn't touch the icon, so unless it was advising all the user accounts, I don't know what it was doing.

    I'm really grateful for your help. I keep looking at your avatar, which makes it seem that you live in dire circumstances (just my imagination). I certainly hope that real life is happier for you.
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in the logs. However, I would suggest that you first download any documents that you want to save. Then do a restore to 28-01-2019 14:24:52 Scheduled Checkpoint....it will take a while. Let me know how the computer is running after that. If you are still having issues, you may have to reinstall Windows.
     
  19. msidea

    msidea Private First Class

    Ok so no Zemana? What about the Fresh Restart that Defender recommended? And if I do either of these, do I do them from the admin account or my regular limited account?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Admin. account.
     
  21. msidea

    msidea Private First Class

    Ok. So I ran Zemana. It only find the updater for Kingsoft/WPS, which it deleted. Then the system did an update which took about an hour to do. When it finally finished, Microsoft Edge opened (not my default) and it said that it was the October update. I thought that I was up to date, but ok.

    Anyway, everything is working fine for now. Would you like me to let you know in say, 2 weeks, if it's still ok?

    Also, looking through Windows Defender logs, I didn't see that it had ever found anything. Is this because it's so good at keeping things out or because it's an ineffective tool? If so, is there one that is better for Windows 10? My research had shown that Defender was the best av for Windows 10, but you do this every day so I trust your opinion.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sounds good. Defender is fine. I will give you final instructions and if you wish, you can come back later to update.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    3. If running Vista, Win 7 or Win 8, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    4. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    5. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    6. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds