Conhost And Presentationhost Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shuroku, Mar 30, 2016.

  1. Shuroku

    Shuroku Private E-2

    I've tried the antivirus I have, microsoft security essentials, and while it seemingly is catching trojans i dont think its catching the main culprit. Randomly usually at night for me (PST) my computer's cpu/memory gets used up by PresentationHost and Conhost and an additional assortment of programs I can't end process on or even open file location or check properties, attached is a JRT.
     

    Attached Files:

    • JRT.txt
      File size:
      5.1 KB
      Views:
      2
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. Shuroku

    Shuroku Private E-2

    Hi and thank you. Sorry I got to the Download CCleaner Slim step and it brings me to a dead link, nothing downloads.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Continue on then... skip that step. ;)
     
  5. Shuroku

    Shuroku Private E-2

    Logs are attached!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you deliberately set up to use a proxy?
     
  7. Shuroku

    Shuroku Private E-2

    Deliberately? I don't believe so, no. o_O
     
  8. Shuroku

    Shuroku Private E-2

    What proxy?
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't worry, we will be rid of it. Run this as well please and then I can deliver a complete fix to you.


    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  10. Shuroku

    Shuroku Private E-2

    Here they are!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] (X86) HKEY_LOCAL_MACHINE\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} -> Found
    • [PUP] (X64) HKEY_USERS\RK_Ohaimikey_ON_F_AE2A\Software\Microsoft\Windows\CurrentVersion\Run | Optimizer Pro : C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [x] -> Found
    • [PUP] (X86) HKEY_USERS\RK_Ohaimikey_ON_F_AE2A\Software\Microsoft\Windows\CurrentVersion\Run | Optimizer Pro : C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [x] -> Found
    • [PUM.Proxy] (X64) HKEY_USERS\RK_Ohaimikey_ON_F_AE2A\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 198.144.159.130:8080 -> Found
    • [PUM.Proxy] (X86) HKEY_USERS\RK_Ohaimikey_ON_F_AE2A\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : 198.144.159.130:8080 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now re run RogueKiller again (just a scan) and upload fresh log pelase.
    Explain how things are running.
     
  12. Shuroku

    Shuroku Private E-2

    I don't see this one or the X86 version
    • [PUP] (X64) HKEY_USERS\RK_Ohaimikey_ON_F_AE2A\Software\Microsoft\Windows\CurrentVersion\Run | Optimizer Pro : C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe [x] -> Found

    For me they all are ON_F_EC3E

    I added the new log.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you seeing the proxy entries?? And the other entries I listed?
     
  14. Shuroku

    Shuroku Private E-2

    I'm seeing the proxy entries and the other one listed, but the Optprolauncher files arent the same, but i'll remove them since its the same program named.

    No RKreport was created though but here is the JRT
     

    Attached Files:

    • JRT.txt
      File size:
      1.8 KB
      Views:
      1
    Last edited: Apr 1, 2016
  15. Shuroku

    Shuroku Private E-2

    Here is the fresh rogue killer log after I rebooted as well
     

    Attached Files:

    Kestrel13! likes this.
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, looks good. Explain how things are running.
     
    Shuroku likes this.
  17. Shuroku

    Shuroku Private E-2

    Things are running fine I believe. The issue I had wasn't constant though just randomly something would star hogging memory and like 5 programs would pop up in Task Manager so i'll know for sure if everything is fine tomorrow but I feel like we took care of it.

    Thanks for everything Kestrel, youre amazing!
     
    Kestrel13! likes this.
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are so welcome. Yes have a surf around, post back in a day or so and give me an update. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds