GPU running at 99% on desktop

Discussion in 'Malware Help (A Specialist Will Reply)' started by janner66, Sep 5, 2013.

  1. janner66

    janner66 Private E-2

    Hi
    In the last couple of days I have noticed a lag on my PC i.e. when I type the letters do not automatically appear, browser and internet speed has been slower and now the fans on my PC are going mad. I checked the GPU and it is running at 99% on the desktop. I ran antivirus and malware programmes initially but am still having problems. I have included the antimalwarebytes log that was produced yesterday as there were items I had to remove. I followed your instructions and uninstalled and re-installed malwarebytes for the purposes of this.

    View attachment TDSSKiller.2.9.2.0_05.09.2013_11.48.25_log.txt
    View attachment HitmanPro_20130905_1156.log
    View attachment MGlogs.zip
    View attachment RKreport[0]_S_09052013_113917.txt
    View attachment mbam-log-2013-09-04 (23-36-24).txt

    Thanks.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it delete Potential Unwanted Programs.


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    • Re run Hitman again and attach log.
    • Explain how things are running.
     
  3. janner66

    janner66 Private E-2

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So now, when you re run Hitman, it no longer finds any PUP's, correct?
     
  5. janner66

    janner66 Private E-2

    No it still finds PUPs.

    Adobe Acrobat Update Service.exe is the only red threat
    all the rest are grey threats
    There is 19 Identified threats and 85 traces.


    Anything to worry about?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run it again. Have it fix the red entry you described, and have it fix anything under the heading Potential Unwanted Program.

    Now rescan again (only a scan) and attach the log for me to see what remains.
     
  7. janner66

    janner66 Private E-2

    Thanks.
    The programme won't let me delete anything as it says my free trial has ended.
    :confused
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, no problem, we'll tackle it another way.


    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [-HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKLM\SOFTWARE\Classes\Prod.cap]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}]
    [-HKLM\SOFTWARE\Classes\Wow6432Node\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}]
    [-HKLM\SOFTWARE\Wow6432Node\Babylon]
    [-HKLM\SOFTWARE\Wow6432Node\DataMngr]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\BabylonToolbar]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Softonic]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000_Classes\Wow6432Node\CLSID\{80922ee0-8a76-46ae-95d5-bd3c3fe0708d}]
    
    :files
    C:\Program Files\Java\Adobe Acrobat Update Service.exe
    C:\Program Files (x86)\Mozilla Firefox\searchplugins\babylon.xml 
    C:\ProgramData\Babylon
    C:\Users\Steve\AppData\Local\Conduit
    C:\Users\Steve\AppData\LocalLow\Conduit
    C:\Users\Steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserProtect
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Now rescan again with Hitman and attach the log please.
     
  9. janner66

    janner66 Private E-2

    The GPU is at 99% again. Are there any other programmes that don't require licences available to delete the PUPs please?
     
  10. janner66

    janner66 Private E-2

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please don't "bump" ;) This will usually result in a delay in me getting back to you.




    Code:
    :reg
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    Did they delete properly? Rescan with Hitman and attach latest log.
     
  12. janner66

    janner66 Private E-2

    I am sorry for the late reply. I have been working shifts all weekend!
    Here are the logs you requested. any Thanks.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those entries still there when you rescan with Hitman?
     
  14. janner66

    janner66 Private E-2

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm only concerned about the PUP's...


    Please download Combofix to your desktop. Please refer to these instructions prior to running.

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Registry::
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1000\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1003\Software\Conduit]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{4D2D3B0F-69BE-477A-90F5-FDDB05357975}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1003\Software\Microsoft\Internet Explorer\Approved Extensions\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKU\S-1-5-21-2349365768-4113002210-3286571531-1003\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    Now rescan with Hitman and attach the log.
     
  16. janner66

    janner66 Private E-2

    Thanks. I just want to check before I go ahead. I have Windows 8 64bit. I see in the instructions that you should only run Combofix on Windows 7 or below. Shall I still go ahead? Thanks.:confused
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes go ahead. Latest download says compatible.
     
  18. janner66

    janner66 Private E-2

  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking advice about these stubborn enntries, in the mean time...

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  20. janner66

    janner66 Private E-2

    Attached Files:

  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  22. janner66

    janner66 Private E-2

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I had a word with Chaslang who has put us on the right path :)

    Please boot up into this restricted user account:

    • Mcx1-STEVE-PC

    Run Hitman as admin and have it fix those PUP's.
    Now rescan with Hitman and let me know whether they reappear or not.
     
  24. janner66

    janner66 Private E-2

    Sorry. How do I boot up in to that restricted user account? It is probably obvious but Could you give me instructions please. Sorry to be such a noob. :-o

    I don't think Hitman will be able to fix the PUPs as the trial license has ended.
     
    Last edited: Sep 11, 2013
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    When you first boot up the computer does it not give you two user accounts to choose from to log into? :confused
     
  26. janner66

    janner66 Private E-2

    No it automatically logs me in. I seem to remember bypassing the login screen as it was annoying so now it signs me in automatically on bootup without putting in a password. Will I need to find a way to either turn this off or boot into the right user ID? Thanks.
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, log in as you normally would. Then go into user accounts > manage another account, and see if this other account shows. Mcx1-STEVE-PC

    If so, try giving this user admin priviledges. Let me know how you get on.
     
  28. janner66

    janner66 Private E-2

    I have gone in to user accounts-manage an account and all that is there is myself as admin and guest turned off. :confused
     
  29. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am seeking advice again.

    I want you to try this in the mean time:

    Windows 8: Enable the hidden Administrator Account

    See if you can get the hidden admin account enabled and then once done, boot into the admin account, and then try and manage other accounts. Let us know what occurs.
     
  30. janner66

    janner66 Private E-2

    It has created a separate administrator log in. I now have 3 accounts. The first one is My name,my email, administrator,password protected. The second account is Guest (turned off) and the newly created one is administrator local account administrator.

    I have discovered that the mcx1-STEVE-PC is the media centre extender
    uuid:10000000-0000-0000-0200-001DD882C7F7
    I can delete this in lusrmgr (local users and groups) if required.
    I got there by using windows key + R and typing netplwiz and the advanced tab.
     
  31. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And there's no way to get into this account at all?
     
  32. janner66

    janner66 Private E-2

    I think it is the link that you use between the PC and the Xbox 360. It allows you to use the media centre on your xbox. You can't sign into the PC using this account.
    I can change the password, rename it or delete it.
     
  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you delete this user account and then recreate if needed?
    • mcx1-STEVE-PC
     
  34. janner66

    janner66 Private E-2

    I think so, yes. Shall I go ahead and delete the profile and then run Hitman?
     
  35. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please. :)
     
  36. janner66

    janner66 Private E-2

    Attached Files:

  37. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi :) Sorry about the delay. There has been some discussion in the background and because this is all Hitman is finding, we don't consider it to be an issue.

    Is everything else running nicely and as it should be?
     
  38. janner66

    janner66 Private E-2

    Attached Files:

  39. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes please, do go ahead and let it fix them.
     
  40. janner66

    janner66 Private E-2

    Attached Files:

  41. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I don't understand. It says no threats found, but when you view the log these PUP's are still listed?
    Did you activate your product key alright and you are sure you are now using the full paid for version? (Not being patronising, just checking for sure) :)
     
  42. janner66

    janner66 Private E-2

    When you run the programme and it finishes scanning it reports no threats found but there are items listed in the box. They are all grey and are set to ignore. These are the ones listed in the log. This is just the way the programme works.

    I just ran it again and it is totally clear now so I am happy to leave it there now. Thanks very much for your help. I am sorry it has dragged out so long.
    Do I need to uninstall the programmes I used now?

    :grouphug
     
  43. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    :grouphug So glad you got it resolved! My next step would have been to advise you to email surfright.

    Final steps are below:


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  44. janner66

    janner66 Private E-2

    Many Many thanks for your help. You always do a great job here. BIG TIME respect to you all. :cloud9
     
  45. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Surf safely! :) Take care.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds