High Use Of Cpu On Startup Because Of Rundll32.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mallorn, Jun 28, 2018.

  1. mallorn

    mallorn Private E-2

    During the past two days, I have noticed that my computer is very slow on startup because of 4 Windows Service Host Processes (can't remember exact name) rundll32.exe, which use a high % of the CPU according to Task Manager. I am able to end these processes and continue as usual but would like to check if this is related to any malware. Logs attached below and thanks for your help! All threats detected by Malwarebytes were deleted.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please have ADWCleaner remove these items:
    ***** [ Folders ] *****
    Adware.pokki C:\ProgramData\Host App Service
    Adware.pokki C:\Users\Administrator\AppData\Local\Host App Service
    Adware.pokki C:\Users\TheresaMarie\AppData\Local\Host App Service
    PUP.Optional.MarketScore C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge

    ***** [ Files ] *****

    PUP.Optional.Legacy C:\Windows\System32\Tasks_Migrated\App Explorer
    PUP.Optional.RelevantKnowledge C:\Windows\System32\rlls64.dll
    Trojan.Agent C:\Windows\SysWOW64\rlls.dll

    Next have RogueKiller remove these:
    ¤¤¤ Registry : 26 ¤¤¤
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-19\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-19\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-20\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-20\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-1002\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-1002\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-500\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-500\Software\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-500\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2781703666-3337875241-3258989298-500\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service -> Found

    ¤¤¤ Files : 19 ¤¤¤
    [PUP.SweetLabs|PUP.Gen1][Folder] C:\ProgramData\Host App Service -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.0_43916\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.0_44090\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.0_44294\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.3_44358\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.3_44396\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.3_44428\utorrentie.exe -> Found
    [PUP.uTorrentAds][File] C:\Users\TheresaMarie\AppData\Roaming\uTorrent\updates\3.5.3_44494\utorrentie.exe -> Found
    [PUP.SweetLabs|PUP.Gen1][Folder] C:\Users\TheresaMarie\AppData\Local\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1][Folder] C:\ProgramData\Host App Service -> Found
    [PUP.SweetLabs|PUP.Gen1][File] C:\Users\TheresaMarie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo App Explorer.lnk [LNK@] C:\Users\THERES~1\AppData\Local\HOSTAP~1\Engine\HOSTAP~1.EXE /OPEN"defd46ddcae7ce35ae9673132f9cf2200f2f1563" -> Found

    Reboot and rescan with both ADW and RogueKiller and attach the new logs.
     
  3. mallorn

    mallorn Private E-2

    Logs attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    So sorry for the delay....how are things running now?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds