Something evil is hogging up all my RAM

Discussion in 'Malware Help (A Specialist Will Reply)' started by andrewr47, Oct 22, 2015.

  1. andrewr47

    andrewr47 Private E-2

    My laptop has been extremely slow the past week
    I initially did a full scan on MS Windows Essentials couple days ago: found a trojan called win32/ramdo.a in the appdata temporary folder, which I subsequently removed.

    I thought the problem went away but it still persisted. Ididn't rescan with MSE, but did the tutorial proposed on this site.

    I attached all the necessary logs, but the RKreport is in .json format. the Program didn't let me export to a .txt file (I had to be a premium member?), but it looks like the file still has readable text on it after I tried to open it. I couldn't upload it with a .json extension so I manually changed it to a .txt

    Thank you
    p.s. i dont know if it's of value, but my task manager shows svchost.exe is taking up almost all the RAM (nothing else is running other than a blank chrome page).
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, andrewr47
    Changing the file extention from .json to TXT format does not make the report readable. *After the scan has completed, you must first select the Report radio button shown beneath the Delete button on the right-hand side, then on the next GUI select the Export TXT button at the bottom far-right corner.

    Please attach this report so I can begin evaluating your logs.
     
  3. andrewr47

    andrewr47 Private E-2

    Sorry, Must have missed it somehow. Here's the log. thanks!
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Re-run HitmanPro and activate the 30-day trial. Then have it fix everything listed under:
    Potential Unwanted Programs

    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.
    After reboot and when you are back in Windows, run another scan with HitmanPro and then attach the latest HitmanPro log

    Please re-run RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.
    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in the original instructions and attach the new log.

    Using "Programs & Features" uninstall: (If you do not find it or it will not uninstall, just keep going.)
    Java 7 Update 7 <== outdated

    Now please download Junkware Removal Tool to your desktop.
    • Make sure to shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Next download AdwCleaner by Xplode and save to your Desktop.
    • Close all open windows and browsers.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
    • Now click on the Logfile button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • Look over the log especially under Files/Folders for any program you want to save.
    • If there's a program you may want to save, just uncheck it from AdwCleaner.
    • If you're not sure, post the log for review. (all items found are either adware/spyware/foistware)
    • If you're ready to clean it all up.....click the Cleaning button.
    • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically.
    • Attach that logfile to your next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which are created when running the tool.

    Now install the current 64 bit version of Oracle Java
    Java Runtime Environment 64-Bit 8 Update 66

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select "Run As Administrator").

    Then attach the below logs:
    • updated Hitman Pro log.txt
    • updated RKreport.txt
    • the JRT.TXT log
    • AdwCleaner[C#].txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. andrewr47

    andrewr47 Private E-2

    dr. moriarty, the logs are attached.

    The HitmanPro evaluation listed the Askbars and Conduit stuff at the end, but they weren't designated as threats (but it also doesn't say they were PUPs), so I assume they were PUPs and deleted them.

    RogueKiller went fine.

    I wasn't able to delete Java 7 manually. When I installed the latest JAVA version, it prompted me to delete old versions of JAVA. it was able to delete a JAVA VERSION 6. It also said it deleted JAVA 7 UPDATE 7 but when I look back in the "programs & features" (after all the steps in your post were finished) it is still there.

    JRT, AdwCleaner, and MGLogs seemed to ran fine.

    At the end, I still have issues. The windows gadget shows that my RAM is still occupied at 50-60% even though no other programs are running, and the CPU is still spinning.

    One of the reasons I also found out I have a problem on the laptop is that I wasn't able to run a testing software (a program to take tests in class). This program is still not running at this point (it is called SofTest v11).

    Thanks for your time!
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Use this portable uninstaller to remove Java 7 Update 7 and Google Update Helper.
    GeekUninstaller

    Yet this service belonging to it IS running =>
    O23 - Service: ExamsoftShieldService (SoftshieldService) - Hewlett-Packard - C:\Program Files (x86)\Examsoft\Softest 11.0\Examsoft.ShieldRunner.exe

    *As a test, use GeekUninstaller to temporarily remove SofTest v11 also, to see if that's part of the problem.

    Please download Farbar Recovery Scan Tool (FRST) and save it to your Desktop.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run from.
    • The first time the tool is run, it also makes another log (Addition.txt).
    • Attach both logfiles to your next reply. (See: How to attach)

    Please tell me if you notice any further change in performance.
     
  7. andrewr47

    andrewr47 Private E-2

    Using GeekUninstaller, I was still unable to uninstall Java 7. The prompts that came up were similar when using the Windows uninstaller. I've attached some screenshots as to the events surrounding the uninstall (taken on my ipad), but I tried several times and it looked like it was removing it but it remains. I've refreshed GeekUninstall several times too and it's still there. I rechecekd the "uninstall" in "control panel" and it's still there too.

    Should I "Force Remove" it?

    I cannot find Google Update Helper on GeekUninstaller nor Control panel.

    I was able to successfull remove Examsoft. It did have 3 processes running even though I just rebooted the laptop, but it seemed to uninstall ok. But performance issue remains (svchost.exe has x2 processes taking up over 1 GB of RAM and no other apps are running).

    As for the Farbar Tool, the link you provided didn't work, but I was able to google it and downloaded from the same site (so hopefully it's the same one).

    Thanks!
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    • Save the attached (fixlist.txt) to your desktop.
    • Right click FRST and run it as admin.
    • Click the FIX button.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply.

    Describe how your machine is running now, please.
     

    Attached Files:

  9. andrewr47

    andrewr47 Private E-2

    I was able to force remove Java 7 (seemed to go fine).

    I attached the log to FRST

    After the reboot, everything was quiet, task manager didn't show anything weird. I waited about 2-3 min, then the culprit SVCHOST started acting up again and starts to take up 80-90% of RAM. I attached the screenshot of the taskmgr if it helps.

    I also realize that this process runs regardless if internet is on or off.

    Something else I noticed (not sure if its relevant) is that during teh time when SVCHOST cranks up, windows pops up the reminder to install security updates (that small blue icon at the bottom right that says "new updates are available."). Not sure if this is just coincidence, but this reminded me that initially when the laptop started acting up (prior to me noticing the trojan as noted in my initial post), i tried to install these updates and it wouldn't start (the c:/windows/softwaredistribution folder is updating, but nothing gets done as far as the installation % goes; this happens even if i only select 1 small file to install).

    Thanks for your help!
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    You may have remembered a good lead...;)

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. *It is better not to run anything else while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.
     
  11. andrewr47

    andrewr47 Private E-2

    I did the windows repair overnight as I slept. laptop already in sleep mode when I woke up. I think everything went fine, no error messages or anything like that. i rebooted it manually for good measures.

    But the SVChost RAM problem is still there :cry

    I notice that it still comes up right around the time when the "New Updates" icon pops up, but also when the "Solve PC issues" pop up (probably simultaneously). The two PC issues on "Solve PC" are
    1. "Windows Update is set to check with you before downloading and installing updates
    2. Set up back up

    I tried to turn off internet to prevent windows from checking an update, but it still popped up (i guess it doesn't use internet to know it's out of date) :/

    Since we did the Repair on Windows Update, I tried to see if I can d/l an update. I tried to d/l a single 60 kb file, and it wouldn't install.

    I also remembered that a week ago when I tried to manually update my virus definition on MS Security Essentials it would stall too. And I tried again this morning and it continued to stall.

    What else should I do?

    Thanks!
     
    Last edited: Oct 24, 2015
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Sounds like you're having issues with Windows itself, but let's rule out malware with this online scan.

    Using ESET's Online Scanner

    Attach the ESETScan.txt log, please.
     
  13. andrewr47

    andrewr47 Private E-2

    ESET scan done.

    looked like the only process it found was from MGTools, which is odd.

    The other thing is that the crazy SVCHost process disappeared during the middle of the scan. Since I had to disable antivirus during scan, I turned it back on once the scan was finished, and the SVCHost reappeared

    This is all really weird

    should i uninstall MSE?
     

    Attached Files:

  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Since we have confirmed that it isn't malware related, uninstalling MS Security Essentials (either for a re-install or using a different anti-virus) seems the next course of action. However, that means the issue belongs in our Software forum. The following link should help with the un-install:

    Windows 7: Microsoft Security Essentials - Uninstall Completely

    *Please follow these steps to cleanup from our malware cleaning procedure -

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase it, it provide no protection. It do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, Win 7/8 - it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7/8, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work through the below link:
    Best Wishes! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  15. andrewr47

    andrewr47 Private E-2

    Thank you sir! It still is acting up, but I'll take it up to the Software forum
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds