Unknown malware remains - gpu spikes

Discussion in 'Malware Help (A Specialist Will Reply)' started by phoenix333, Sep 28, 2014.

  1. phoenix333

    phoenix333 Private E-2

    Yesterday, I started getting unusual slowdown activity. MY GPU would be running at 100% especially when any browser would be open. I use exclusively chcrome for browsing. I knew I had some sort o malware/virus. A few days earlier I downloaded a file, and it was a masked exe file with .zip extension. I clicked on it, and shut it down, but it was too late, the payload already launched in the background. for a few days, there was nothing, but yesterday the problems started. Laptop runs extremely slow with any multi-threaded activity, especially when using chrome.

    I attempted to remove it mysel, by running multiple scans of malwarebytes, kaspersky, spybot, superantimalware, rkill, roguekiller, tddskiller, combofix, etc. After a second desperate attempt with Combofix, my internet systemfiles got messed up. I coudn't restore my internet connection with any help file that I could find, and I tried everything. eventually I just repair upgraded to windows 7 ultimate and that fixed internet connectivity issues, but did not solve the GPU spike issues. I've been running scans all day today and unfortunately for you guys deleted, quarantened a bunch of stuff before opening this thread. I will still post all logs requested, in hopes of getting some help.

    Hopefully this bad boy can be found. thank you in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There aren't any realy signs of active malware. Just a few left overs from some junkware. Some of this junkware you appear to have removed with ComboFix ( it show in the logs from MGtools ). But remaining issues may be more of a topic for the Software Forum since they do not appear to be malware issues. However, let's do a little more junk cleanup and run a repair tool and see what happens.

    First I suggest that you uninstall Spybot before continuing because Teatimer from Spybot can get in the way of fixes. Also Teatimer has been know to cause performance issues. So let's start by uninstalling Spybot. Make sure that you do this first!!!!

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
     
    :Files
    C:\Users\Sam D\AppData\Roaming\Uniblue
    C:\ProgramData\ec2b7aa70d461af1
    C:\ProgramData\GoSaeve
    C:\Program Files\GoSaeve
    C:\Windows\Temp\*.*
    C:\Users\Sam D\AppData\Local\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E33CF602-D945-461A-83F0-819F76A199F8}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. phoenix333

    phoenix333 Private E-2

    did everything as asked.

    GPU still hiking when using chrome.
     

    Attached Files:

  4. phoenix333

    phoenix333 Private E-2

    After testing a little bit, there is a little bit of improvement.

    the browsers seem to be working a bit faster, I think this might have to do with resetting permissions, etc. I've opened up 2 different browsers to test out the GPU handling, and the spikes are still there, but the good is that they don't stay at maximum, there is more variation....going from low to mid to high. Still abnormal, but definitely an improvement.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. phoenix333

    phoenix333 Private E-2

    Hi,

    Thank you again for your help. This resetting the Chrome to default seemed to help temporarily. I'm browsing for few minutes now with only occasional high spike. Yesterday I deleted chrome with Revo Uninstaller and reinstalled and that helped slightly too. I will have to test a bit more before giving you a final state of things. Please keep this thread open for another day. Thanks.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If the reset and also the reinstall are not helping then the problem is not related to Chrome and also not related to malware since your logs were basically clean. More likely it would be either normal spikes as applications start up and also as your perform various operations or there is an interaction with something else you are running.
     
  8. phoenix333

    phoenix333 Private E-2

    Chaslang, go ahead and close the thread. I think my laptop is back to manageable levels. Spikes are at a minimum now, I think there were a few corrupted google chrome browser addons that were causing problems in addition to malware.

    I would like to thank you again for the invaluable service that you and the rest of the people here do, especially for the less technical savvy people who struggle with stuff like this. I can do most of this stuff myself, but having a resource like this available through your volunteer work is always a ++++
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks!


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
    Last edited: Oct 7, 2014
  10. phoenix333

    phoenix333 Private E-2

    All done.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Great. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds