Unstable Laptop - Infection Likely Found

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Twistid, Dec 29, 2014.

  1. Twistid

    Twistid Corporal

    Hello.

    I just ran the Malware Removal/Cleaning Procedure for a Windows 7 system.

    RogueKiller appeared to find something when I ran it. I've also run all the other software and saved the logs.

    After RogueKiller finished scanning, it automatically loaded the following site in Internet Explorer: http://www.adlice.com/poweliks-removal-with-roguekiller/

    It seemed like my laptop had a possible infection when it started using up somewhere in the range of 50%-100% CPU and Memory without doing much of anything on the computer. At first after a startup, the computer seems to run fine. It will start off anywhere from 0% to 10% CPU usage and usually 20%-30% Memory usage. After around 15 minutes or so, eventually it will start acting up and use 50%-100% of CPU and Memory suddenly.

    The following processes appear related:
    Microsoft(C) Register Server: regsvr32.exe *32
    Host Process for Windows Servicees: svchost.exe
    Windows host process (Rundll32): rundll32.exe *32

    When the Memory and CPU usage starts spiking up too high suddenly for a long period of time, I noticed it is always these three processes that are using up the most amount of Memory under the Processes column when looking at them in the Task Manager. I sorted the Processes by "Memory (Private Working Set)" is how I know.

    rundll32.exe *32 usually doesn't appear to be using a lot of memory most of the time, but there have been cases where it was spiking about as high as the other two. Usually it is the first two that appear to be using the most Memory.

    This occurs regardless of what I am doing on my computer at the time. I could let the laptop simply sit there and not do anything with it and it will spike with this Memory and CPU usage issue eventually.

    This appears to be causing an overheating problem at times. It can cause the laptop to become sluggish in response and causes the fan to whir loudly, and the vent feels hotter to the touch as a result. There are times where the laptop becomes barely functional.
     

    Attached Files:

  2. Twistid

    Twistid Corporal

    I encountered two errors when running MGTools.

    I have attached a screenshot of my desktop with these two errors showing.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have a poweliks infection.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  4. Twistid

    Twistid Corporal

    Thanks for helping me out!

    Farbar Recovery Scan logs are attached.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want to double check the status of Poweliks by having you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  6. Twistid

    Twistid Corporal

    New Fixlog and MGlogs attached
     

    Attached Files:

  7. Twistid

    Twistid Corporal

    New FRST and Addition logs attached.

    Laptop seems to run faster and more stable now :).
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes and the logs look good too. :)

    Delete all Windows lets you from this location:
    C:\Users\Twistid\AppData\Local\Temp

    Can you re run RogueKiller once again and attach log please?
     
    Last edited: Dec 30, 2014
  9. Twistid

    Twistid Corporal

    New RogueKiller log attached
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent. Ready for final steps? :)
     
  11. Twistid

    Twistid Corporal

    Awesome! Definitely ready :).
     
  12. Twistid

    Twistid Corporal

    Should I just follow the final steps in the ReadMe or did you have final steps specific to my case that I should do?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. Twistid

    Twistid Corporal

    Final steps done! Still running smoothly. Thanks again for your help!
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome! :) Safe surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds