Page 2 of 2 FirstFirst 12
Results 11 to 14 of 14

Thread: svchost.exe*32 winrscmde hogging all of the cpu

  1. #11
    Junior Member
    Join Date
    Oct 2012
    Posts
    7

    Default

    The computer is working great, thank you so much for your time.


    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-10-24 14:31:08
    -----------------------------
    14:31:08.933 OS Version: Windows x64 6.1.7601 Service Pack 1
    14:31:08.933 Number of processors: 4 586 0x2502
    14:31:08.933 ComputerName: JEREMY-PC UserName: Jeremy_2
    14:31:11.850 Initialize success
    14:31:32.613 AVAST engine defs: 12102302
    14:31:55.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    14:31:55.280 Disk 0 Vendor: ST925041 D005 Size: 238475MB BusType: 3
    14:31:55.389 Disk 0 MBR read successfully
    14:31:55.405 Disk 0 MBR scan
    14:31:55.405 Disk 0 Windows VISTA default MBR code
    14:31:55.436 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
    14:31:55.483 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 80325
    14:31:55.514 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 223434 MB offset 30800325
    14:31:55.764 Disk 0 scanning C:\Windows\system32\drivers
    14:32:38.291 Service scanning
    14:33:13.032 Modules scanning
    14:33:13.047 Disk 0 trace - called modules:
    14:33:13.079 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    14:33:13.094 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800658d060]
    14:33:13.110 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062d9050]
    14:33:15.153 AVAST engine scan C:\Windows
    14:33:23.811 AVAST engine scan C:\Windows\system32
    14:38:59.665 AVAST engine scan C:\Windows\system32\drivers
    14:39:25.672 AVAST engine scan C:\Users\Jeremy_2
    14:54:50.187 AVAST engine scan C:\ProgramData
    15:00:09.232 Scan finished successfully
    15:06:04.571 Disk 0 MBR has been saved successfully to "C:\Users\Jeremy_2\Desktop\MBR.dat"
    15:06:04.586 The log file has been saved successfully to "C:\Users\Jeremy_2\Desktop\aswMBR.txt"
    15:06:24.372 Disk 0 MBR has been saved successfully to "C:\Users\Jeremy_2\Documents\MBR.dat"
    15:06:24.387 The log file has been saved successfully to "C:\Users\Jeremy_2\Documents\aswMBR.txt"

  2. #12
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi Altiery,

    Looks good. A couple more scans to make sure we got everything and we can clean up.

    You have some old java installed Click start > Control pane. Under programs click uninstall a program and uninstall

    Java(TM) 6 Update 20 (64-bit)
    Java(TM) 6 Update 31
    Java(TM) 7 Update 5 (64-bit)


    Do not uninstall Java 7 Update 9

    You can get the newest 64BIT version from HERE It's the last one in the list.

    • Accept the License Agreement
    • Download the last file in the list jre-7-windows-x64.exe
    • double click the files one at a time to install them
    Decline any additional installs that may be offered during the update.



    Next

    Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean





    Next


    You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

    Open MBAM

    • Click the Update tab
    • Click Check for Updates
    • If an update is found, it will download and install the latest version.
    • The program will close to update and reopen.
    • Once the program has loaded, select "Perform Quick Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.

    Extra Note:
    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



    One more scan to check our handiwork.

    As a Vista/Win7 user you will need to right click your browser icon and select "Run as Administrator" in order to run this scan.
    • Do not use this instance of your browser for anything besides doing this scan
    • When the scan is complete and the results saved, close that instance of your browser
    • Open a new one the usual way and post the results in this topic.


    *Note
    It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
    Please don't go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



    Go here to run an online scannner from
    ESET

    (Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the activex control to install
    • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
    • Click Start
    • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
    • Click Scan.
    • Wait for the scan to finish.
    • When the scan completes, click List of found threats
    • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
    • Include the contents of this report in your next reply

      Note - when ESET doesn't find any threats, no report will be created.
    • Push the back button.
    • Push Finish
    • Re-enable your Antivirus software.


    Please post back with
    • MBAM log
    • ESET log is there is one
    Everything still ok?
    Member of UNITE and ASAP

  3. #13
    Junior Member
    Join Date
    Oct 2012
    Posts
    7

    Default

    The computer is working great.
    heres the logs you wanted

  4. #14
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi Altiery,

    I do believe you are good to go. The ESET detections are files we have all ready quarantined and will be removed when we remove the tools.

    We'll clean up the tools now.

    From your desktop, please delete, if present
    • any notepads/logs that we created
    • aswMBR.exe
    • mbr.zip
    • mbr.dat
    • TDSSKiller
    You can also delete this folder C:\TDSSKiller_Quarantine and these files TDSSKiller.2.8.13.0_21.10.2012_22.20.14_log.txt and TDSSKiller.2.8.13.0_21.10.2012_22.29.12_log.txt from C:\


    Next

    Click the Start button. Copy and paste the following line into the search box and click OK


    Combofix /uninstall




    Next

    Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


    I suggest you keep MBAM. Keep it updated and use it regularly.

    You can keep TFC if you want to.



    Updates and upgrades

    You have an older version of Adobe Reader. You can download the current version HERE

    You may want to consider Foxit Reader instead. It may be a bit lighter on resources. If you choose to use Foxit decline the FoxIt Toolbar that may be offered during the install.

    Visit their support forum
    Foxit Forum

    In either case you should uninstall Adobe Reader 9.1.2 first. Be sure to move any PDF documents to another folder first though.



    Some Recommendations and prevention tips

    Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Those you have now.

    You should also use Spyware Blaster to help immunize your computer.

    - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
    settings that will protect you from running and downloading known malicious programs.

    OR

    A guide to understanding and using the hosts file.

    Learn how your Hosts file can protect you and how you can protect it.
    Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
    HOSTS

    Please read the info on disabling the DNS Client before installing a custom hosts file.


    -Secure your Internet Explorer

    From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.


    - Make sure you have reset Windows Updates to your chosen option. Click your start button > Control Panel > System > Windows updates (lower left) > change settings


    - Keep your antivirus program updated, as well as any other security programs you have.


    -More tips and programs can be found HERE

    Please post back if you have any problems.

    Take care
    Member of UNITE and ASAP

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •