Results 1 to 10 of 14

Thread: svchost.exe*32 winrscmde hogging all of the cpu

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi Altiery,


    Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Save ComboFix.exe to your Desktop

    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
    • Right click on ComboFix.exe, click Run as Administrator & follow the prompts.


    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

    Notes:

    1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    3. If after running combofix you recieve an message "Illegal operation attempted on a registery key that has been marked for deletion" or similar reboot the computer.
    4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

    Please post back with the combofix log.

    Thanks
    Member of UNITE and ASAP

  2. #2
    Junior Member
    Join Date
    Oct 2012
    Posts
    7

    Default

    Here is the combofix log.

  3. #3
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi Altiery,

    How's the computer?

    This looks pretty good. Please rerun aswMBR and post the log.

    Thanks
    Member of UNITE and ASAP

  4. #4
    Junior Member
    Join Date
    Oct 2012
    Posts
    7

    Default

    The computer is working great, thank you so much for your time.


    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-10-24 14:31:08
    -----------------------------
    14:31:08.933 OS Version: Windows x64 6.1.7601 Service Pack 1
    14:31:08.933 Number of processors: 4 586 0x2502
    14:31:08.933 ComputerName: JEREMY-PC UserName: Jeremy_2
    14:31:11.850 Initialize success
    14:31:32.613 AVAST engine defs: 12102302
    14:31:55.265 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
    14:31:55.280 Disk 0 Vendor: ST925041 D005 Size: 238475MB BusType: 3
    14:31:55.389 Disk 0 MBR read successfully
    14:31:55.405 Disk 0 MBR scan
    14:31:55.405 Disk 0 Windows VISTA default MBR code
    14:31:55.436 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
    14:31:55.483 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 80325
    14:31:55.514 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 223434 MB offset 30800325
    14:31:55.764 Disk 0 scanning C:\Windows\system32\drivers
    14:32:38.291 Service scanning
    14:33:13.032 Modules scanning
    14:33:13.047 Disk 0 trace - called modules:
    14:33:13.079 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
    14:33:13.094 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800658d060]
    14:33:13.110 3 CLASSPNP.SYS[fffff8800140143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80062d9050]
    14:33:15.153 AVAST engine scan C:\Windows
    14:33:23.811 AVAST engine scan C:\Windows\system32
    14:38:59.665 AVAST engine scan C:\Windows\system32\drivers
    14:39:25.672 AVAST engine scan C:\Users\Jeremy_2
    14:54:50.187 AVAST engine scan C:\ProgramData
    15:00:09.232 Scan finished successfully
    15:06:04.571 Disk 0 MBR has been saved successfully to "C:\Users\Jeremy_2\Desktop\MBR.dat"
    15:06:04.586 The log file has been saved successfully to "C:\Users\Jeremy_2\Desktop\aswMBR.txt"
    15:06:24.372 Disk 0 MBR has been saved successfully to "C:\Users\Jeremy_2\Documents\MBR.dat"
    15:06:24.387 The log file has been saved successfully to "C:\Users\Jeremy_2\Documents\aswMBR.txt"

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •