bad virus, computer CPU at 100%

Status
Not open for further replies.
Juliet, you are going to kill me or not respond! I thought I was clean, and my son wanted to play his game, minecraft, which I paid for on the Mojang website. Downloaded the game from their site, and there we go again. extremely sluggish computer and CPU running at 100%. So sorry I didn't wait for your reply.

Do we start over? I am in safe mode again, as its the only way I can write an email without waiting for 5 minutes before it sends.
 
I repeated your instructions and now seem to be running normal again. sorry. let me know if you want any repeat scans. CPU is running well. I deleted the offending minecraft.
 
Well, thats odd. Wonder if it downloaded extras from that site?

To make sure let's run:

Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
 
Juliet, sorry for the delay. Eset would hang in normal, so I ran it in safe mode. Looks like we still have some threats.

C:\Users\Andy Besing\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUG4TXV1\spstub[1].exe Win32/Conduit.SearchProtect.L potentially unwanted application
C:\Users\Andy Besing\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\17dcbab9-4e40897e a variant of Java/Exploit.CVE-2010-0840.NAN trojan
C:\Users\Andy Besing\AppData\Roaming\0S1F1O2Z0S2Y1H1T\Font Installer Packages\uninstaller.exe Win32/InstallCore.AZ potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi145-AdwCleaner-ORG-75851221.exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe a variant of Win32/CNETInstaller.B potentially unwanted application
C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe a variant of Win32/InstallCore.IO potentially unwanted application
C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe a variant of Win32/InstallCore.JK potentially unwanted application
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe a variant of Win32/InstallCore.FJ potentially unwanted application
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe a variant of Win32/InstallCore.FJ potentially unwanted application
C:\Users\Andy Besing\Downloads\Setup.exe a variant of Win32/AdWare.iBryte.Q application
C:\Users\Andy Besing\Downloads\UltimateCodec.exe a variant of Win32/InstallCore.JK potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-809.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-994.dll a variant of Win32/BrowseFox.F potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081425-738.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-082845-587.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-092331-917.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\Users\Andy Besing\Downloads\backups\backup-20131120-093331-326.dll a variant of Win32/BrowseFox.F potentially unwanted application
 
Let's remove some bad files.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (FRST) program (If asked to overwrite existing one please allow)

start
C:\Users\Andy Besing\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUG4TXV1\spstub[1].exe
C:\Users\Andy Besing\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\17dcbab9-4e40897e
C:\Users\Andy Besing\AppData\Roaming\0S1F1O2Z0S2Y1H1T\Font Installer Packages\uninstaller.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi145-AdwCleaner-ORG-75851221.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe
C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe
C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe
C:\Users\Andy Besing\Downloads\Setup.exe
C:\Users\Andy Besing\Downloads\UltimateCodec.exe
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-809.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-994.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081425-738.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-082845-587.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-092331-917.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-093331-326.dll
end
Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system


Please post the Fixlog when finished.

How is your computer now?
 
Here is the log, I will reboot and let you know!

sFix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 20-02-2014
Ran by Andy Besing at 2014-02-21 07:36:14 Run:1
Running from C:\Users\Andy Besing\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
start
C:\Users\Andy Besing\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUG4TXV1\spstub[1].exe
C:\Users\Andy Besing\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\17dcbab9-4e40897e
C:\Users\Andy Besing\AppData\Roaming\0S1F1O2Z0S2Y1H1T\Font Installer Packages\uninstaller.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi145-AdwCleaner-ORG-75851221.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe
C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe
C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe
C:\Users\Andy Besing\Downloads\Setup.exe
C:\Users\Andy Besing\Downloads\UltimateCodec.exe
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-809.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-994.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081425-738.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-082845-587.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-092331-917.dll
C:\Users\Andy Besing\Downloads\backups\backup-20131120-093331-326.dll
end
*****************

C:\Users\Andy Besing\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SUG4TXV1\spstub[1].exe => Moved successfully.
C:\Users\Andy Besing\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57\17dcbab9-4e40897e => Moved successfully.
C:\Users\Andy Besing\AppData\Roaming\0S1F1O2Z0S2Y1H1T\Font Installer Packages\uninstaller.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi145-AdwCleaner-ORG-75851221.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (1).exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (2).exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (3).exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221 (4).exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-AdwCleaner-SEO-75851221.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\cbsidlm-cbsi176-CleanUp-SEO-10727454.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\Minecraft Download Manager.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\PDFCreatorSetup.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2 (1).exe => Moved successfully.
C:\Users\Andy Besing\Downloads\PDFlite-0.11.2.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\Setup.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\UltimateCodec.exe => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-809.dll => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081242-994.dll => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-081425-738.dll => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-082845-587.dll => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-092331-917.dll => Moved successfully.
C:\Users\Andy Besing\Downloads\backups\backup-20131120-093331-326.dll => Moved successfully.

==== End of Fixlog ====
 
Running good sounds great to me!

Got a question. When going back over your logs I see
AVG your computers antivirus? or Microsoft Security Essentials?, both are OK to use but we need to make sure there is only 1 on the computer or we will run into issues caused by having 2.

Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

Run FRST/FRST64 and press the Fix button just once and wait.
no needed to post the log this time.

start
DeleteQuarantine:
end

Just delete any other remaining tools with their folders.

Your good to go, good job!

Please take the time to read over a few of my preventive tips.

Computer Security
http://malwareremoval.com/forum/viewtopic.php?p=557960#p557960
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Be prepared for CryptoLocker:

Cryptolocker Ransomware: What You Need To Know

CryptoLocker Ransomware Information Guide and FAQ

to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

CryptoPrevent.JPG


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please navigate to Microsoft Windows Updates and download all the "Critical Updates" for Windows.


Firefox 3
The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 3, added powerful new features that make your online experience even better. It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
*NoScript - Addon for Firefox that stops all scripts from running on websites. Stops malicious software from invading via flash, java, javascript, and many other entry points.

AdblockPlus
  • AdblockPlus, Surf the web without annoying ads!
  • Blocks banners, pop-ups and video ads - even on Facebook and YouTube
  • Protects your online privacy
  • Two-click installation, It's free!
  • click the icon that corresponds to your browser and download.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
WOT Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites - green to go, yellow for caution and red to stop, helping you avoid the dangerous sites. WOT has an addon available for both Firefox and IE.
Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
 
did windows update, then decided to go with MS security essentials. Now slow again!! running ESET in safe mode, stand by.
 
Could also be a recent Microsoft update?

anxious to hear back from you.
 
ESET found nothing. prior to running it, I uninstalled MS essentials and Flash, as you suggested. Computer seems to be running fine now. I wonder why the MS essentials was slowing it down? What antivirus would you suggest that not going to eat up processing?
 
Glad we could help. :)
sparkle.gif


Since this issue appears resolved ... this Topic is closed.
 
HPMSGSVC.exe is the main culprit. I think its the crap that HP loads on new computers. I googled it and I see other users with the same complaint. Do I need it? I see some who have removed it from the start menu and have had no problems.
 
it is unnecessary to run this program automatically when Windows starts as you can run it manually when necessary.
My old HP came with preinstalled little programs all related to HP, the only one I allow now is for my printer.


You can check your start up programs here http://www.bleepingcomputer.com/startups/?&act=search&st=0&keyword=HPMSGSVC.exe

If you don't know some programs listed there or unsure if they are needed or not, leave them enabled, or use RubberDucky's StartUpLite

This will display all unnecessary startup entries - so actually, everything it displays there is not necessary to start up with Windows.
The choice is up to you whether you need some to start up with Windows (in that case, select "No action" for them) - but you can always start them manually via start > all programs.
(Do not choose the "Remove" checkboxes, because this will delete it from the Registry - only select the "Remove" checkboxes if you are sure you don't want to enable them again in the future)
 
i got the offender, thanks! before your post, I did msconfig and unchecked it from start up. other users did the same thing, working great now. CPU is averaging 16% with just browser open. Maybe that is what caused the antivirus to act up. I think its safe to close the topic, thanks for all your help.
 
Could be.
I'll leave this topic open for a day or so, something spikes it up again let me know.
 
Status
Not open for further replies.
Back
Top