Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I think I have a virus that's cutting internet access.


  • Please log in to reply
No replies to this topic

#1 Shivalyn

Shivalyn

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:03 PM

Posted 11 June 2011 - 02:36 PM

Yesterday my computer started freaking out and my processor's activity shot through the roof with tons of activity on each core. Usually each core (out of 4) had at least 25% activity, spiking to 50% at times, and at any given time at least one core would be at 100%. RAM usage was 60% of 4 gigs on a Windows 7 Pro 64-bit system. This was while idling.

Also, for all intents and purposes, I couldn't connect to the internet at all beyond just my computer connecting to the network. I could maybe load a single page once in a blue moon but beyond that, nothing. I've since deactivated my wireless card as a preventative measure. Other computers can connect though (hence why I'm here lol).

I ran SuperAntiSpyware, MalwareBytes, HijackThis, and SpybotS&D. Will post the first three and then Spybot if y'all just really wanna see it (it's 15 pages long even though the program said it found nothing). Though for that matter, none of them really found anything beyond some tracking cookies.

Any and all help is appreciated because I'm at a complete loss as to what to do.

Super Anti Spyware
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/11/2011 at 04:43 AM

Application Version : 4.53.1000

Core Rules Database Version : 7125
Trace Rules Database Version: 4937

Scan type : Complete Scan
Total Scan Time : 02:29:24

Memory items scanned : 827
Memory threats detected : 0
Registry items scanned : 15318
Registry threats detected : 0
File items scanned : 39173
File threats detected : 19

Adware.Tracking Cookie
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@us.adform[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@at.atwola[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@2o7[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@advertising[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@ads.ad4game[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@apmebf[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@serving-sys[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@tacoda.at.atwola[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@mediaplex[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@ar.atwola[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@ad.yieldmanager[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@revsci[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@adform[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@eyewonder[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@atwola[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@zedo[2].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@adxpose[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@content.yieldmanager[1].txt
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Cookies\Spiffy@doubleclick[1].txt




MalwareBytes
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6366

Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514

6/11/2011 4:35:08 AM
mbam-log-2011-06-11 (04-35-08).txt

Scan type: Full scan (C:\|D:\|G:\|)
Objects scanned: 414810
Time elapsed: 2 hour(s), 27 minute(s), 10 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




HijackThis
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:11:08 AM, on 6/11/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
C:\Users\Spiffy\Local Settings\Apps\F.lux\flux.exe
C:\Users\Spiffy\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
C:\Users\Spiffy\Desktop\HijackThis.exe
C:\Users\Spiffy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\speedfan.exe
C:\Program Files (x86)\Winamp\winamp.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.wikipedia.org/wiki/Special:Random
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 208.122.31.3 i.imgur.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [F.lux] "C:\Users\Spiffy\Local Settings\Apps\F.lux\flux.exe" /noshow
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: debug.nfo
O4 - Startup: Dropbox.lnk = Spiffy\AppData\Roaming\Dropbox\bin\Dropbox.exe
O4 - Startup: ProgramHotkeys.ahk - Shortcut.lnk = Spiffy\Documents\My Dropbox\Shortcuts.ahk
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O4 - Startup: speedfan.exe
O4 - Startup: speedfanparams.cfg
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: connection manager.lnk = ?
O4 - Global Startup: UltraMon.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{14D423E3-74A5-4DA8-9A1A-2953BDC5AF9D}: NameServer = 8.8.8.8,4.4.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{AFD6FD2D-6C85-4F38-9F8E-85EE2EF172F4}: NameServer = 208.67.222.222
O17 - HKLM\System\CS1\Services\Tcpip\..\{14D423E3-74A5-4DA8-9A1A-2953BDC5AF9D}: NameServer = 8.8.8.8,4.4.2.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{14D423E3-74A5-4DA8-9A1A-2953BDC5AF9D}: NameServer = 8.8.8.8,4.4.2.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD Reservation Manager - Advanced Micro Devices - C:\Program Files\ATI Technologies\ATI.ACE\Reservation Manager\AMD Reservation Manager.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Livescribe Pulse Smartpen Service (PenCommService) - Livescribe - C:\Program Files (x86)\Common Files\Livescribe\PenComm\PenCommService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: SAMSUNG WiselinkPro Service (WiselinkPro) - Unknown owner - C:\Program Files (x86)\Samsung\SAMSUNG PC Share Manager\WiselinkPro.exe
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10536 bytes

BC AdBot (Login to Remove)

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users