Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

DHCP Client 100% CPU after ComboFix


  • This topic is locked This topic is locked
4 replies to this topic

#1 Troudhyl

Troudhyl

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:France
  • Local time:10:24 PM

Posted 24 August 2012 - 03:25 PM

Hello,

I tried ComboFix, not in optimal conditions and without reading some recommendations before... thinking there would be some warnings and steps where cancels if it is too risky. Bad game. Moreover, I was/am not infected.

So... I retrieved the control of my machine, with damages in services. I lost the "PolicyAgent" service, which I disabled because it is created and stopped very very quickly, and so services.exe saturates the memory.
But firstable I need to fix the DHCP Client, which always takes 100% CPU and doesn't do its job very well. Here are 2 event logs, activated for 1-2s, I'm not able to understand what it is about :
http://www.partage-facile.com/20DT89L53Z/dhcp_client.evtx.html
http://www.partage-facile.com/P0J2BZVGAV/dhcpv6_client.evtx.html
I don't know if you will see it in English, tell me if I must retry.

Hoping you can help me !

Edit : of course I'm on Windows 7 (x64).

Edited by Troudhyl, 24 August 2012 - 03:52 PM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:03:24 PM

Posted 24 August 2012 - 09:14 PM

Read the guide here on preparing logs

http://www.bleepingcomputer.com/forums/topic34773.html

and create a topic here

http://www.bleepingcomputer.com/forums/forum22.html

Good luck

#3 Troudhyl

Troudhyl
  • Topic Starter

  • Members
  • 15 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:France
  • Local time:10:24 PM

Posted 25 August 2012 - 05:55 AM

Ok, here it is. I think you don't need to waste your time with logs, I already focused on the problem, and the cause is ComboFix, maybe conflicting with a network utility (after that, I ran it again but in safe mode, without more problem - the first time, after reboot, and maybe because of 100% CPU/RAM, some ComboFix processus crashed before end).

Edited by Troudhyl, 25 August 2012 - 05:55 AM.


#4 SleepyDude

SleepyDude

  • Malware Response Team
  • 3,083 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Portugal
  • Local time:09:24 PM

Posted 25 August 2012 - 06:53 AM

Hi,

On my humble opinion you should copy the log generated by Combofix located at c:\combofix.log and post it contents in the other thread also.

Its the best way to know what Combofix did.

• Please do not PM me asking for support. Post on the forums instead it will increases the chances of getting help for your problem by one of us.
• Posts in the Malware section that are not replied to within 4 days will be closed. PM me or a moderator to reactivate.
• Please post your final results, good or bad. We like to know! Thank you!

 
Proud graduate of GeekU and member of UNITE
___
Rui

 
 


#5 hamluis

hamluis

    Moderator


  • Moderator
  • 56,274 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:03:24 PM

Posted 25 August 2012 - 07:16 AM

Now that you have properly posted a malware log topic, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a MRT Team member, nor should you ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on, the MRT Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the MRT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the MRT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRT Team member is already assisting you and not open the thread to respond.

It may take several days to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

If HelpBot replies to your topic, PLEASE follow Step One so it will report your topic to the team members.

To avoid confusion, I am closing this topic.

Louis




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users