Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

80-99% of CPU used all times by mscorsvw.exe, 2 Days now


  • Please log in to reply
3 replies to this topic

#1 Bineet

Bineet

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 16 December 2012 - 09:48 PM

Hi there,
This is my first post here, I hope it helps me :)
Okay I've mscorsvw.exe process which has been running all the times from past 2 days, and it eats 80-99% of my CPU making it slow.
I have taken following steps in vain:

1)Did executequeueditems on both 2.0.5077 and 4.0.30319 under Framework and Framework64 (of Microsoft.Net) which gave me :
All Compilation Target are uptodate

2)Installed Process Lasso and marked this process under "Terminate Always(Disallowed Process)" but then it would try again and again to run while being terminated by Lasso. So I removed it from "Terminate Always".

3) A day back, Another file sbs_wminet_utils.dat was eating my CPU- nealry 100%, I searched about this file on internet and found 1 user telling that it was a new virus. As instructed there

http://social.technet.microsoft.com/Forums/pl/w7itproperf/thread/82e493bb-5e30-4886-a7fb-a70e7621acf3

, I deleted this file and it never ate my cpu again, but after doing this step again came "mscorsvw.exe", which started eating my CPU.

4) Right now, When I checked security History under Norton Internet Security, I am really amazed to see "sbs_wminet_utils.dat" again, It says at 6:30, this ate at least 100% of my CPU :(

5) All these problems started after I installed Call of Duty: Black Ops 2 (It was Skidrow crack(Trusted Provider)), I have uninstalled this game with its setup files now from my PC :(

6) Hence now summarizing :
This is by Norton Internet Security
Category: Performance Alert
Date & Time,Risk,Activity,Status,Recommended Action
17-12-2012 06:36,Info,High CPU usage by: mscorsvw.exe ,Detected,No Action Required
17-12-2012 06:30,Info,High CPU usage by: .NET Runtime Optimization Service ,Detected,No Action Required - (sbs_wminet_utils.dat)
16-12-2012 17:31,Info,High CPU usage by: .NET Runtime Optimization Service ,Detected,No Action Required - (sbs_wminet_utils.dat)
16-12-2012 16:59,Info,High CPU usage by: .NET Runtime Optimization Service ,Detected,No Action Required - (sbs_wminet_utils.dat)
16-12-2012 10:30,Info,High CPU usage by: mscorsvw.exe ,Detected,No Action Required
16-12-2012 10:25,Info,High CPU usage by: mscorsvw.exe ,Detected,No Action Required
16-12-2012 09:52,Info,High CPU usage by: .NET Runtime Optimization Service ,Detected,No Action Required - (sbs_wminet_utils.dat)
13-12-2012 14:04,Info,High Disk Read usage by: Windows Start-Up Application ,Detected,No Action Required
13-12-2012 10:49,Info,High Memory usage by: Call of Duty®: Black Ops II ,Detected,No Action Required
13-12-2012 08:38,Info,"High Disk Read, Disk Write usage by: Setup/Uninstall ",Detected,No Action Required




All these reasons are making me believe this a very very suspicious activity.

My System Config is:
Intel core i7-2630QM CPU
Memory 4GB, DirectX11
Windows 7 Home Premium x64

EDITED: 1) WOW! IT'll EAT CPU but not when TASK MANAGER IS ON.
2) Virustotal.com is giving 6/45 detection ration for sbs_wminet_utils.dat, SUPERAntiSpyware saying there: Trojan.Agent/Gen-MSFake[Gen]
Here is the detection page:

https://www.virustotal.com/file/9ca0a70e18766b9d80634329cf1bf249c4cc380003574208e778fb12552ae3eb/analysis/1355724296/

3) Used SuperAntiSpyware Professional Trial Version and scanned custom for : Memory, Registry, Startup Locations and Folders: \system32 and \syswow64. It detected and cleaned three threats, including sbs_wminet_utils.dat, SBS_MSCORSEC.dat and a tracking cookie.
4) After restarts, The CPU is not being eaten but it is working very very slow. I click something which will happen probably after 2 minutes.
5) After System Restore at a clean day and again using SUperAntiSpyware, everything is clean and working now.


Thanks.

Edited by Bineet, 17 December 2012 - 07:39 AM.


BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,323 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:36 PM

Posted 17 December 2012 - 11:13 PM

Looks like you installed a cracked software and it has executed some exploit kit


So I think we should get a deeper look. Please follow this Preparation Guide and post in a new topic.

Let me know if all went well.

Include this link back to here...

http://www.bleepingcomputer.com/forums/topic478700.html
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Bineet

Bineet
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:11:06 PM

Posted 18 December 2012 - 03:38 AM

Should I do it?, I think the System is working very good now after system restore + Cleaning threats using SuperAntiSpyware + Ccleaner + Revo Uninstaller + cklnks :)
I only want to ask now whether those scanners who detected this new threat, 6/45 on 'virustotal.com' are better than the rest ?

#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,323 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:01:36 PM

Posted 18 December 2012 - 12:35 PM

VirusTotal runs some 20 AV apps to check a file.It wil not scan your whole PC.probably O

You are probably OK until you start running cracks or torrents and reinfect.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users