hi…
i have windows 7 ultimate, but cpu is 100% usage, when i search i found that a file named dgen.exe was running, when i end process this file at task manager the cpu is good. the last edition and update of avast free can’t detect it. what i can do to delete this file??? thanks
Do you have any UBIsoft flight simulators on the computer ?
Download OTL to your Desktop
Secondary link
[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif
[*]Select All Users
[]Select LOP and Purity
[]Under the Custom Scan box paste this in
netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT
[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs
i have windows 7 ultimate, but cpu is 100% usage, when i search i found that a file named [b]dgen.exe [/b]was running,upload and test suspicious file(s) at www.virustotal.com if tested before, click new scan. Post link to scan result here
thanks, i started avast with boot-time and enabled to scan pup so avast found this:
File C:\Program Files\PCDApp\dgen.exe is infected by Win32:Miner-B [PUP], Deleted
as you seen the file was deleted and till now cpu is ok, if any thing wrong in future i will do as you want.
thanks
You should follow Essexboy instructions, there are probably more Adware on your system.
there are the link :
https://www.virustotal.com/ar/file/4733d12194f3cac2435962c94265d7a8424cad228a8f6bde3cd0817c7eb29039/analysis/1399386961/
there are the files attached…
upoloading OTL diagnostic logs to virustotal does not tell us much… they are not the infected ones. ;D
it is the dgen.exe file you need to upload and test.
File C:\Program Files\PCDApp\dgen.exe is infected by Win32:Miner-B [b][PUP],[/b] Deletedbut i guess that is to late since you have deleted it PUP = not virus / Possible Unwanted Program ..... usually crap that comes bundled with freware downloads....
On completion of this let me know of any remaining problems
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:OTL
SRV - [2014/04/10 11:03:04 | 000,097,007 | ---- | M] () [Auto | Stopped] -- C:\Program Files\PCDApp\StartHelp.exe -- (ProtectMonitor)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://istart.webssearches.com/web/?type=ds&ts=1398207585&from=amt&uid=HitachiXHDS721050CLA362_JPF511HF27YTMR27YTMRX&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-search.net/search?sid=476&aid=121&itype=a&ver=12521&tm=329&src=ds&p={searchTerms}
IE - HKU\S-1-5-21-1940374435-2387316273-678284423-1001\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}: "URL" = http://www.default-search.net/search?sid=476&aid=121&itype=a&ver=12521&tm=329&src=ds&p={searchTerms}
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O36 - AppCertDlls: x64 - (c:\program files\settings manager\systemk\x64\sysapcrt.dll) - File not found
O36 - AppCertDlls: x86 - (C:\Program Files\Settings Manager\systemk\sysapcrt.dll) - File not found
[2014/04/29 16:48:48 | 000,000,000 | ---D | C] -- C:\Users\tm\AppData\Roaming\BabSolution
[2014/04/29 16:48:03 | 000,000,000 | ---D | C] -- C:\Users\tm\AppData\Roaming\systweak
[2014/04/29 16:48:00 | 000,000,000 | ---D | C] -- C:\Users\tm\AppData\Local\Programs
[2014/04/22 15:58:16 | 000,000,000 | ---D | C] -- C:\Program Files\PCDApp
:Files
C:\Windows\Temp\nsh5DE0.tmp
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.
there are two attached, the first one for otl , the second for adwcleaner…
How is the computer now ?
till now its ok thanks, if any problem found i post you.
In that case methinks I will send you on your merry way
Subject to no further problems
I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean
A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Download and run Delfix
https://dl.dropboxusercontent.com/u/73555776/delfix.JPG
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
CryptoPrevent install this programme to lock down and prevent crypto ransome ware
https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG
Update and run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe