Task Manager Disabled + High CPU usage

Hi all!

Since lately (1 week) I have trouble with working with my laptop as I have problems with apparantly a virus/worm. Whenever I startup Windows, I cannot open task manager and I have to use regedit and change DisableTskMngr every time I start up. Furthermore, the processor is working 100% all the time, but there are no clear programs for it to work maximum effort. Could somebody help me out? It might take a while for me to respond, as the laptop is failing every 15-20 min or so due to overheating.

Thanks in advance!

–Joost

–EDIT–

I have also tried to use Malware and CCcleaner but no effect.

Will add Malware info ASAP

Do you have latest version of Malwarebytes? … attach log

Attach OTL diagnostic log http://forum.avast.com/index.php?topic=53253.0

Took me a while, as the laptop overheated twice while scanning, but after sitting outside, it lasted longer.

Here are the logs.

Hi,

  1. Please download ComboFix by sUBs (
    http://www.mcshield.net/personal/magna86/Images/IconComboFix.png
    ) from here and save it to your Desktop.
    [i]If you are unsure how ComboFix works, read this guide.

  1. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:
• Right click on the avast! system tray icon (
http://www.mcshield.net/pg/images/avast5.png
) in the lower right corner of the screen and scroll up to avast! shield controls;
• In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


  1. Run ComboFix. Then, on disclaimer window, click I Agree! button.

[i][size=7pt]- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.

  • ComboFix will scan your computer in stages, total of 50 stages.
    Do not mouse-click around while ComboFix is running.
  • If malware is detected, ComboFix will begin with its removal, and may need to restart Windows.
    Note:If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart your computer.
    [/i]

  1. When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt)
    => Attach log report (ComboFix.txt) back to topic.

ComboFix shall also create addition log (typical location: C:\Qoobox\ComboFix-quarantined-files.txt)
=> Please attach that report (ComboFix-quarantined-files.txt) as well.

Hi guys,

Here are the logs:

The CPU seems to have calmed down and I can open Task Manager, but it seems there still might be some slowdown (or that is in my mind).

Open notepad and copy/paste the text present inside the code box below:

ClearJavaCache::

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000000

KillAll::

Driver::
mdf16
mvd23

Save this as CFScript.txt

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )

Hi guys,

Here is the log, laptop seems to work better now.

Any info in the log?

Hi,

It is necessary to uninstall ComboFix :

[*] Click Start (or
http://amf.mycity.rs/pg/images/VistaStartButton.png
) then Run.

On Windows7 or Vista you may use Start Search field if Run is not available.

[*] In the line of text type in (Copy) the following:

ComboFix /Uninstall

Note that there is a space between " ComboFix " and " /Uninstall " .

[*] then click OK (or press Enter ).

Wait for the uninstall process is complete.

Now I just want to check again if everything is good. Please download Farbar Recovery Scan Tool (
http://www.mcshield.net/personal/magna86/Images/FRST_canned.png
) by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

Hi,

Here are the logs.

Hi,

Do you know the E:\S.EXE file?

I’d also like to point out, you should stop torrenting your software. It is illegal.

Edit: screw auto correct

Hi all,

I am not aware of the E:\S.EXE file, E:\ is the Virtual Blu-ray Drive, or would that be something else?

As for the torrenting; it was ‘legal’ in The Netherlands (at least downloading) until two weeks ago. I am not justifying the torrenting, but since it has been officially declared illegal in court, I have ceased torrenting.

Then this is clean PC. Cleaning time … ;D

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup

http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

Hi guys,

Here is the log of DelFix.

I have not had any troubles concerning the earlier specified problems, so I suspect you guys have done a great job!

Thanks for all the help and keep up the great work!

–Joost