Multiple Chrome exe32 processes, popups everywhere, CPU spikes to 100%

alexreece27

New Member
Thread author
Mar 30, 2016
10
Hi there, I really hope you can help me… I opened Chrome a few days ago and there were pop-ups everywhere until Chrome crashed... the icons on my desktop keep on flashing, and then when I open Task Manager there are about 20 Chrome.exe32 files running and the CPU keeps spiking to 100% as the icons flash.

I managed to block the adverts with Adguard Adblocker and Adblock, but the system still seems to be doing huge amounts of background processes, and webpages seem to time out now from slowness.

A huge amount of RAM is being used as well, even when hardly any programs are open. I have tried several malware removal programs, ESET Powerliks Cleaner, Malwarebytes Anti-malware, Hitman pro, Roguekiller, Emisoft emergency kit, and none seem to be reaching it.

Thank you very much for your time, and I really hope you can help me.
 

Attachments

  • Task Manager - Chrome exe 32 processes.jpg
    Task Manager - Chrome exe 32 processes.jpg
    467.4 KB · Views: 6
  • CPU spikes to almost 100.jpg
    CPU spikes to almost 100.jpg
    302.4 KB · Views: 5
  • FRST.txt
    76.8 KB · Views: 7
  • Addition.txt
    58 KB · Views: 4
  • aswMBR.txt
    1.9 KB · Views: 2
  • AdwCleaner[S1].txt
    48.2 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hello,



Please download Zemana AntiMalware and save it to your Desktop.
  • Install the program and once the installation is complete it will start automatically.
  • Without changing any options, press Scan to begin.
  • After the short scan is finished, if threats are detected press Next to remove them.
Note: If restart is required to finish the cleaning process, you should click Reboot. If reboot isn't required, please restart your computer manually.
  • Open Zemana AntiMalware again.
  • Click on
    4zu6vb.jpg
    icon and double click the latest report.
  • Now click File > Save As and choose your Desktop before pressing Save.
  • The only left thing is to attach saved report in your next message.




51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a612a8b27e2-Zoek.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    Code:
    createsrpoint;
    autoclean;
    emptyclsid;
    emptyalltemp;
    ipconfig /flushdns >>"%temp%\log.txt";b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Upload it in your next reply.
 

alexreece27

New Member
Thread author
Mar 30, 2016
10
Hi, thanks for the swift response.

I ran both scans and rebooted (repots enclosed)

Unfortunately there are still the huge CPU spikes and memory drain.

What would you suggest that I do next?

Many thanks for your help so far
 

Attachments

  • 2016.03.31-06.40.02-i0-t92-d1.txt
    1.5 KB · Views: 6
  • zoek-results.txt
    10 KB · Views: 4

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

alexreece27

New Member
Thread author
Mar 30, 2016
10
Hi, I've just rescanned the system and attached the two reports

Cheers
 

Attachments

  • FRST.txt
    67.1 KB · Views: 4
  • Addition.txt
    58.2 KB · Views: 3

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Fix with Farbar Recovery Scan Tool

icon_exclaim.gif
This fix was created for this user for use on that particular machine.
icon_exclaim.gif

icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
icon_exclaim.gif

Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please attach it to your reply.
 

Attachments

  • fixlist.txt
    2.1 KB · Views: 9

alexreece27

New Member
Thread author
Mar 30, 2016
10
Many thanks for the reply.

The good news is that there seem to be less Google Chrome.exe*32 processes running in the Task Manager.

The bad news is that the CPU seems to be consuming even more memory now, there is still an excessive amount of RAM being used with nothing running, and to be honest the system seems even slower than before with websites timing out before they can load. It feels like some positive changes have been made, but that there is still some part of the virus still infecting things.

What do you suggest I do next?

And again, thank you very much for your help so far
 

Attachments

  • Fixlog.txt
    6.1 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
51a46ae42d560-malwarebytes_anti_malware.png
Scan with Malwarebytes' Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Install the progam and select update.
  • Once updated, click the Settings tab, in the left panel choose Detection & Protection and tick Scan for rootkits.
  • In the same tab, under PUP and PUM detections make sure it is set to Treat detections as malware.
  • Click the Scan tab, choose Threat Scan is checked and click Start Scan.
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • At the bottom click Export and choose Text file.
Save the file to your desktop and include its content in your next reply.
 

alexreece27

New Member
Thread author
Mar 30, 2016
10
Ok thanks, Please see attached scan log.

Unfortunately CPU still behaving erratically...
 

Attachments

  • malwarebytes scan log.txt
    1.6 KB · Views: 6

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on
    FRST.gif
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition.txt option is checked.

    2873ryc.png

  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach report into your next reply.
 

alexreece27

New Member
Thread author
Mar 30, 2016
10
Ok just rescanned and attached the 2 reports...

Cheers
 

Attachments

  • FRST.txt
    62.8 KB · Views: 2
  • Addition.txt
    58.9 KB · Views: 2

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Your PC seems clean. Let's make one more check:


51a5bf3d99e8a-ComboFixlogo16.png
Scan with ComboFix

This is a very powerful tool that should be used only if advised by Malware Analyst.
Do not run ComboFix on your own!


Referring to this instruction, please download ComboFix by sUBs and save it to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on
    51a5bf3d99e8a-ComboFixlogo16.png
    icon and select
    RunAsAdmin.jpg
    Run as Administrator to start the tool.
  • Accept the disclaimer and agree if prompted to install Recovery Console.
  • Do not take any actions while ComboFix goes through your System - it may cause it to stall!
  • This scan may take some time!
  • When finished - it will display a logfile (located also on your main drive, usually C:\ComboFix.txt).

Include that log in your next reply.
icon_idea.gif
If you'll encounter any issues with internet connection after running ComboFix, please visit this link.
icon_idea.gif
If an error about operation on the key marked for deletion will appear after running the tool, please reboot your machine.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top