Malware bytes detected no malicious threat
Malware Removal Forums
dllhost.exe taking too much CPU memory help please
352 min read
Hello mantgar,
Very good, but I'm still waiting for the results of the last scan by ESET from the Step 3.
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
Very good, but I'm still waiting for the results of the last scan by ESET from the Step 3.
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Ask.com\SaUpdate.exe.vir a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll.vir a variant of Win32/Toolbar.Montiera.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll.vir Win32/Toolbar.Babylon potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\Local\AskToolbar\Downloaded Program Files\xaddon.dll.vir a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\LocalLow\AskToolbar\setup.exe.vir a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\LocalLow\AskToolbar\xaddon.cab.vir a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Qoobox\Quarantine\Registry_backups\CLSID_{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}.reg.dat Win32/Poweliks.C trojan
C:\Users\mbmnb\AppData\Local\Ivzgsoft\mDNSResponder.dll a variant of Win32/Packed.Themida potentially unwanted application
C:\Users\mbmnb\AppData\Local\Onlics\kgmjaxslpalvgn.dll a variant of Win32/Packed.Themida potentially unwanted application
C:\Users\mbmnb\Downloads\Zwinky.exe Win32/AdInstaller potentially unwanted application
C:\Windows\Installer\172a0a5.msi a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\_OTL\MovedFiles\11142014_093103\C_Users\Arturo Flores\Downloads\zyngaIE_toolbar.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
D:\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarApp.dll.vir a variant of Win32/Toolbar.Montiera.A potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll.vir Win32/Toolbar.Babylon potentially unwanted application
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\Community Alerts\Alert.dll.vir Win32/Toolbar.Conduit.Y potentially unwanted application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\Local\AskToolbar\Downloaded Program Files\xaddon.dll.vir a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\LocalLow\AskToolbar\setup.exe.vir a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application
C:\AdwCleaner\Quarantine\C\Users\mbmnb\AppData\LocalLow\AskToolbar\xaddon.cab.vir a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\Qoobox\Quarantine\Registry_backups\CLSID_{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}.reg.dat Win32/Poweliks.C trojan
C:\Users\mbmnb\AppData\Local\Ivzgsoft\mDNSResponder.dll a variant of Win32/Packed.Themida potentially unwanted application
C:\Users\mbmnb\AppData\Local\Onlics\kgmjaxslpalvgn.dll a variant of Win32/Packed.Themida potentially unwanted application
C:\Users\mbmnb\Downloads\Zwinky.exe Win32/AdInstaller potentially unwanted application
C:\Windows\Installer\172a0a5.msi a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
C:\_OTL\MovedFiles\11142014_093103\C_Users\Arturo Flores\Downloads\zyngaIE_toolbar.exe a variant of Win32/Toolbar.Conduit.B potentially unwanted application
D:\DECRYPT_INSTRUCTION.TXT Win32/Filecoder.CR trojan
Hello mantgar,
Step 1.
Show Hidden and System files
Step 2.
Online Multi Antivirus file scan
Please go to either: Jotti or Virus Total and upload - only one file per scan - the following file(s) for scanning:
C:\Users\mbmnb\AppData\Local\Ivzgsoft\mDNSResponder.dll
C:\Users\mbmnb\AppData\Local\Onlics\kgmjaxslpalvgn.dll
C:\Users\mbmnb\Downloads\Zwinky.exe
C:\Windows\Installer\172a0a5.msi
D:\DECRYPT_INSTRUCTION.TXT
Using Jotti
Using Virus Total
Please include in your next reply:
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
Step 1.
Show Hidden and System files
- Close all programs so that you are at your desktop.
- Press
. - Click the Start Search box on the Start Menu
- Copy and paste the following value in blue, in the open text entry box:
change search options for files and folders
then press Enter button - Click on the View tab, then under the "Hidden files and folders" section please
- SELECT "Show hidden files and folders"
- Find below and
- remove check mark from check box "Hide extensions for known file types"
- remove check mark from check box "Hide protected operating system files"
- Press the Apply, then the OK buttons.
Step 2.
Online Multi Antivirus file scan
Please go to either: Jotti or Virus Total and upload - only one file per scan - the following file(s) for scanning:
C:\Users\mbmnb\AppData\Local\Ivzgsoft\mDNSResponder.dll
C:\Users\mbmnb\AppData\Local\Onlics\kgmjaxslpalvgn.dll
C:\Users\mbmnb\Downloads\Zwinky.exe
C:\Windows\Installer\172a0a5.msi
D:\DECRYPT_INSTRUCTION.TXT
Using Jotti
- Choose the appropriate language (if needed)... once a language is selected, you'll see a message "Ready to receive files"
- Press the Browse button and navigate to -one- of the files in the list.
- Double click the located file name...The file name should now appear in the online scanner's "File to scan:" box.
- Click on Submit..button.
- If you receive the message: This file has been scanned before. The results for this previous scan are listed below.
Please press the Scan again button, so your file will be scanned. - The file will be uploaded and scanned by various antivirus scanners..this may take a few minutes.
- When all scans have completed... the results page is displayed
- Please highlight and copy the page web address link from your browser window.
Example of web address :

- Please repeat this procedure for each file listed above.
- Paste the Web address link(s) for the scan results in your next reply.
Using Virus Total
- Press the Browse button and navigate to -one- of the files in the list.
- Double click the located file name... The file name should now appear in the online scanner's text entry box.
- Click on Send File...button.
- The file will be queued, uploaded and scanned by various antivirus scanners..this may take a few minutes.
- If you receive the message: File has already been analysed:
Please press the Reanalyse file now button, so your file will be scanned. - When all scans have completed... the results page is displayed
- Please highlight and copy the page web address link from your browser window.
Example of web address:

- Please repeat this procedure for each file listed above.
- Paste the Web address link(s) for the scan results in your next reply.
Please include in your next reply:
- Do you have any problems executing the instructions?
- The resulting web links after online file scan by Virus Total or Jotti.
- Do you see any changes in computer behavior?
Thanks,
pgmigg
Failure to post replies within 72 hours will result in this thread being closed
No problem following instructions, links requested have been posted
Hello mantgar,
Your latest set of logs appear to be clean!
This is my general post for when your logs show no more signs of malware.
Before I give you instructions how to keep your computer clean and secure, you need to make a few additional steps.
Step 1.
OTL - Run Script
You should still have OTL on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
Step 2.
OTL-Cleanup
You should still have OTL on your desktop.
Step 3.
Hide Hidden and System files
Step 4.
Please download delfix and save it to your desktop.
Then:
Finally:
Please click HERE to find a short guide to staying safer online.
Please don't hesitate to ask any additional questions.
Stay Safe!
pgmigg
Your latest set of logs appear to be clean!
This is my general post for when your logs show no more signs of malware.
Before I give you instructions how to keep your computer clean and secure, you need to make a few additional steps.
Step 1.
OTL - Run Script
You should still have OTL on your desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Copy and Paste the following code into the
text box.
(Do not include the words Code: Select all - instead of it please click the Select all button next to Code: to select the entire script.)
:Commands
[CREATERESTOREPOINT]
:Files
C:\Users\mbmnb\AppData\Local\Ivzgsoft\mDNSResponder.dll
C:\Users\mbmnb\AppData\Local\Onlics\kgmjaxslpalvgn.dll
C:\Users\mbmnb\Downloads\Zwinky.exe
C:\Windows\Installer\172a0a5.msi
:Commands
[EMPTYTEMP]
[CLEARALLRESTOREPOINTS]
- Click under the Custom Scan/Fixes box and paste the copied text.
- Click the Run Fix button. If prompted... click OK.
- OTL may ask to reboot the machine. Please do so if asked.
Step 2.
OTL-Cleanup
You should still have OTL on your desktop.
- Right click on OTL.exe, select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
- Press the CleanUp button.
- When done, you will be prompted to reboot your system to finish file removal, please select OK to reboot your computer.
Step 3.
Hide Hidden and System files
- Close all programs so that you are at your desktop.
- Press
. - Click the Start Search box on the Start Menu
- Copy and paste the following value, in the open text entry box:
change search options for files and folders - Click on the View tab, then under the "Hidden files and folders" section
- UNSELECT "Show hidden files and folders"
- Place check mark in check box "Hide extensions for known file types"
- Place check mark in check box "Hide protected operating system files"
- Press the Apply, then the OK buttons.
Step 4.
Please download delfix and save it to your desktop.
- Right-click on delfix.exe and select " Run as administrator " to run it.
- Check the following boxes then click on Run.
- Activate UAC
- Remove disinfection tools
- Create registry backup
- Reset system settings
- All tools we used to clean your computer should be gone now.
- You can now delete any tools/logs we used if they remain on your computer.
Then:
- Please don't forget to enable and update all your defense software!
Finally:
Please click HERE to find a short guide to staying safer online.
Please don't hesitate to ask any additional questions.
Stay Safe!
pgmigg