Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 03-05-2009, 02:19 PM   #1 (permalink)
Broken In
 
Join Date: Nov 2006
Posts: 131
Default regsvr.exe rosource drainer


dear friends,
off lately my cpu usage is showing 100% always when I havn't installed any big software and antivirus.
when I go to task manager>processes i find two regsvr.exe image name eating away around 100% of the cpu usage. As a result of this my lappy works very slow, even if it has a 2gb RAM.
pls help to get rid of the problem
ritish is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 03-05-2009, 05:20 PM   #2 (permalink)
Overlord v2.0
 
alexanderthegreat's Avatar
 
Join Date: Dec 2006
Location: ICA Headquarters
Posts: 369
Default Re: regsvr.exe rosource drainer

That might be a virus. In most cases it is a trojan masquerading as the regsvr32.exe. On the other hand, sometimes, it may be launched by an innocent program running in the background. I recommend that you post a hijackthis log.
__________________
The Only quote worth quoting: "E Loboa!!! What man???
Forum Rules:http://www.thinkdigit.com/forum/announcement.php?f=16&a=1

Disclaimer:No offence meant to ANYONE!
alexanderthegreat is offline  
Old 03-05-2009, 06:52 PM   #3 (permalink)
Broken In
 
Join Date: Nov 2006
Posts: 131
Default Re: regsvr.exe rosource drainer

the hijackthis log:-
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:47:16 PM, on 5/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\VistaDrive\VistaDrive.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Philips\SA19XX\Philips Device Manager\Bin\DeviceManager.exe
C:\WINDOWS\system32\28463\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Zoom Player\zplayer.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://shyam.com.np/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = shyam.com.np
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\system32\wscript.exe C:\WINDOWS\system32\VirusRemoval.vbs
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [VistaDrive] C:\WINDOWS\VistaDrive\VistaDrive.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [PhilipsDM\SA1916] C:\Program Files\Philips\SA19XX\Philips Device Manager\Bin\DeviceManager.exe OS_STARTUP
O4 - HKLM\..\Run: [svchost Agent] C:\WINDOWS\system32\28463\svchost.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Msn Messsenger] C:\WINDOWS\system32\regsvr.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{87878BBE-DD03-4F5E-AE6B-C1BB689C2BFC}: NameServer = 203.187.217.203 203.187.215.35
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

--
End of file - 4690 bytes
ritish is offline  
Old 03-05-2009, 07:25 PM   #4 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: regsvr.exe rosource drainer

Analyse your Hijack this log file here: http://www.hijackthis.de/ You can see there are some unknown/nasty processes running on your system

Have a Full Scan with Updated Definition using: http://www.superantispyware.com/download.html

Do report back
__________________
- MrinTech :)
mrintech is offline  
Old 03-05-2009, 07:28 PM   #5 (permalink)
Overlord v2.0
 
alexanderthegreat's Avatar
 
Join Date: Dec 2006
Location: ICA Headquarters
Posts: 369
Default Re: regsvr.exe rosource drainer

Those two 'regsvr.exe's are not listed in the Running Processes list. Nevertheless, they might have been executed by MSN messenger or Zoom Player.

However, what caught my attention were these two lines:-
Quote:
C:\WINDOWS\system32\28463\svchost.exe
and
O4 - HKLM\..\Run: [svchost Agent] C:\WINDOWS\system32\28463\svchost.exe
'svchost.exe' is a Windows process which exists in the System32 folder, not the System32\28463\ folder. You'd better fix this in HijackThis. Try to delete this file manually (NOT the System32 one! Delete the System32\28463\svchost.exe file). After that, run a virus scan.

About your regsvr.exe problem, search for regsvr.exe on your PC. Delete all instances which are not present in the C:\Windows\System32 folder. Also, scan the one present in C:Windows\System32 folder with a good antivirus.

If all is clean, try to exit MSN messenger and Zoom Player and then check the task manager for any remaining 'regsvr.exe' precesses.

One more thing, this seems weird:-
Quote:
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\system32\wscript.exe C:\WINDOWS\system32\VirusRemoval.vbs
Check your startup list. I reckon you might find a few surprises. Oh, and upgrade to SP3! It's more secure.
__________________
The Only quote worth quoting: "E Loboa!!! What man???
Forum Rules:http://www.thinkdigit.com/forum/announcement.php?f=16&a=1

Disclaimer:No offence meant to ANYONE!

Last edited by alexanderthegreat; 03-05-2009 at 07:34 PM.
alexanderthegreat is offline  
Old 03-05-2009, 08:05 PM   #6 (permalink)
Call me D_J!
 
Disc_Junkie's Avatar
 
Join Date: Nov 2008
Location: INDIA
Posts: 866
Default Re: regsvr.exe rosource drainer

Yes, it's malware!! You should ckeck the drives with Malwarebytes Antimalware and Trojan Remover! Also delete the autorun.inf files in the partitions if there is any!!

Trojan Remover: www.softpedia.com/get/Antivirus/Trojan-Remover.shtml

Malwarebytes Antimalware: www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html
__________________
ASUS K42JA-VX032D RAWKS !!!!!!:grin:
Disc_Junkie is offline  
Old 03-05-2009, 08:10 PM   #7 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: regsvr.exe rosource drainer

Quote:
Originally Posted by Disc_Junkie View Post
Yes, it's malware!! You should ckeck the drives with Malwarebytes Antimalware and Trojan Remover! Also delete the autorun.inf files in the partitions if there is any!!
You forgot Noob Killer
__________________
- MrinTech :)
mrintech is offline  
Old 03-05-2009, 08:26 PM   #8 (permalink)
Call me D_J!
 
Disc_Junkie's Avatar
 
Join Date: Nov 2008
Location: INDIA
Posts: 866
Default Re: regsvr.exe rosource drainer

Quote:
Originally Posted by mrintech View Post
You forgot Noob Killer
I have stopped promoting it!!
__________________
ASUS K42JA-VX032D RAWKS !!!!!!:grin:
Disc_Junkie is offline  
Old 03-05-2009, 11:18 PM   #9 (permalink)
Broken In
 
Join Date: Nov 2006
Posts: 131
Default Re: regsvr.exe rosource drainer

the two regsvr.exe is not showing in hijackthis tool becoz I hav deleted the two images by ending the processes. Now when I am doing a search for regsvr.exe no search search result found shows. But on restart it again comes..
ritish is offline  
Old 03-05-2009, 11:21 PM   #10 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: regsvr.exe rosource drainer

Have you scanned your computer????
__________________
- MrinTech :)
mrintech is offline  
Old 03-05-2009, 11:31 PM   #11 (permalink)
Broken In
 
Join Date: Nov 2006
Posts: 131
Default Re: regsvr.exe rosource drainer

pls suggest which antivirus to use for scanning
ritish is offline  
Old 03-05-2009, 11:33 PM   #12 (permalink)
Wise Old Mouse
 
mrintech's Avatar
 
Join Date: Sep 2005
Location: Bhopal, India
Posts: 1,930
Default Re: regsvr.exe rosource drainer

http://www.superantispyware.com/download.html

Update it to latest definition and than go for full scan. Do report back after scan
__________________
- MrinTech :)
mrintech is offline  
Old 03-05-2009, 11:53 PM   #13 (permalink)
silentFOX
 
mittyr's Avatar
 
Join Date: Jun 2008
Posts: 113
Default Re: regsvr.exe rosource drainer

@ritish

The geniune file is "Regsvr32.exe"

If you are not getting startup errors like "Windows cannot find regsvr.exe" or errors in startup of any other programs, its fine.

"Trojan Remover" was a good suggestion. Hard to get past its boot-time scan. If you still got problem after scan suggest you give it a try.
mittyr is offline  
Old 04-05-2009, 08:57 AM   #14 (permalink)
Call me D_J!
 
Disc_Junkie's Avatar
 
Join Date: Nov 2008
Location: INDIA
Posts: 866
Default Re: regsvr.exe rosource drainer

If nothing works, try to block it with the help of a firewall!!
__________________
ASUS K42JA-VX032D RAWKS !!!!!!:grin:
Disc_Junkie is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by gohan89
- by icebags

Advertisement




All times are GMT +5.5. The time now is 07:51 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2