mbam chameleon stops on clbcatq.dll, amidst general paranoia

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Aplabos, Mar 25, 2014.

  1. Aplabos

    Aplabos Private E-2

    Hello!
    So, I've been freshening up my computer and I decided, just for good measure, to go about my upkeep in safe mode w/ networking.

    For one thing my computer is usually in excellent shape, but there's always a part of me that suspects I've got a particularly well hidden something or other lurking ever so sneakily in the bowels of my PC. I've exhausted my capabilities, and google isn't helping, so I decided to get some real backup from someone who knows how to tango. Honestly I'm not sure what I'm on the lookout for, beit malware or trojan or anything else sinister. On a day to day basis, there is nothing glaringly obvious that worries me; only after I start my upkeep do I notice things that don't seem to line up with the norm.

    Most/all? of the following programs' active services are obv disabled in safe mode.

    Some quick deets:
    -Running Windows 7 Home Premium 64 bit - UAC is off.
    -16gb of RAM, of which atm (in safe mode) 3.54 gb are in use.
    -At any given time I have at least four instances of svchost running, currently looking at eight. Three under SYSTEM, three under LOCAL SERVICE, and two under NETWORK SERVICE.

    Based on my limited knowledge of netstat -o -f -b nothing stood out, but there were a few things I couldn't identify.

    By now, I've gone through all the scanning processes with the below programs in and out of safe mode, so the coast seems clear as far as they can reach.

    Programs used for upkeep:
    -CCleaner - I'll admit I use the registry cleaner fairly often, mainly after uninstalls and the like. After reading this site's main go-to post for problem solving, I'm wondering if my check boxes for the cleaner and registry are as they should be. Currently, this program has nothing to show from analysis.

    -Spybot S&D 1.6.2 - Lately I've been using this to handle a few startup programs. Two instances of "sidebar" and two "mctadmin" are the most recent things I've disabled. I believe I usually have TeaTimer and SDhelper active most of the time. While in safe mode, I decided to undo the "immunization" feature entirely, with the plan of reapplying it once I'm confident all is well. Scans currently turn up nothing.

    -TDSSkiller - With all option boxes checked, it hasn't found me a thing.

    -SuperAntiSpyware pro trial with real time protection on. The various types of scans (not including the "rescue scan") are over and done with. Only turning up standard tracking cookies by now.

    -Malwarebytes - Pro trial, real time protection on. Scans done with and without Chameleon seem clear by now. The most recent attempts with Chameleon have stopped on CLBCATQ.DLL located in C:\Windows\SYSWOW64 at which point it waits to time out, or I attempt to confirm the cancel command attempt and it sits there uselessly stuck, not necessarily frozen.

    -Mbam Anti Rootkit - Found me nothing.

    -Mbam Anti Exploit - Intended unless you think it's uneeded.

    -Microsoft Security Essentials - Meh, when is it ever helpful? I'm not sure if this has a firewall of its own, if so it may be up. Real time protection is usually on. No scan finds.

    -OTL - Ran once, did nothing with the log.

    -AVAST - Pro trial w/ internet security, web shield, file system shield, mail shield, antispam and firewall up. While AFK yesterday, it stopped a download attempt of an svchost.exe as it was deemed "very new or very rare." The svchost.exe location seemed normal enough, the file was an am_delta_patch of sorts, the source of which is apparently the normal download.windowsupdate.com/msdownload (etc) site address. I remain unconvinced of its secure nature.

    Recent peculiar events - random Conime.exe, two csrss running under SERVICES, four clr_optimizations running

    Other programs used if at all relevant and you're still reading: Search Everything, Windows disc cleanup, MyDefrag, System Explorer, WinDirStat, Should I Remove It w/ background feature, Windows firewall active and recently set back to defaults to close all unused gaming ports.

    Many many thanks for your patience here. I'm at my wits end.
    Recap of my main concerns, what's the scoop with that CLBCATQ.dll and Mbams chameleon?
    Avast preventing an svchost download.
    Many svchosts, with one usually running upwards of 250,000 K to 300,000+ K
    These have various labels next to them - (DcomLaunch) (LocalService) (LocalServiceNetworkRestricted) (LocalServiceNoNetwork) (RPCSS) (netsvcs) (NetworkService) - currently safe mode, but it's similar normally.
    Investigating these has and past events seems to turn up other little peculiarities that honestly I've lost track of by now. It's come to the point where I'd like the wisdom of a pro.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    NOTE: You should not have both Avast and Microsoft Security Essentials installed. Only one antivirus program should be installed at any time.

    Questions about this should be posted an Malwarebytes forum. I don't know whyyou are even running Chameleon if MBAM runs okay to begin with.

    Normal.

    If your goal is to determine if your PC is clean, we need you to run the below procedure and attach all the logs we request whether anything if found or not. Since you ran many of the tools already you can attach the log for the scans we requested from what you have but you still need to complete all the steps and attach each log we request at the end.


    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds