conhost and PresentationHost virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by titanium13, Jun 1, 2015.

Thread Status:
Not open for further replies.
  1. titanium13

    titanium13 Private E-2

    Hi,
    I was infected with the conhost.exe and PresentationHost.exe virus yesterday and ran the attached scans. The computer CPU usage is running near or at 100% usage and the computer is very sluggish.
    Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove all that it finds.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    How are things running?
     
  3. titanium13

    titanium13 Private E-2

    I ran HitmanPro and JRT to remove the infected files.

    Same problem. After I boot up, it runs okay for about 5 minutes. Then the CPU starts to bounce up to 100%. I see that the virus is launching notepad.exe as well in the Task manager. PresentationHost.exe is using 25 of the CPU.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any signs of virus.....

    Please download Combofix to your desktop. Please refer to these instructions prior to running. Attach log once done.
     
  5. titanium13

    titanium13 Private E-2

    I ran Combofix. It rebooted during the process, which I'm not sure whether it's normal. I had Avira Antivirus turned off but when it rebooted, it turned back on by default and I turned it off again. Also, after it rebooted, I got an error box saying " C:\windows\system32\GfxUI.exe A device attached to the system is not functioning."
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    OutfoxTvService
    
    DirLook::
    c:\windows\SysWow64\008D~1
    c:\windows\SysWow64\)7388~1
    c:\windows\SysWow64\2A7C~1
    c:\windows\SysWow64\2E37~1
    c:\windows\SysWow64\F884~1
    c:\windows\SysWow64\B26E~1
    c:\windows\SysWow64\4C3A~1
    c:\windows\SysWow64\7B05~1
    
    Folder::
    c:\program files\OutfoxTV
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
     
  7. titanium13

    titanium13 Private E-2

    I ran Combofix again. Computer is still running at very high CPU usage.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\windows\SysWow64\008D~1
    c:\windows\SysWow64\)7388~1
    c:\windows\SysWow64\2A7C~1
    c:\windows\SysWow64\2E37~1
    c:\windows\SysWow64\F884~1
    c:\windows\SysWow64\B26E~1
    c:\windows\SysWow64\4C3A~1
    c:\windows\SysWow64\7B05~1
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    What actual malware problems are you currently having because I'm not seeing anything apart from a few bits and what Hitman removed.... :confused
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @Kestrel, I suggest that you run a check with FRST for Poweliks just to be sure it is not found even though nothing showed in RogueKiller.

    If no Poweliks, I have to then question that I observe two instances of MS Installer running? Why is it running at all unless something was being installed.
    Check new logs from MGtools.
     
    Last edited: Jun 5, 2015
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.


    Also do this please.... Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  11. titanium13

    titanium13 Private E-2

    The malware problem I'm having is that conhost.exe and presentationhost.exe is using up a huge chunk of CPU and it bounces up to 100% and the fans kick in. It will settle down after a while but then repeat the process.

    Chaslang mentioned MS Installer. I just checked in Windows Task Manager and saw two instances of the installer open. Then a new one would pop up. It is up to six now with three using a combined 75% CPU. Nothing is being installed right now and the only thing open is the browser window to type this.
     

    Attached Files:

    Last edited: Jun 5, 2015
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.


    Download Fixlist.txt

    Save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Please attach the above two log first before you continue with the below.
    Also at this point, I want you run another scan with FRST like in my last message and attach the new FRST.txt and Addition.txt logs.
     

    Attached Files:

  13. titanium13

    titanium13 Private E-2

    FRST64.exe ran nearly instantaneously and it didn't reboot. I manually rebooted.

    Attached Fixlog.txt and MGlogs.zip.
     

    Attached Files:

  14. titanium13

    titanium13 Private E-2

    FRST and Addition logs attached.
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Describe how things are running.
     
  16. titanium13

    titanium13 Private E-2

    It is running normal now. Thanks!
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Excellent :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds