svchost.exe/Windows Update/Web Redirection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by mpizzo10, Nov 25, 2010.

Thread Status:
Not open for further replies.
  1. mpizzo10

    mpizzo10 Private E-2

    Been having a lot of trouble with a PC. Almost a month ago, this PC was severely infected with a virus that called itself Antivirus8. I thought I had gotten rid of all the infections. There were times when I couldnt go to the Windows Update website, as the infection seemed to block me from getting there. I had that problem fixed, and now I am back to being unable to access the Windows Update website.

    I am wondering if it is related to another issue I have with the PC. I have seen the following error several times: "generic host process for win32 services has encountered a problem and needs to close". Also, svchost.exe will take up nearly 100% of the CPU for long periods of time.



    I received an error report (details shown in photo attached). I googled svchost.exe and the other file mentioned in the error report (ntdll.dll) in the same search. I found a bunch of forums/sites with other's troubles and solutions with the same problem I am having. Apparently, windows addressed this in one of their updates. Also, many state that the issue is related to svchost.exe trying to access updates and it is unable to. There are several suggestions by people, and I am hesitant to choose which to do, especially since most are around 3 years old. One solution suggests to run ComboFix. I wanted to run it, but ComboFix indicates that AntiVir, AOL Antivirus, and AVG need to be disabled. Antivir and AVG have been uninstalled, and I have no idea where AOL Antivirus is. I don't understand why ComboFix sees them as running processes.

    One final thing, while surfing the web, there are times when I will be redirected against my will. Also, very recently, my homepage of IE was changed to msn.com (not by choice).

    If possible, I could really use some help with this.
     

    Attached Files:

  2. mpizzo10

    mpizzo10 Private E-2

    Here is a photo of the error I receive.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    You are out of date with your version of SUPERAntiSpyware.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this new log.


    Now download TDSSKiller from Kaspersky to your directly onto your Desktop
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
    Now shutdown Online Armor and Microsoft Security Essentials and run ComboFix. Try to run it even if it tells you that any antivirus programs are active.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now you must put your PC into normal Startup Mode with MSconfig as was requested in step 4 of the READ & RUN ME. Please do this now. This is part of the reason ComboFix was detecting AOL protection. You hadMcAfee services, AV8, and lots of other junk trapped in there which the above fix with Avenger tried to correct.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Nov 26, 2010
  4. mpizzo10

    mpizzo10 Private E-2

    PC seems to be running a bit better now. I was able to access Windows Updates. In the short time since applying your directions, it seems I am not being redirected and svchost.exe isnt acting up.

    I have attached the requested log files. What makes me somewhat nervous is how many errors occurred during Avenger.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's my fault. I reversed the commands by mistake which cause this. Not a problem as some were automatically fixed anyway by ComboFix and some we will fix with the below.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. mpizzo10

    mpizzo10 Private E-2

    PC seems to be running fine. Though, I haven't done much except follow your instructions.

    Here are the logs you requested. ComboFix still saw those anti-virus programs (AVG, Antivir, AOL) as running processes however.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but the last fix corrected that now.;)

    Your logs are clean.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  8. mpizzo10

    mpizzo10 Private E-2

    I hope you don't mind me reviving this thread. My issue with IE being redirected has resurfaced. MSE has detected WIN32/FakeXPA twice in the past week. What makes me nervous is that the file was located in the folder for Antivirus 8, the malware that seemed to have start this problem two months ago.

    Since I am helping a friend with this, I wasn't present when the problem resurfaced, so I am unsure what happened to bring the issue back.

    Here is the information MSE provided me the two times it was found:

    (First time)
    Items:
    file:C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP18\A0002107.exe
    folder:C:\Program Files\av8\

    (Second time)
    Items:
    file:C:\Documents and Settings\Mario Graziano\Local Settings\Temporary Internet Files\Content.IE5\XF3YD3YJ\securityav_2013_br8[1].exe
    file:C:\Program Files\av8\av8.exe
    folder:C:\Program Files\av8\

    I also have attached the log of an MBAM scan I ran after MSE. I am going to wait for directions before proceeding with any other scans (ie Super Anti-Spyware). MBAM found 5 infections.
     

    Attached Files:

  9. mpizzo10

    mpizzo10 Private E-2

    Update: When I ran MSE and it detected the virus, IE was still being redirected. After my last post, MBAM (after the scan that caught 5 infections) prompted me to reboot. After the reboot, I am now surfing without redirection.

    I am going to tell the owner of the PC to hold off on using it until I hear from you (or someone else here). I have a feeling my fix was superficial, but what do I know. That's why I'm posting here ;).

    (Thank you, by the way).
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes we do. This is not the same problem. It is a new infection or a reinfection that occurred by repeating whatever you previously did to get infected. And your thread was completed a little over a month ago now. Even after 2 weeks we would need you to start over. So please run the READ & RUN ME from beginning to end and attach new logs in a new thread. This thread will be closed now.
     
Thread Status:
Not open for further replies.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds