Stubborn Malware, mysterious

Discussion in 'Malware Help (A Specialist Will Reply)' started by egafx, Aug 14, 2009.

  1. egafx

    egafx Private E-2

    Hi I'm having a problem on my XP SP3 computer here, I think the malware have infected my system files (I expect svchost.exe) because of following symptoms:

    When its the "time" (the malware starts up)
    -theres some "Open Program" sound (because I've set a sound for the "Open Program" and "Close Program" event.
    -followed by a virus alert by NAV2003 that there is a BN5.tmp or anything that is detected as "Packed.Generic.233"
    -After that, a total of 5 SvcHost.exe (1 Local, 2 Network, 2 System) becomes 8 now, with 3 addition in System.
    -I don't know but I think the malware has done something with wmiprvse.exe and wmiadap.exe because they are more often executed now.
    -There is a registry entry in "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run", a string named Regedit32 containing "C:\WINDOWS\system32\regedit.exe" that is kept getting written whenever I delete it.
    -A glimpse of regedit.exe processed during start up is identified, I wonder why is regedit.exe run during start up? but when I delete the regedit.exe the attack still occurs (then I restored the regedit.exe).

    Here are some info:
    -theres no regedit.exe in System32 (checked with cmd.exe too) even after "the time"
    -there is no suspicious files or programs running (at least I can't find any) I only am curious about the svchost.exe because recently, I've cleared all the msword98.exe, braviax.exe, etc.

    "The time" occurs after some minutes delay from starting the operating system, and as far as I know, it occurs only when the network adapter (I mean the Internet) is connected, but I haven't make sure enough.

    The network is currently very busy sending and receiving data but I don't know what is it doing. (The LAN computer icon). I hope its just Windows Update running.

    I need some help, but do I need any more information here? I've searched so many forums but never found problem like this, usually I just found obvious malware attacks which are clearly identifiable and are able to be solved. In my case, I don't know where does the BN5.tmp come from.
     
  2. egafx

    egafx Private E-2

    oh ya I forgot to tell,

    about "the time", it also delayed to occur when I start enabling network adapter (enabling the Internet). But I'm still 80% sure that the malware is caused by the Internet connection.

    May be the malware that I expect resides in SvcHost.exe needs my Internet connection so "the time" occurs when Internet is available.
     
  3. egafx

    egafx Private E-2

    New info: SvcHost.exe is neutral I think, have cross-checked with other computer's SvcHost.exe. I have compared some system files and I found my services.exe MD5 is different!
     
  4. egafx

    egafx Private E-2

    Follow-up

    About services.exe, yes they are different to each other in MD5 sum but has same version; I'm using the 'normal' services.exe now.

    I left my computer on today for work, with the net cable unplugged and even the network adapter disabled. No attack! no more SvcHost.exe is running (total still 5)

    I disabled every service run under the file "SvcHost.exe" and enabled the network adapter and plugged the cable too; no attack! :cool:cool only I can't log into Yahoo! Messenger..
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Note, the more you post, the longer it takes to get an answer. See this sticky thread: Don't Bump! It Only Hurts You!!!


    Please follow the instructions in the READ & RUN ME FIRST link given futher down and attach the requested logs when you finish these instructions.
    • If you have problems where no tools seem to run, please try following the steps given in the below and then continue on no matter what you find. You only need to try the TDSSserv steps if having problems getting scans in the Read & Run Me First. If TDSSserv is not found, just continue on with the READ & RUN ME.
    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  6. egafx

    egafx Private E-2

    fixed!

    nevermind, no more problems now after some immediate windows auto-update patches (around 7 critical patches suddenly showed up).

    those arent bumping anyway, I have read the rules; only I didnt realize I should've used Edit Post feature, not posting New Reply; sorry.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: fixed!

    Glad to hear you resolved your problems.

    Just for furture reference, every post you make is a bump to the previous post since it changes your position in the work queue. It does not matter whether you are intentionally bumping or adding new info. Basically you at least increase you waiting time by the difference in time between the posts. So for example, below are your first 4 post times with comments indicating the effect

    08-14-09 20:47 << initial post into queue
    08-14-09 20:50 << bump queue position backwards by 3 minutes (no big deal)
    08-14-09 21:06 << bump initial queue position backwards 29 minutes (also not to big a deal for you unless very impatient)
    08-15-09 07:34 << bump initial queue position backwards 10 hrs and 47 minutes ( potentially a big deal to you )

    I think this illustrates what happens. Potentially if someone keeps bumping, they may never get an answer.
     
  8. egafx

    egafx Private E-2

    figures..

    yes I should have used edit post right.. didn't realize the bumping thing is technically analyzed.

    Well as a conclusion I could give.. "ensure windowsupdate is updating your Windows to the most current" :D
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Posts can only be edited for 5 minutes and then they are locked to maintain original info.

    There is no technical analysis. It is just how queues work just like on phone lines when you call in for tech support when you get the next available operator. If you hang up, you have start your waiting time again from the end of the queue. This is exactly what a bump (any additional message) does.

    Yes which is why it is the first step in the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds