svchost.exe issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by smonster50, Jul 28, 2011.

  1. smonster50

    smonster50 Private E-2

    Ok, I've read multiple threads about this trojan and what exactly the symptoms are and the only issue I am currently having is AntiMalwarebytes is reporting that I have a trojan agent located in the svchost.exe. I remove it and naturally it comes back upon restarting, I actually see a command line prompt loading a program very quickly once my system boots back up. This is really the only thing that seems odd with my computer at the moment. Ive tried looking for the svchost in the task manager processes tab and there is nothing resembling svchost in there. Can someone please tell me if I'm receiving a false positive from Malwarebytes or I actually have a trojan?
    Attached is my most recent scan log from Malwarebytes, any help is very much appreciated. Thanks in advance.
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks

    That can be determined by providing us with the requested logs from running the below:
     
  3. smonster50

    smonster50 Private E-2

    Ok, it took a little while getting everything downloaded and ran properly but things seem to be running smoothly now. Before I ran my first scan (superanti spyware) malwarebytes alerted me to a possibly malicious process trying to run, TESTE.VBS. I just turned malwarebytes back on and no warning yet so I think one of the scans fixed the problem. Attached is the first set of logs.
     

    Attached Files:

  4. smonster50

    smonster50 Private E-2

    Last log is attached. thanks for all your help so far.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.


    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\Justin\desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 1:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Notes:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    *If after running Combofix you discover none of your programs will open up, and you receive the following error: "Illegal operation attempted on a registry key that has been marked for deletion", then you will need to reboot your computer which will normally fix this problem.

    Step 2:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 3:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).
    *Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Please attach the new C:\MGlogs.zip file to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  6. smonster50

    smonster50 Private E-2

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    I actually seem to be malware free at this moment, no issues. Previously upon startup, I would see a script run very quickly as everything was loading into my computer. After the first wave of scans I no longer saw that running. My only concern now is that there isn't still something lurking in the depths, waiting to come out and play.

    Attached are the newest logs.
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'll look over your logs this evening when I return from work.

    dr.m
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Your logs are looking good!

    We'll look even deeper -

    Please download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Please follow the instructions in this link:
    Using ESET's Online Scanner
    NOTE: This scan can take more than an hour, so be patient!

    Then attach the MBRCheck and ESET Scan results logs.

    dr.m
     
  9. smonster50

    smonster50 Private E-2

    Attached are my logs. I had a little trouble with the ESET scan, it stalled on me twice (probably my fault) but I eventually got it to run.
     

    Attached Files:

  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Do you have all important data backed up? You really should do this before continuing since we will need to rewrite your MBR to fix this and while most times this can be done without any problem, these infections can react badly and that could result in a PC not being bootable. You really don't have much choice though since these infections are too dangerous to your security to leave on a PC.

    *Do you have your Windows Vistaâ„¢ Home Premium DVD so that you can get into the Vista System Recovery Environment to repair your MBR?
     
  11. smonster50

    smonster50 Private E-2

    No, I really haven't backed anything up recently other than some of my designs for work, would you recommend that I back everything up? Windows backup assistant or some other method?
    As for the Vista Home premium DVD, I do not have a copy of that since Microsoft has decided to charge people extra for a physical disk....bastards.
    Once started, how long of a process would this be to clean the infections out of my computer? Also what kind of infections am I dealing with?
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    * Regarding your question about data backup:
    You can create the Recovery Environment disc from here:
    http://digiex.net/downloads/download-center-2-0/applications/956-windows-vista-32-bit-x86-recovery-disc.html

    This is a download of an .iso file of just the Recovery Console for Vista 32bit. You can use ImageBurn to create the disc.

    You will need to first boot into the bios and change the boot order to cd/dvd as first boot device. Then insert the disc and reboot. Once you get to the command prompt in the Recovery Console, type fixmbr and hit enter. After it finishes type exit to reboot and remove the CD to allow Windows to boot normally.

    If you were able to run fixmbr, rerun MBRCheck and attach a new log. Also tell me how things are working.
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  14. smonster50

    smonster50 Private E-2

    Ok? Im not quite sure how to accomplish this. I'm thinking what you are talking about is upon boot hit f12 or something along those lines in order to access the boot menu, is this correct?
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Follow the steps below to configure the boot order on most HP computers.
    1. Turn on or restart the computer.
    2. While the display is blank, press the f10 key to enter the BIOS settings menu.
    3. Select the Advanced tab using the right and left arrow keys.
    4. Use the up and down arrow keys to select Boot Order .
    5. Follow the on-screen instructions to change the boot order.
     
  16. smonster50

    smonster50 Private E-2

    Ok, finally got some free time to take care of this step. First of all with an hp vista machine I was able yo just throw my boot CD in the drive and upon reboot it asks you if you want to boot from disk. Which is nice and easy. Secondly once I was into the boot CD I found the command prompt option and opened it up. Now I'm not to familiar with a command prompt window but the first line x:\sources> " and when I type fixmbr I get 'fixmbr' is not recognized as an internal or external command, operable program or batch file. No clue how to get this to run properly.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read all of this message before doing anything.

    You are running Vista, you need to enter the below command:

    bootrec /fixmbr


    Information about the bootrec command can be found here >> http://support.microsoft.com/kb/927392


    HOWEVER, are ou still having problems? Only do the above if your answer is yes.
     
  18. smonster50

    smonster50 Private E-2

    On the surface I would have to say no, but I have noticed that when I wake up every morning my computer is on even though I put it in hibernation mode before I went to sleep. This could be completely unrelated but it seemed weird to me. Also I have been noticing increased boot times on my machine as well. Do you think this warrants completing this step or no?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think it is related.

    No I would not risk running it for either of these issues. Unless you are having redirection issues with search engines or unusual popups or extreme slow downs in all normal operation, I would ignore the "unknown MBR". The slow boot up times are just due to all the unncessary stuff you allow to load at startup. Like the below. Many of which you can probably remove. Depends on whether you really use these or not at each startup of your PC and the answer is probably no.


     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh and just to be safe, please do the below.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Be sure to attach your log from TDSSKiller
     
  21. smonster50

    smonster50 Private E-2

    Got the scan to run the first time around and everything looks on the up and up.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks fine.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds