Infected computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Recruit, Feb 1, 2013.

  1. Recruit

    Recruit Private E-2

    Some background information before we start: I'm using a network that has usually at least 3 computers connected to it, as well as 1 or 2 cellphones sometimes. Some days ago we got a new wi-fi modem and were wrongly using WPA-PSK instead of WPA2-PSK, we kept using WPA (which is surprisingly easy to hack into) for 2 or 3 days before noticing it and switching to WPA2.

    The infection was noticed yesterday. Some hours prior I used TOR Browser to download files from a WikiLeaks Mirror and then switched to normal browsing. Later our network was lost due to a storm and I went to check said files, then internet came back and as soon as it came the PC started freezing, it became really slow and using the task manager I noticed a certain svchosted.exe

    Using internet to check it up I saw it was related to a certain Worm.Skopvel, a backdoor capable of downloading files, switching off antivirus and firewall, contacting IPs, and will start itself when initiating the computer. The page also stated that this virus can, and will try to, spread through other computers in the network. Using CCleaner I found out there was a startup entry at C:\Users\Danilo\AppData\Roaming\svchosted.exe for a program called ncservice32 (it started with a 'n' and finished as 'service32' but I'm not sure this is the exact name). I finished the process and also deleted further processes at the task Manager that I wasn't sure about, they were cvtres.exe and two instances of taskeng.exe. Right after finishing the processes my computer came back to its normal speed. I also deleted the svchosted.exe manually. Before deleting it I noticed its properties said it had been created at January 4th and last modified at January 2th, as well as last executed January 2th. I have no idea what to make out of this but if said times are true then the virus had nothing to do with the WikiLeaks files since I first checked those yesterday, due to its properties of spreading through the network I believe someone else must've gotten the virus in their PCs beforehand and then it got to mine.

    I thought I was done with the virus by then but decided to check further and found a winini.exe at C:\Users\Danilo\AppData, Googleing it I found a thread in this same forum where someone was asking for help related to a certain winini.exe. I decided to delete the file manually and later used CCleaner to scan the registry and fix all issues (in the hopes of eliminating any startup-related entry). The only issue found was a Invalid File Reference at: HKLM\SYSTEM\CurrentControlSet\services\009093135965865mcinstcleanup

    with the following data in it:
    ImagePath - c:\windows\temp\009093~1.exe - cleanup -molog

    Again thinking I was done and only expecting to confirm this I decided to run your READ and RUN ME FIRST. Downloaded all the files and started scanning.

    I have McAfee antivirus and firewall.

    RogueKiller

    It'll make the pre-scan but when I click to make the normal scan it'll stop working while 'Searching in SERVICE', I tried it twice and it stoppped working both times while performing this same function. It'll search in SERVICE for some seconds and then stop, so I don't know if the problem is in SERVICE or at the next thing it was supposed to scan. I renamed it to rg.exe and tried to scan a third time and got the same error as before so I went to the next step. I'm uploading its debug.log as the last attachment, I'm afraid it's not the log you wanted but it shows where it stopped working, it seems the last file it scanned before halting was related to my antivirus, I've opted not to disable it for the time being.

    Malwarebytes Anti-Malware

    Made 2 detections and apparently deleted both. I believed those were the viruses stoping the RogueKiller from running so tried to make another scan and it failed a fourth time. The detections were:

    C:\Windows\crss.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

    HKCU\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.

    TDSSKiller

    Uneventful, found nothing.

    HitmanPro

    When I first opened it there was no text, I opened the settings window and could see the check boxes but there was nothing written at their side. I tried to emulate the checks from your images and run it nonetheless but then I noticed that there were only 4 tabs at the top, unlike in your images where there were a Proxy and an Advanced tabs. I switched from my local language to English and since I needed the Advanced to continue I closed HitmanPro and tried to open it by pressing the left-ctrl and clicking at the icon twice. At 3rd attempt (6th click) I got a memory dump Blue Screen of Death and PC rebooted. I tried opening it with the left-ctrl pressed once again and it opened at first, there were no warnings about some process trying to block it though. The text was also appearing and I had both 5th and 6th tabs. I don't know wether the text problems before were result of language selection or lack of memory nor I know if the BSOD was caused by a virus.

    I scanned and it found a virus (winini.exe, the same one I had manually removed beforehand, coincidentally or not this one is also from January 4th and apparently from a certain redbot crack which I swear have nothing to do with :p) and a tracer (from Softonic). I ignored both as requested, they are still within my computer.

    MGtools

    Made the scan but forgot to open it as Administrator, so once it fiished I did it a second time as Administrator. I have both logs saved here but will only upload the second one for the time being.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-scan with Hitman and have it fix what it finds. Then reboot and re-scan and attach the new log. Then see if you can run Roguekiller.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds