Something might be hidden in my PC!

Discussion in 'Malware Help (A Specialist Will Reply)' started by GBP, Jun 30, 2009.

  1. GBP

    GBP Private E-2

    Hello All and thanks in advance for looking at this. I've been through Read & Run me first and although nothing major was apparently found to my knowledge, I have the feeling that something very hidden is running on my pc. My system is:
    Celeron 1.60GHz, WinXp Home SP3, 2GB RAM

    I'm suspicious especially about an hidden service found by RootRepeal:
    name: fercu
    location: %SystemRoot%\system32\svchost.exe -k netsvcs

    I would be grateful if somebody can have a look at my attached logs.
    Again, thanks.
    GBP.
     

    Attached Files:

  2. GBP

    GBP Private E-2

    The rest of the logs!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes this does look suspicious. Let's go ahead and do this:

    I would suggest that you remove these items from your trusted web sites:
    O15 - Trusted Zone: http://snl.bydeluxe.com
    O15 - Trusted Zone: http://iweb.dgmusa.com

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    NetSvc::
    fercu
    
    File::
    c:\windows\system32\njlgorq.dll
    
    Registry::
    [-HKEY_LOCAL_MACHINE\System\ControlSet001\Services\fercu]
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the prvevious file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip
     
  4. GBP

    GBP Private E-2

    TimW,
    Thanks a lot for your reply. So, I went through your instructions and attached you'll find my new logs. Though, it looks like the suspicious service is still there. I'll be waiting for more information. Do you see anything else from my logs? Also, for your information, O15 - Trusted Zone: http://snl.bydeluxe.com is legit.
    Again, thanks for your time.
    GBP
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I can not find any references to this dll. And it only shows in your Combo logs. Having removed it, and since it returns and seeing no other indications of infections, I would say it is not a malware problem. So without any other symptoms, I would surmise that it is a legit item.

    Tell me if you have any other issues....and in the meantime:
    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. GBP

    GBP Private E-2

    TimW, I also checked around and found myself a bit alone with this dll :) I don't know, my pc is acting strange and that's why I went through all the process to see if there was something wrong. Maybe I should have mentioned before, my mistake, but especially after or during playing a flash movie the PC slows down (any browser) and sometimes I have to switch off and wait few minutes before everything is OK again. I don't think I'm running a lot of stuff and after I upgraded my RAM a while ago to 2GB everything was running smooth. I don't know if this information is important, but if you still think I'm clean I can only say a big thank you for your help. Otherwise let me know.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wasn't seeing anything in your logs to indicate a browser issue. And the problem with flash games should probably be something to address in the software forum.

    However, we can do this and see if any issues are found:

    Using BitDefender Online Scan.
     
  8. GBP

    GBP Private E-2

    Hello again!
    Here my BitDefender log. Some comments about the viruses found: The majority of them were in a backup folder of an old email account, not the actual one. As you can see the other one is, and I assume is a false positive, SmitFraud and one quarantined item by ComboFix. Another comment: I didn't have the option to save the log as .txt but just .html, hope this works. Have a great week-end!
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then I do suggest that you post in the software forum regarding the issue with the flash games. And good luck sorting this out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds