Svchost Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by safetydave, Sep 2, 2012.

  1. safetydave

    safetydave Private E-2

    Hello
    Windows 7 PC
    3 user profiles
    Malwarebytes continues to id svchost trojan multiple times each day
    Encounter random blue screens
    Hijack This would not show hosts files

    Appreciate your help

    Safetydave
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. safetydave

    safetydave Private E-2

    Kestrel13!
    Thanks for your reminder
    TDSSKILLER found nothing
    Ran Ccleaner after running Hitman Pro
    Seems Hitman Pro found some issues
     
  4. safetydave

    safetydave Private E-2

    Attachments did not post to last post
     
  5. safetydave

    safetydave Private E-2

    Sorry about files not being attached
     

    Attached Files:

  6. safetydave

    safetydave Private E-2

    I seem to have confused rkill with roguekiller previously
    I have now attached a roguekiller log
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Your Background Intelligent Transfer Service has stopped and needs to be corrected but first - malware removal.

    Uninstall the below software: (junk)
    • My Faster PC

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;*.local
    • R3 - URLSearchHook: (no name) - {1c68c940-1b2f-46eb-bd8c-2e1612ff6a58} - (no file)
    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    After clicking Fix exit HJT.

    Delete these folders:
    • C:\Program Files (x86)\Conduit
    • C:\Program Files (x86)\FixCleaner
    • C:\Program Files (x86)\Qwiklinx
    • C:\Program Files (x86)\Playbryte
    • C:\Program Files (x86)\SearchAmong Toolbar
    • C:\Program Files (x86)\Shop To Win
    • C:\Program Files (x86)\Shop to Win 12
    • C:\Program Files (x86)\SMPlayer
    • C:\Program Files (x86)\VIO Player
    • C:\Program Files (x86)\WhiteSmoke_US


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Files/Folder tab and locate these 4 detections:
    • [ZeroAccess][FOLDER] L : C:\Windows\Installer\{b194a004-f4e3-6533-890c-e5749412ea02}\L --> FOUND
    • [ZeroAccess][FILE] @ : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\L --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    • Reboot the machine.
    • Re run RogueKiller - no fix, just a scan and attach log.
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. safetydave

    safetydave Private E-2

    Kestrel13!
    Thank you for reviewing my email!
    Deleted Faster PC

    Used MGtools\analyse.exe to delete the following

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1:9421;*.local
    R3 - URLSearchHook: (no name) - {1c68c940-1b2f-46eb-bd8c-2e1612ff6a58} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)


    Deleted these folders:

    C:\Program Files (x86)\Conduit
    C:\Program Files (x86)\FixCleaner
    C:\Program Files (x86)\Qwiklinx
    C:\Program Files (x86)\Playbryte
    C:\Program Files (x86)\SearchAmong Toolbar
    C:\Program Files (x86)\Shop To Win
    C:\Program Files (x86)\Shop to Win 12
    C:\Program Files (x86)\SMPlayer
    C:\Program Files (x86)\VIO Player
    C:\Program Files (x86)\WhiteSmoke_US

    Had success merging the following in the registry
    REGEDIT4

    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DA2287BC-51DD-46AE-803A-368D640ADD20}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{BFE680F5-69D4-4A76-A974-C15503F8F00B}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{BFE680F5-69D4-4A76-A974-C15503F8F00B}]

    Deleted the following with Roguekiller not to be confused with rkill

    [ZeroAccess][FOLDER] L : C:\Windows\Installer\{b194a004-f4e3-6533-890c-e5749412ea02}\L --> FOUND
    [ZeroAccess][FILE] @ : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\@ --> FOUND
    [ZeroAccess][FOLDER] U : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\U --> FOUND
    [ZeroAccess][FOLDER] L : C:\Users\spike\AppData\Local\{b194a004-f4e3-6533-890c-e5749412ea02}\L --> FOUND


    Ran Roguekiller again, but forgot to delete an older Roguekiller log so the attached logs are named one digit out of sequence

    Ran MGtools\GetLogs.bat and attached MGlogs.zip

    Felt good to delete those files!

    Gratefully
    Safetydave
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download the below file to your desktop

    BITS.reg


    • Now please click Start, and type regedit into the search box.
    • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
    • Right click on regedit.exe and select Run As Administrator
    • Then in the Registry Editor menu click File and select Import.
    • Navigate to the BITS.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

    Reboot the machine.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
    Last edited: Sep 7, 2012
  10. safetydave

    safetydave Private E-2

    Kestrel13!
    thank you
    Despite UAC and antivirus sw disabled cannot download BITS.reg
    Computer cancels the download every time

    in your instructions did you mean to say

    Navigate to the BITS.reg not BFE.reg file saved to your Desktop and double click it. Allow it to be added to the registry

    I am getting a lot of high memory usage warnings from the attached svchost*32

    Gratefully
    Safetydave
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try downloading this zip then. Unzip it and try again. Yes, sorry I meant BITS not BFE ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds