SVGHost Virus?

Discussion in 'Malware Help (A Specialist Will Reply)' started by ameliorate, May 6, 2013.

  1. ameliorate

    ameliorate Private E-2

    Hi there,

    I've had various problems trying to clean this computer with no luck.

    Could you see if you can help?

    I cleaned up the system and defragged, I ran a CHKDSK and it seemed to burst in to life.

    I found a threat initially with EST and removed it. I ran WWDC and it said the SVGHost was using more memory than it should and have far too many incidents of it running I would think.

    I've run all of the programs and not cured anything, I also ran Rkill and have attached that too.

    The internet is painful again too :( the audio playback has started to jitter on top.

    Thank for any help you can offer :)
     

    Attached Files:

  2. ameliorate

    ameliorate Private E-2

    I ran TDSS Killer too but nothing back in the results, forgot to mention above. Thanks ag
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks! ​


    Your logs are clean. Your performance issues are more likely due to this being an older slower PC type with too little memory. And drive C is getting too low on free disk space. The is quoted from your logs.
    Code:
    Processor x86 Family 15 Model 4 Stepping 1 GenuineIntel ~2527 Mhz 
    Code:
    
    [LEFT]BIOS Version/Date Dell Computer Corporation A00, 15/08/2005
    [LEFT]Total Physical Memory 1,024.00 MB 
    Available Physical Memory 447.64 MB[/LEFT]
     
    [LEFT]Drive C: 
    Description Local Fixed Disk
    Size 34.19 GB (36,709,421,056 bytes) 
    Free Space 6.45 GB (6,926,036,992 bytes)[/LEFT]
    [/LEFT]
    




     
  4. ameliorate

    ameliorate Private E-2

    Hi ya, thanks for that.

    I forgot to menion I tried aswMBR and it kept rebooting the system. So I decided to fixMBR as it wasn't showing as correct. I thought maybe I'd caused a problem and hidden it further using this.

    I realise that it should have another gig to run XP I'm not sure why my friend upgraed it and no longer have a W2000 disk I could use.

    Since the aswMBR the sound card jitters when I scroll in another web page.
    Any ideas, could I have caused a problem somewhere?

    So the Rkill and Rogue Killer logs are a false positive then?
    I've also never had that warning from Windows Worms Door Closer and have used it for a few years now on various machines.

    After I did the cleaning tasks the internet was fine, is there any reason its slowed right down now?
    Should I jusr keep the temp files clean to help it along

    Thanks for your help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah! This is important information. After looking further in relationship to this info, I see a partition on your hard disk the could potentially be a fake partition for an infection. Do you have all important data on your C drive backed up before we attempt to fix this?

    You have the below partitions on this drive and the one in read may be an infection.
    Code:
    Partition Disk #0, Partition #0 
    Partition Size 47.03 MB (49,319,424 bytes) 
    Partition Starting Offset 32,256 bytes 
    Partition Disk #0, Partition #1 
    Partition Size 34.19 GB (36,709,424,640 bytes) 
    Partition Starting Offset 49,351,680 bytes 
    [B][COLOR=red]Partition Disk #0, Partition #2 
    Partition Size 3.00 GB (3,224,309,760 bytes) 
    Partition Starting Offset 36,767,001,600 bytes[/COLOR][/B] 
     
  6. ameliorate

    ameliorate Private E-2

    Just checking everything is backed up, so should be ready whenyou are :0

    Thanks again
     
  7. ameliorate

    ameliorate Private E-2

    Just to let you know I opened another thread last night after losing the hard drive after a chkdsk fix on start up. Took all day and in the end had to go to recovery console, booting from disk to run a chkdsk /r. Left it to run and this morning thankfully windows was all there again. Will go back to thread and let them know potentially there's still an infection

    I've backed up everything and am ready when you are :)

    Thanks again
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay before we attempt to delete that unknown partition ( which I'm still not convinced is even an infected partition ) I want to run two more scans to check status after what you have just run with chkdsk. So please do the below.


    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista, Win7, or Win8 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      activex
      netsvcs
      drives
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      lsass.exe
      nsiproxy.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      tdx.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %allusersprofile%\application data\*.exe
      
    • Now click the Run Scan button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)
    Also please run another scan with RogueKiller and attach the new log.


    Also Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it. Let me know if this asks for the CD.
     
    Last edited: May 11, 2013
  9. ameliorate

    ameliorate Private E-2

    Thanks, sorry for the delay been away a few days and only just home.
    Will get straight on ot that tomorrow when I'm back to normal. :)
     
  10. ameliorate

    ameliorate Private E-2

    Hi ya,
    All scanned as requested, nothing back on sfc /scannow :)
    Look forward to your thoughts, thanks again
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Everything looks fine there too. The more I look at it, the less I think that partition is an issue. I think it is just a factory recovery partition. So I would leave it alone.

    So that brings us back to your performance issues, which I still think is due to your lack of memory, old PC/processor type, limited hard disk space. And also what you are running. Try uninstalling ALL of the below and then reboot:

    AVG 2012
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 39
    Malwarebytes Anti-Malware version 1.75.0.1300
    Viewpoint Media Player


    After reboot, tell me how things are working. Minimize your surfing since not protection is installed now.
     
  12. ameliorate

    ameliorate Private E-2

    Hmmm, I find that so strange that I could do all of those cleaning tasks and the computer seem like new.

    As I say aswMBR kept killing the PC and after fixing the MBR it hasnt been the same.

    The Jave entries have been uninstalled but cant get rid of them out of the programs list.

    If AVG is too big is there something little I could put on there as mainly used by children?
     
  13. ameliorate

    ameliorate Private E-2

    I've uninstalled malware bytes and viewpoint media player. As I say cant get rid of those entries for java even through cc cleaner. However it seems ok today after doing those bits I could.
    So will let the kids back on it.
    Would the free avast s/w be smaller that AVG on there?

    Typically the one I use crashed today, scanned, looks like I have an infection there. Great!

    Is it ok to open another post? I'm happy to donate for the help.

    Thanks and will stop bothering you about this particular machine.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still have any left overs, the below may help:

    Revo Uninstaller 1.94

    Avast or Avira. See the link in my final instructions below.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds