Avast WEBforum

Other => Viruses and worms => Topic started by: demontosome26 on March 07, 2013, 04:49:37 PM

Title: Win32 Injector Infection
Post by: demontosome26 on March 07, 2013, 04:49:37 PM
I ran a scan recently and found that I was infected with what's known as an Injector virus.  I can't recall what the full name of the file was, but in the scan logs it has it listed under "C:\WINDOWS\system32\MCSysUtil.dll".  It will not let me delete it, repair it, or even send it to the chest.  What steps should I take from here? 
Title: Re: Win32 Injector Infection
Post by: true indian on March 07, 2013, 05:03:02 PM
upload the file to www.virustotal.com

and post the link to the results here.

it could be a possible false alarm..
Title: Re: Win32 Injector Infection
Post by: Pondus on March 07, 2013, 07:09:12 PM
What is mcsysutil.dll doing on my computer?
http://www.processlibrary.com/directory/files/mcsysutil/404347/
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 05:39:08 AM
I tried using virustotal but I couldn't find the file.  I even went about searching for it through the windows search setting and still nothing.  The post Pondus posted asked me to run Speedupmypc, but I have CCleaner and I always run the registry cleaner, so what else is recommended?
Title: Re: Win32 Injector Infection
Post by: Pondus on March 09, 2013, 09:46:35 AM
Quote
The post Pondus posted asked me to run Speedupmypc
i gave you info about the file

Quote
mcsysutil.dll is a Manna System Utility belonging to Metamail from Metamail Corp
something you know?

Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 05:12:59 PM
Of course and I read all of the information that link listed, but it recommended I do a scan with SpeedUpMyPC, which I doubt will resolve my issue.  At least I would assume that since I already use CCleaner on a daily basis to search for Registry Errors and as a clean up utility.  I tend to do all the necessary steps to keep my laptop up to speed including checking for bad sectors through properties on drive C: (once a month).  Maybe I deleted a registry that was needed?

I'll await any instructions that are needed for me to move further with my issue.  Thank you all for your time.
Title: Re: Win32 Injector Infection
Post by: Pondus on March 09, 2013, 05:22:36 PM
Quote
SpeedUpMyPC, which I doubt will resolve my issue.
it is just an ad as many of these websites have
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 05:40:11 PM
That may be a false positive, could you upload to Avast as an FP
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 06:30:17 PM
Hello essexboy, I remember you helping me out in the past and resolving my problem, so it's nice to see that you're still around.  How exactly would I go about uploading it to avast as a False Positive?  Would that be the same as submitting the file to the virus lab?
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 06:39:00 PM
Yep just the same, are you running V7 or V8 of Avast

V8 .. Go to support and select report file
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 07:28:52 PM
I'm using the most recent version of Avast and I went ahead and submitted it through the virus chest instead.  I have no clue how it's in the chest if it said it couldn't be moved there, but it's there now.
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 07:41:37 PM
Rescan it from the chest tomorrow and see if it still reports it.  Has the removal affected any of your programmes at all ?
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 07:44:49 PM
Not that I have noticed, but once again my laptop is starting to run a lot slower than usual.  I had recently uninstalled advanced system care and replaced it with CCleaner with the advise of a member on here, which seemed to have corrected my speed issue for a while. 
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 07:47:14 PM
I can have a quick looksee if you wish
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 10:10:04 PM
Sure, just let me know what you need me to provide you.
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 10:12:04 PM
OK lets start with OTL initially

Download OTL (http://oldtimer.geekstogo.com/OTL.exe)  to your Desktop
Secondary link  (http://www.itxassociates.com/OT-Tools/OTL.exe)
(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)

netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
winsock.*
/md5stop
CREATERESTOREPOINT


Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 09, 2013, 11:31:31 PM
posted
Title: Re: Win32 Injector Infection
Post by: essexboy on March 09, 2013, 11:49:07 PM
The logs look nice and clean .. Are you experiencing any problems ?
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 10, 2013, 12:26:35 AM
I've just noticed the laptop being real slow no matter what I'm doing on it.  Other then that I haven't seen any other problems.
Title: Re: Win32 Injector Infection
Post by: essexboy on March 10, 2013, 12:35:52 PM
Clear Cache/Temp Files
Download TFC by OldTimer (http://oldtimer.geekstogo.com/TFC.exe) to your desktop
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 10, 2013, 09:42:34 PM
I scanned the file again today like you asked of me and the result still read "MCSysUtil.dll   Win32:Injector - AZQ [Trj]".  I also ran the program TFC, so I'll let you know if I start noticing a difference in my system.  Thanks for your assistance as usual, essexboy.
Title: Re: Win32 Injector Infection
Post by: essexboy on March 10, 2013, 09:50:19 PM
OK lets see where that file is

(https://dl.dropbox.com/u/73555776/OTL_Main_Tutorial.gif)

netsvcs
/md5start
MCSysUtil.* 
/md5stop
CREATERESTOREPOINT


Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 10, 2013, 10:41:06 PM
posted
Title: Re: Win32 Injector Infection
Post by: essexboy on March 10, 2013, 11:00:55 PM
Intriguing, what location does Avast say it is in ?
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 10, 2013, 11:08:10 PM
"C:\WINDOWS\system32" for Original Location.
Title: Re: Win32 Injector Infection
Post by: essexboy on March 10, 2013, 11:13:12 PM
Is it in the chest now ?
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 10, 2013, 11:19:26 PM
Yes sir.  At first it told me it couldn't be moved to the chest, deleted, or fixed, but later when I opened Avast I found it in there. 
Title: Re: Win32 Injector Infection
Post by: essexboy on March 10, 2013, 11:29:50 PM
Leave it there for now and check it again in a bout a weeks time

Although metamail appears to be a Linux programme
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 12, 2013, 02:14:27 AM
I'll let you know, essexboy.
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 16, 2013, 05:23:29 PM
I ran a scan on the file today and it came back with "MCSysUtil -no virus-".  I'm assuming that means it's safe, so should I restore the file?
Title: Re: Win32 Injector Infection
Post by: essexboy on March 16, 2013, 05:37:39 PM
If you need it then restore it.  But if you have experienced no problems then you can leave it there
Title: Re: Win32 Injector Infection
Post by: demontosome26 on March 17, 2013, 03:19:12 AM
Alright, I'll leave it there for now and if I see any issues I'll post an update on here.
Title: Re: Win32 Injector Infection
Post by: demontosome26 on April 09, 2013, 06:35:46 AM
Update: No virus has been detected lately, but my laptop is still running extremely slow.  I clean all of my computer history using Ccleaner once a day, defragment once a month, and scan for viruses at least once a week, but the problem still continues.  What should I do from here?
Title: Re: Win32 Injector Infection
Post by: essexboy on April 09, 2013, 04:21:32 PM
You only have 500Mb of RAM on an XP machine, which is borderline
However, there are a lot of start up programmes. 
Try reducing these to the ones you actually need :
Quote
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\Toshiba\E-KEY\CeEKey.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HWSetup] C:\Program Files\TOSHIBA\TOSHIBA Applet\HWSetup.exe (TOSHIBA CO.,LTD.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe (Intel Corporation)
O4 - HKLM..\Run: [LXBXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.DLL ()
O4 - HKLM..\Run: [PadTouch] C:\Program Files\Toshiba\Touch and Launch\PadExe.exe (TOSHIBA)
O4 - HKLM..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\Toshiba\Windows Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [TCtryIOHook] C:\WINDOWS\System32\TCtrlIOHook.exe (TOSHIBA)
O4 - HKLM..\Run: [TDispVol] C:\WINDOWS\System32\TDispVol.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TFncKy] TFncKy.exe File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\Toshiba\TouchPad\TPTray.exe (COMPAL ELECTRONIC INC.)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
Title: Re: Win32 Injector Infection
Post by: demontosome26 on April 10, 2013, 05:43:59 AM
I'm familiar with computer software, but only to a certain degree.  Which ones would you recommend I disable from start up?  I can always reverse the process, so that's not an issue.  Ccleaner also has easy access when it comes to disabling and enabling start up programs.
Title: Re: Win32 Injector Infection
Post by: essexboy on April 10, 2013, 02:47:09 PM
I would recommend that as you are using CC that you temporarily disable all bar Avast

Then reboot and see which other ones you need to re-enable to get the elements you require running

Probably touchpad and intel wireless
Title: Re: Win32 Injector Infection
Post by: demontosome26 on April 15, 2013, 07:05:33 AM
I disabled just about everything minus 6 programs, which include Avast.  So far things have been working a lot better for the last few days. 
Title: Re: Win32 Injector Infection
Post by: essexboy on April 15, 2013, 03:28:17 PM
Run OTL and press the cleanup button to remove it and its associated files  ;D