Avast WEBforum

Other => Viruses and worms => Topic started by: JaeJaeAgogo on May 04, 2014, 09:34:36 PM

Title: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 04, 2014, 09:34:36 PM
I'm running a legal Windows 8 (Came with the computer when I bought it)

For a few days now, Avast has been constantly blocking files that all came from the same place, but it doesn't show up in scans:
(http://i1065.photobucket.com/albums/u390/JaeJaeAgogo/Svsblocks.jpg)

I've followed the instructions provided by the website to the best of my abilities, though OTL only made one notepad document and aswMBR isn't supported by windows 8?

I've attached the logs the requested logs after following all of the instructions in the sticky threads, I've made no changes to my computer since before the scans.

Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 04, 2014, 09:38:06 PM
Monitoring. Await my reply.
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 04, 2014, 09:48:13 PM
Hi,

Code: [Select]
:Commands
[createrestorepoint]

:OTL
[2014/04/23 17:08:35 | 000,000,000 | --S- | M] () -- C:\windows\SysNative\clsnj.sib
[2014/04/23 12:37:46 | 000,000,028 | ---- | M] () -- C:\windows\SysWow64\u
[2014/04/22 13:08:37 | 000,000,064 | ---- | M] () -- C:\windows\SysNative\mmowwun.phl
[2014/04/22 13:08:37 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\trli.ecr
[2014/04/22 12:52:49 | 000,236,804 | --S- | M] () -- C:\windows\SysNative\wpkwi.kab
[2014/04/26 16:30:25 | 000,000,000 | ---- | M] () -- C:\END
[2014/05/03 18:38:35 | 000,000,066 | ---- | M] () -- C:\windows\SysNative\exowtch.gll

:Files
C:\$Recycle.bin\S-1-5-21-915191271-1565821320-4066514102-1002\$RRFT9EM

:Commands
[emptytemp]





Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 05, 2014, 12:23:28 AM
Sorry to keep you waiting.

After finishing, combofix didn't reboot, but it did open a log, so I saved the log and manually restarted my computer.

Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 05, 2014, 03:09:10 PM
Hi,

Code: [Select]
FCopy::
c:\windows\WinSxS\amd64_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.2.9200.16384_none_c2948360c7a43433\rpcss.dll | c:\windows\system32\rpcss.dll





Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 05, 2014, 11:27:24 PM
Here they are, sorry to be so much trouble.
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 06, 2014, 05:42:35 AM
Hi,

May I ask why you ran Zoek.exe?



Code: [Select]
Start
2014-05-04 16:13 - 2014-05-05 13:44 - 00000069 _____ () C:\windows\system32\exowtch.gll
2014-05-04 16:05 - 2014-05-04 16:05 - 00000027 _____ () C:\windows\SysWOW64\u
2014-05-04 16:02 - 2014-05-04 16:02 - 00000064 _____ () C:\windows\system32\mmowwun.phl
2014-05-01 16:13 - 2014-05-01 16:13 - 01115136 _____ () C:\Users\Jae\Downloads\th12e_patch_1.0 (1).exe
2014-05-01 16:12 - 2014-05-01 16:13 - 01115136 _____ () C:\Users\Jae\Downloads\th12e_patch_1.0.exe
2014-04-23 17:08 - 2014-04-23 17:08 - 00000000 ____S () C:\windows\system32\clsnj.sib
2014-04-22 13:08 - 2014-04-22 13:08 - 00000000 _____ () C:\windows\system32\trli.ecr
2014-04-22 12:52 - 2014-04-22 12:52 - 00236804 ____S () C:\windows\system32\wpkwi.kab
Reboot:
End



Re-run FRST and click on Scan. Attach the log after the scan. In addition, attach the following file as well : C:\zoek-results.log and C:\zoek-results2014-04-24-203103.log.

I implore you not to run any fix tools unless asked.



Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 06, 2014, 08:00:50 AM
Is there a way for Zoek to scan automatically? The only time I used it was before coming here for help, so I apologize if it scanned afterwards.
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 06, 2014, 08:28:40 AM
Hi,

You should not run these programs (zoek, OTL, FRST, ComboFix et cetera) without supervision. They are designed for manual removal and in most cases they will carry out any commands given to them. In you are not experienced, there is a good change of a dreadful occurrence. How is your system running?

Pando Media Booster Advice:

I see you Pando Media Booster installed, maybe intentionally and or came with one of your installed games for example. Technically this type of software is based upon peer to peer technology and you can never really be sure what it is purportedly downloading is always safe. Plus it does not always make that much of a improvement with downloading.

My friendly advice is if you do not really use it, merely uninstall. However this is choice to do so or not and end of the day I respect whomever I assist with what they wish to have installed on their respective machines.











Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 06, 2014, 09:58:47 AM
Alright, I've followed your instructions and here are the logs. I also uninstalled the programs with poor reputations and Pando Media Booster.

My system is running fine. Fortunately, nothing was messed up from running Zoek. I'm definitely not touching them again without someone experienced, though.
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 06, 2014, 10:06:23 AM
Hi,





Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 07, 2014, 04:10:27 PM
ESET found quite a few things. The log was very long, did you still want it copy and pasted?

Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 07, 2014, 05:11:27 PM
Hi,

How is your system running?



Uninstall the following --

Code: [Select]
Start
C:\Program Files (x86)\Web Layers
C:\Users\Jae\AppData\Local\CRE\banjjklfojcdbofbhbgiedekefohoaff.crx
C:\Users\Jae\Desktop\Adobe Photoshop CS4 + Keygen
C:\Users\Jae\Downloads\Adobe Photoshop CS4 + Keygen.rar
C:\Users\Jae\Downloads\Audacity.exe
C:\Users\Jae\Downloads\cbsidlm-cbsi145-Hamster_Free_Video_Converter-SEO-75218449.exe
C:\Users\Jae\Downloads\cbsidlm-tr1_14-SMRecorder-ORG-75332290.exe
C:\Users\Jae\Downloads\FreeWAVToMP3Converter.zip
C:\Users\Jae\Downloads\RealPlayer.exe
C:\Users\Jae\Downloads\Setup_FreeVideoPlayer.exe
C:\Users\Jae\Downloads\smconverter_installer.exe
C:\Users\Jae\Downloads\smrecorder_installer.exe
C:\Users\Jae\Downloads\FreeWAVToMP3Converter
C:\Users\Jae\Pictures\ccsetup405.exe
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\banjjklfojcdbofbhbgiedekefohoaff\10.22.0.593_0\TBHostSupport
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghdomkkcnldpmfcefiaaahchgoinofkb\1.0.0_0\background.js
C:\Windows\System32\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghdomkkcnldpmfcefiaaahchgoinofkb\1.0.0_0\content.js
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\co[1].htm
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\co[2].htm
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\co[3].htm
Reboot:
End



Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 07, 2014, 05:43:31 PM
My system is running better (no lagging, stalling or processes taking longer than they should to start) and I haven't seen the infection notice from Avast for at least a day.

I've removed Web Layers as instructed.
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 07, 2014, 07:13:59 PM
Perusing your logs, I see no infection currently present in your system. Unless you are having any issue(s), the machine appears to be Malware-free as we speak.



♣ Removal of Tools and Quarantined Files ♣



Despite the tools we have used are clean, they are powerful removal tools and made in a way so that they carry out any commands given to them without (most cases) asking for a confirmation. In the hands of an inept person, they can make the machine un-bootable -- a scenario we do not wish to see. Also, we need to remove the quarantined files/folders from your system as a dormant malware can be as bad as an active one if given the proper environment. I shall now give you the guidelines to remove the tools and the quarantined files from your system.



♣ Prevention and Future Guidelines ♣



Prevention is better than cure -- goes the old saying. As much as we love to see you visit our site, we do not want to see you having your PC infected by malwares again.

Regards,
Valinorum
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 07, 2014, 11:27:06 PM
# DelFix v10.7 - Logfile created 07/05/2014 at 17:22:40
# Updated 27/04/2014 by Xplode
# Username : Jae - JUSTICE
# Operating System : Windows 8  (64 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Qoobox
Deleted : C:\_OTL
Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\TDSSKiller_Quarantine
Deleted : C:\AdwCleaner
Deleted : C:\Users\Jae\Desktop\mbar
Deleted : C:\ComboFix.txt
Deleted : C:\TDSSKiller.2.8.16.0_24.04.2014_15.01.38_log.txt
Deleted : C:\TDSSKiller.3.0.0.33_24.04.2014_15.02.52_log.txt
Deleted : C:\zoek-results.log
Deleted : C:\zoek-results2014-04-24-203103.log
Deleted : C:\Users\Jae\Desktop\Addition.txt
Deleted : C:\Users\Jae\Desktop\adwcleaner.exe
Deleted : C:\Users\Jae\Desktop\AdwCleaner[S1].txt
Deleted : C:\Users\Jae\Desktop\ComboFix.exe
Deleted : C:\Users\Jae\Desktop\esetsmartinstaller_enu.exe
Deleted : C:\Users\Jae\Desktop\Fixlog.txt
Deleted : C:\Users\Jae\Desktop\FRST.txt
Deleted : C:\Users\Jae\Desktop\FRST1.txt
Deleted : C:\Users\Jae\Desktop\FRST64.exe
Deleted : C:\Users\Jae\Desktop\JRT.exe
Deleted : C:\Users\Jae\Desktop\JRT.txt
Deleted : C:\Users\Jae\Desktop\logfile.txt
Deleted : C:\Users\Jae\Desktop\OTLrecent.Txt
Deleted : C:\Users\Jae\Desktop\Rkill.txt
Deleted : C:\Users\Jae\Desktop\Shortcut.txt
Deleted : C:\Users\Jae\Downloads\aswMBR.exe
Deleted : C:\Users\Jae\Downloads\logfile.txt
Deleted : C:\Users\Jae\Downloads\OTL.Txt
Deleted : C:\Users\Jae\Downloads\OTL.exe
Deleted : C:\Users\Jae\Downloads\tdsskiller.exe
Deleted : C:\Users\Jae\Downloads\tdsskiller.zip
Deleted : C:\Users\Jae\Downloads\zoek.exe
Deleted : C:\windows\grep.exe
Deleted : C:\windows\PEV.exe
Deleted : C:\windows\NIRCMD.exe
Deleted : C:\windows\MBR.exe
Deleted : C:\windows\SED.exe
Deleted : C:\windows\SWREG.exe
Deleted : C:\windows\SWSC.exe
Deleted : C:\windows\SWXCACLS.exe
Deleted : C:\windows\Zip.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #101 [OTL Restore Point - 5/3/2014 6:45:23 PM | 05/03/2014 22:45:27]
Deleted : RP #102 [ComboFix created restore point | 05/05/2014 17:48:52]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
Title: Re: Svchost.exe is infected.
Post by: Valinorum on May 08, 2014, 06:14:21 AM
Browse safely. Adieu. :)
Title: Re: Svchost.exe is infected.
Post by: JaeJaeAgogo on May 08, 2014, 09:23:19 AM
Thank you for everything, Valinorum!