Reply
Contributor
oaryajiv2002
Posts: 13
Registered: ‎08-10-2009
Accepted Solution

Multiple viruses-svchost.exe, infostealer, hacktool rootkit

I have Symantec antivirus corporate edition (provided by my school) and am having some virus problems. It started a couple months ago. I believe the virus was names hacktool rootkit or something of the nature. There were hundreds of them and Symantec kept on catching them, but it seemed like they were being created faster than they could be caught. Then the infostealer virus started. For a while I had both bothering me and Symantec couldn't stop it. After lots and lots of scans, those 2 problems have been cleaned (or Symantec isn't finding them anymore). Now I have a svchost.exe virus. Symantec doesn't notice it.  I found out by opening my task manager to find hundreds of processes running. When I start my computer I have around 50 processes running. If I leave my computer on, hundreds of svchost.exe processes form (the number slowly increases). I have tried solutions found on various forums, but they have not worked. If you think you can help, please do so.
delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Hi Oaryajiv2002:

 

We may need to eventually send you over to the corporate forum, but for now:

 

Please run a SysProt log for us so we can check your system for rootkit activity. You will need to disable Norton auto-protect while you run the scan.

Once it is downloaded to your desktop, right click on the SysProt icon, go to properties, and click unblock and apply.

Choose log, check all the boxes except show hidden objects only and scan.

You will be able to post the log here using the "add attachments" link just below the orange post button.

http://homepages.slingshot.co.nz/~crutches/SysProt

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Contributor
oaryajiv2002
Posts: 13
Registered: ‎08-10-2009

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Hello Delphinium,

 

Thanks for helping. Attached is the log you requested. Also, since you told me to disable Norton, I remembered another problem. Every once in a while, Norton auto protect is disabled. When I see that, I simply right click the logo on the bottom right of my computer and re-enable it. I don't know if this helps, but its something else I have noticed.

 

Thanks again for the help.

 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

oaryajiv2002:

 

You have a SKYNET rootkit infection.  I will advise Quads, who is our malware specialist.  Follow his instructions as he makes them available to you.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain
Contributor
oaryajiv2002
Posts: 13
Registered: ‎08-10-2009

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

I appreciate the quick reply. Once I remove that virus, will the other problems (Infostealer and svchost.exe) go away?

 

Thank you very much for the help.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Hi

 

 

1.  Download Combofix  to your Desktop, http://www.bleepingcomputer.com/combofix/how-to-use-combofix

 

Don't use yet.

 

2. I have Personal Messaged you the script between the lines, look for the yellow envelope at the upper right hand side.   Copy the Script.

 

3.  Open Notepad and paste it in to notepad with the first line being killall::

 

4. Save the script as "CFScript.txt"       CFScript.txt is what you see on your desktop after saving.

 

5. Disable Nortons Auto-Protect and Firewall.

 

6.  Drag and drop CFScript.txt on top of Combofix.exe, like when you drop files into the recycle bin.

 

7. Combofix will start,  When it is scanning don't move the mouse cursor inside the box, can cause freezing.

 

Combofix will create a log at the finish

 

 

Quads 

Contributor
oaryajiv2002
Posts: 13
Registered: ‎08-10-2009

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Thanks for the help. Attached is the log. Also if the hacktool rootkit problem is now gone, the svchost.exe problem is still there and I am not sure if the infostealer problem has been fixed. 

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Ok

 

Now download, Install, Update (update tab) the definitions, then run a FULL scan with Malwarebytes  http://www.filehippo.com/download_malwarebytes_anti_malware/

 

Quads 

Contributor
oaryajiv2002
Posts: 13
Registered: ‎08-10-2009

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

Here is the log that I saved. I removed the 2 trojans detected. Even though these trojans were removed, the folders that they were kept in (for example the one that starts with C:\Qoobox...) still remain. When going through I also noticed multiple folders with absurd names such as "1a9d9276ff6d7b9a0fac07" and "5d65c60d6c6b922bf62d6b1ecab8" in my C drive. There are 7 of these crazily named folders. I don't know if this is normal, but its something I saw.

 

Thanks for the continued help.

 

oaryajiv2002 

delphinium
Posts: 9,680
Kudos: 2,855
Solutions: 282
Registered: ‎11-21-2008

Re: Multiple viruses-svchost.exe, infostealer, hacktool rootkit

I think if you disable your system restore, that will get rid of that one file.  The other one is in the combofix quarantine, Qoobox.

 

Quads will have a look at the others.

Under certain circumstances profanity provides relief denied even to prayer.
Mark Twain