Jump to content

Recommended Posts

Hello yesterday those popups began to appear out of nowhere. MB keeps blocking inbound/outbound connections of svchost.exe.

 

Already checked what information you guys need. Disabled all p2p things and i havent pirated any software so that should be okay. Will post Malwarebytes and TDSSKiller logs asap.

Link to post
Share on other sites

Hello martinz0000 and :welcome:! My name is Borislav and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support. If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.
  • Do not perform any kind of scanning and fixing without my instructions. If you want to proceed on your own, please let me know.
One or more of the identified infections is related to a nasty rootkit component which is difficult to remove. Rootkits and backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums from a CLEAN COMPUTER. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed the computer is now secure. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, delete the partition, reformat and reinstall the Operating System.

Please read:

Should you decide not to follow this advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. If you wish to proceed, disinfection will require more time and more advanced tools.

Please let us know how you would like to proceed.

Link to post
Share on other sites

So i did a os reinstall. After a hour or something the problem appeared again , just a bit different.

First it detected something in qTorrent , so i closed it (Only downloaded some songs and stuff)  After a while it blocked outbound connection of skype.exe. So far looks like svchost.exe is okay. I can do the tdskiller and mbam logs thingy again so we could find what's the cause of this. (OS is a clean one from ms page.)  Anyway check the first detection in protection log , its some kind of temporary file in appdata folder.

 

 

This is the protection log :

Malwarebytes Anti-Malware
www.malwarebytes.org


Error, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, IsLicensed, 13,
Protection, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, Malware Protection, Stopping,
Protection, 02.11.2014. 19:15:59, SYSTEM, HOME, Protection, Malware Protection, Stopped,
Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malware Protection, Starting,
Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malware Protection, Started,
Protection, 02.11.2014. 19:16:05, SYSTEM, HOME, Protection, Malicious Website Protection, Starting,
Protection, 02.11.2014. 19:16:06, SYSTEM, HOME, Protection, Malicious Website Protection, Started,
Update, 02.11.2014. 19:16:09, SYSTEM, HOME, Manual, Rootkit Database, 2014.9.18.1, 2014.11.1.2,
Update, 02.11.2014. 19:16:23, SYSTEM, HOME, Manual, Malware Database, 2014.9.19.5, 2014.11.2.5,
Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Refresh, Starting,
Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Malicious Website Protection, Stopping,
Protection, 02.11.2014. 19:16:23, SYSTEM, HOME, Protection, Malicious Website Protection, Stopped,
Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Refresh, Success,
Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Malicious Website Protection, Starting,
Protection, 02.11.2014. 19:16:27, SYSTEM, HOME, Protection, Malicious Website Protection, Started,
Detection, 02.11.2014. 19:59:30, MÄrtiÅÅ¡, HOME, Protection, Malware Protection, File, PUP.Optional.OpenCandy, C:\Users\MÄrtiÅÅ¡\AppData\Local\Temp\uttCB7F.tmp, Quarantine, [c03dcd69ed8f7cbaed9d4f0e11f427d9]
Detection, 02.11.2014. 20:02:05, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 109.163.226.236, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:02:05, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 109.163.226.236, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:02:34, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:02:34, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:03:36, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 217.23.187.159, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:03:36, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 217.23.187.159, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:03:40, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 188.65.50.47, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:03:41, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 188.65.50.47, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:05:08, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 5.150.195.167, 0427d7.se, 63633, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Detection, 02.11.2014. 20:05:08, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 5.150.195.167, 0427d7.se, 63633, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malware Protection, Starting,
Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malware Protection, Started,
Protection, 02.11.2014. 20:17:43, SYSTEM, HOME, Protection, Malicious Website Protection, Starting,
Protection, 02.11.2014. 20:18:23, SYSTEM, HOME, Protection, Malicious Website Protection, Started,
Detection, 02.11.2014. 20:20:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 20:20:27, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Scan, 02.11.2014. 20:38:01, SYSTEM, HOME, Manual, Start:02.11.2014. 20:20:26, Duration:17 min 34 sec, Threat Scan, Completed, 0 Malware Detections, 0 Non-Malware Detections,
Detection, 02.11.2014. 20:59:24, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60171, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:25, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60171, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60176, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60180, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:26, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60181, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60200, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60200, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60204, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60205, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 20:59:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 60206, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60307, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60308, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60309, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:22, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 60310, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60329, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60330, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60331, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60332, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:00:28, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.188.57.152, 60329, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malware Protection, Starting,
Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malware Protection, Started,
Protection, 02.11.2014. 21:14:19, SYSTEM, HOME, Protection, Malicious Website Protection, Starting,
Protection, 02.11.2014. 21:14:52, SYSTEM, HOME, Protection, Malicious Website Protection, Started,
Detection, 02.11.2014. 21:17:44, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Detection, 02.11.2014. 21:17:44, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 91.212.124.13, 64333, Outbound, C:\Users\MÄrtiÅÅ¡\AppData\Roaming\uTorrent\uTorrent.exe,
Update, 02.11.2014. 21:26:15, SYSTEM, HOME, Manual, Malware Database, 2014.11.2.5, 2014.11.2.6,
Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Refresh, Starting,
Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Malicious Website Protection, Stopping,
Protection, 02.11.2014. 21:26:15, SYSTEM, HOME, Protection, Malicious Website Protection, Stopped,
Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Refresh, Success,
Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Malicious Website Protection, Starting,
Protection, 02.11.2014. 21:26:20, SYSTEM, HOME, Protection, Malicious Website Protection, Started,
Detection, 02.11.2014. 21:29:06, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50336, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:06, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50336, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50338, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50339, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50340, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50341, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.173.168, 50338, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50343, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50344, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:29:07, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 50345, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52562, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52564, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52565, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Detection, 02.11.2014. 21:42:42, SYSTEM, HOME, Protection, Malicious Website Protection, IP, 85.234.172.208, 52566, Outbound, C:\Program Files (x86)\Skype\Phone\Skype.exe,
Scan, 02.11.2014. 21:55:00, SYSTEM, HOME, Manual, Start:02.11.2014. 21:26:15, Duration:28 min 44 sec, Threat Scan, Cancelled, 0 Malware Detections, 0 Non-Malware Detections,

(end)

Link to post
Share on other sites

The main reason for malware infections is p2p software. I'm sure that your problems are two:

1. Installing p2p software and using it.

2. There is malware in your backup. Should be check.

Okay thanks for you help , Will check my backup for malware. Will be still using p2p , can't really stop using that right now when its the only way to watch some tv shows that are not aviable in my country.

Link to post
Share on other sites

  • 3 months later...
  • Root Admin

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.