Pending Windows 7 - winrscmde and google redirects

Discussion in 'Virus, Spyware and Malware Removal' started by orma, Jul 4, 2012.


  1. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    I have looked around and tried things to no avail. This is my last option of hope to ask for help here.

    Recently I discovered this fake scvhost running with the description "winrscmde" hogging memory. I have enough memory for it to not really effect me, but it does effect the startup time. It is also running multiple scvhosts.

    I have also been experiencing google redirects for quite a while now and wouldn't mind tackling that while I'm here.

    I have tried to system restore, but I keep getting an error that an anti-virus is not allowing it to run, so I disabled all anti-virus software and it still did not work.

    I was encountering blue-screens on start-ups, until I disabled all start-up programs.

    Attached Files:

  2. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    Hello.

    Please download ComboFix [IMG] from BleepingComputer.com

    Alternate link: GeeksToGo.com


    Rename ComboFix.exe to commy.exe before you save it to your Desktop
    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
    • Click Start then copy paste the following command into the search box & hit enter: "%userprofile%\desktop\commy.exe" /stepdel
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. This will not install in Vista. Just continue scanning, and skip the console install.
    • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.
  3. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    This is a nightmare. I ran combofix and now my internet wont connect. It is saying no internet access. Also my services.exe is taking up great amounts of memory. 3gigs and growing.

    All of this crazyness shows up under task manager when I have the show all users processes box checked. What could this mean? Im the only user. Computer also seems pretty unusable in the current state.
  4. Google Advertisement

  5. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    Can you use an external thumb drive to get the log to another machine with net access? the infection you have is fairly new and quite resilient.
  6. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    Grabbed it through my phone. Here it is. May have to go via thumb drive. Thumb drive it is.

    Attached Files:

  7. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    Hello.
    Do you have your Windows 7 disc? just in case we need to repair any damage.

    Please download TDSSKiller from here and save it to your Desktop.
    • Doubleclick TDSSKiller.exe to run the tool
    • Click the Start Scan button
    • After the scan has finished, click the Close button
    • Click the Report button and copy/paste the contents of it into your next reply
    Note:It will also create a log in the C:\ directory.
  8. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    I don't have a windows 7 disc on hand but here is the tdsskiller log

    Attached Files:

  9. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    Okay that removed the rootkit - can you re-run Combofix please just to make sure the majority of the infection is gone.

    Attach the new log when complete.
  10. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    I can try to rerun combo fix, last time I tried, the sevices.exe took up 13+ gigs of ram and it couldnt really run. Will get back in a bit with results.

    Running it in safe mode seems to be the choice of action here, since whatever it is isnt running.

    Problem still persists

    Attached Files:

  11. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    It's possible this infection has patched services.exe, so that's our next step.

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2
    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      services.exe
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
  12. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    Svchost is also taking a lot of processor memory so I did that one, too.

    Attached Files:

  13. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    That's strange, services.exe isn't in its right place.

    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Check "Include All Files" option.

    • Press "Scan".
      It will create a log (FSS.txt) in the same directory the tool is run.
      Please copy and paste the log to your reply.
  14. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    Here is the text file

    Attached Files:

    • FSS.txt
      File size:
      2.5 KB
      Views:
      5
  15. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,863
    Likes Received:
    902
    My System
    Loading...
    Oh wow, that's sneaky. You may have a new infection here, so were gonna need a bit more information so this can be sent to our developers and experts.

    Submit a file for analysis.
    1. Please visit this website: Jotti's Malware Scanner
    2. Press the "Browse" button and locate the following file in bold:
      C:\WINDOWS\system32\drivers\afd.sys
    3. Press the "Submit File button to submit the file for analysis.
    4. Allow it to be scanned, it could take a few minutes depending on server load.
    5. Copy and paste the result back here.
    DragonMaster Jay likes this.
  16. orma Bronze Member

    Bronze
    Message Count:
    28
    Likes Received:
    0
    My System
    Loading...
    I will have to transfer this file and scan it Im guessing? Did I do this right?

    Transferred and scanned.

    2012-07-06 Found nothing
    2012-07-05 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

    2012-07-06 Found nothing
    2012-07-06 Found nothing

Windows 7 - winrscmde and google redirects