Evening! Or morning! Or afternoon!
I'll try to make this quick: I believe that my Svchost.exe program is infected with... something. I want to fix that, naturally. That's why I've gathered you here today.
I need help in one, possibly two things:
1. I need to confirm that Svchost is indeed infected
2. If it is, I need to fix it.
To start my report, I noticed that Svchost was showing up in my Volume Mixer (sometimes multiple times. I counted 8 once). I looked it up, got RogueKiller, and it was just as suspicious about them as I was. Problem is, RogueKiller is the only thing that seems to agree with me. Both MalwareBytes and Search&Destroy find nothing wrong with the process. I'm convinced that there is something seriously wrong with the process (By the way, the duplicate processes always come from my SysWOW64 folder instead of System32.). RogueKiller doesn't seem to have an option to repair the process directly, and I don't know what programs that might fix it are trustworthy. I've included the log from RogueKiller below, and await response from the people who know what they're doing ;3
-------------------------------Report Start-----------------------------------
RogueKiller V9.2.8.0 [Jul 11 2014] by Adlice Software
mail :
http://www.adlice.com/contact/Feedback :
http://forum.adlice.comWebsite :
http://www.adlice.com/softwares/roguekiller/Blog :
http://www.adlice.comOperating System : Windows 7 (6.1.7600 ) 64 bits version
Started in : Normal mode
User : Chance [Admin rights]
Mode : Scan -- Date : 08/23/2014 15:06:07
¤¤¤ Bad processes : 8 ¤¤¤
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\System32\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
[Proc.Svchost] svchost.exe -- C:\Windows\SysWOW64\svchost.exe
¤¤¤ Registry Entries : 14 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-3144317477-4014965747-2316806996-1000\Software\Microsoft\Windows\CurrentVersion\Run | {a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a} : "C:\Users\Chance\AppData\Local\Microsoft\{a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a}\{a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a}.exe" -> FOUND
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-3144317477-4014965747-2316806996-1000\Software\Microsoft\Windows\CurrentVersion\Run | {a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a} : "C:\Users\Chance\AppData\Local\Microsoft\{a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a}\{a7eb9183-ccb7-45b8-0b88-e2dea5f0b23a}.exe" -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BRDriver64 -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BRSptSvc -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BRDriver64 -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\BRSptSvc -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\BRDriver64 -> FOUND
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\BRSptSvc -> FOUND
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> FOUND
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> FOUND
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> FOUND
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-3144317477-4014965747-2316806996-1000\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> FOUND
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-3144317477-4014965747-2316806996-1000\Software\Microsoft\Internet Explorer\Main | Start Page : about:blank -> FOUND
¤¤¤ Scheduled tasks : 0 ¤¤¤
¤¤¤ Files : 0 ¤¤¤
¤¤¤ HOSTS File : 0 ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: NOT LOADED [0xc000036b]) ¤¤¤
¤¤¤ Web browsers : 2 ¤¤¤
[PUP][FIREFX:Addon] s8byd29d.default : AVG SafeGuard toolbar [avg@toolbar] -> FOUND
[PUM.HomePage][FIREFX:Config] s8byd29d.default : user_pref("browser.startup.homepage", "
https://www.facebook.com/"); -> FOUND
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 51b7d81bad15e8869e96d8007a24f089
[BSP] b0ea3820aba664f00220477c1b486de8 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 114471 MB
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive1: +++++
--- User ---
[MBR] cacfbcf88b90eda8895c15004f3d0bdb
[BSP] d3bcfa80b85a2d6fdd1f130f549fd199 : Windows Vista/7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 1907627 MB
User = LL1 ... OK
User = LL2 ... OK
============================================
RKreport_SCN_08232014_141446.log - RKreport_DEL_08232014_141554.log
----------------------------------------Report End---------------------------------------
Sincerely,
Cat