Infected with Whistler / Black internet

I can remove that folder for you- and to give you peace of mind I will run one additional tool

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

 
[Unregister Dlls]
[Files/Folders - Created Within 30 Days]
NY ->  Winnydows -> C:\Program Files\Winnydows
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

Depending on what the fix contains, this process may take some time and your desktop icons might disappear or other uncommon behavior may occur.

This is no sign of malfunction, do not panic!

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.

As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.

http://img.photobucket.com/albums/v706/ried7/RC1.png

[*]Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/RC2-1.png

[*]Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Here is the log. I don’t know if this is related but i came back to my pc today and websites were informing me that i didn’t have flash installed, but i know for a fact i did so i went into add/remove programs and they weren’t there. They just uninstalled themselves so i went to the adobe site and downloaded flash again and i got a file that said the company name was “Solid State Networks”. Anyway i’ve started a thread at adobe forums for that. Running combofix now. Thanks.

All Processes Killed
[Files/Folders - Created Within 30 Days]
C:\Program Files\Winnydows folder moved successfully.
[Empty Temp Folders]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Youngie
->Temp folder emptied: 33593144 bytes
->Temporary Internet Files folder emptied: 1048978 bytes
->Java cache emptied: 190334 bytes
->FireFox cache emptied: 55436231 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 1717 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2402044 bytes
%systemroot%\System32 .tmp files removed: 26129 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 20297 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 89.00 mb

[EMPTYFLASH]

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: Youngie
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore point Set: OTS Restore Point (0)
< End of fix log >
OTS by OldTimer - Version 3.1.44.0 fix logfile created on 07312011_141044

Files\Folders moved on Reboot…
File\Folder C:\WINDOWS\temp_avast_\Webshlock.txt not found!

Registry entries deleted on Reboot…

Not overly impressed with that company http://www.solidstatenetworks.com/index.php/products/

Me neither never even heard of them, do you think this looks dodgy? And that flash has seemed to have uninstalled itself?

http://i51.tinypic.com/28bsehe.jpg

Here is combofix log when i ran it it said there was an update for combofix and shall i update, i said no cos i wasn’t sure, and i can’t remember exactly what it said but it was something like i have an alternative version of the recovery console that might need updating.

Do you play online games ?

Could you re-run combofix and allow it to update please

Next combofix log. I don’t play any online games my brother plays facebook games sometimes but not for a while, that file i got from get.adobe.com/flashplayer.

It appears to be related in some way to MP3 files used in online gaming - as to why I am not sure, but if it was installed via the adobe site then it should be legit… What are your current problems ?

Like i said in my first post i haven’t really been having any problems that i can speak of apart from svchost.exe trying to recieve incoming connections about 5 times a minute is my main one and all the searching i’ve done hasn’t been able to explain why. I guess i will just keep it unplugged til i can get a new one if you really think i have nothing to worry about?
And thanks alot for your help it really is appreciated. Cheers.

I can see no apparent malware, does the alert state what file is using svchost ?

No i got an alert from comodo that svchost.exe was trying to recieve a connection from the internet so i blocked it, now when i go into comodo and look at the logs it’s just got svchost.exe listed as a blocked event from 100 to 1000 a day. Outgoing i could understand but i could not find any answers as to why it would be incoming so i blocked it. I think i’m just being paranoid cos i uploaded the file to virustotal and it was clean but better to be safe and all that.

So it is incoming - that is totally illogical ???

I think the source is my default gateway and the destination is my pc whatever that means.

Edit: 16382 times in the last month sometimes UDP sometimes TCP, same destination port the source port is tried 7 times then moves up 1, always same IP.

http://i52.tinypic.com/1zqcas9.jpg

Can i just ask as well what does “detected NTDLL code modification” “ZwClose” mean? Thanks.

To me like essexboy, that doesn’t make sense either, as this is giving svchost.exe as the application but the blocking as inbound. Masking the destination IP, etc. doesn’t aid investigation.

Generally this inbound connection would have an associated outbound connection for any inbound connection to be for a local file.

So I think filtering this on only inbound/blocked connections may be giving a misleading impression.

What should i change the policy to?

I don’t think it is a case of changing policy, but seeing all results and not just those blocked.

Virtually all outbound connections will have an associated inbound connection, so to make sense of this, there should be an outbound connection from svchost.exe at very close to the same time.

By looking at the associated outbound connection can you get an idea of what is going on. The svchost.exe file has legit reasons for making an outbound connection and the more most common is connecting to windows update.

I don’t use comodo, so I can’t help with its settings.

I’ve set it to allow and log outgoing. It is connecting to the IP address of my dns server and 1 to 255.255.255.255 from the IP address of my PC, on the incoming the source is the IP of my default gateway and the destination is the IP address of my PC. I really, really don’t understand what any of this means it’s just from looking at the comodo log and the support tab of the LAN Status in sys tray. So do you think i should just unblock it?

As I said I’m really not familiar with comodo and I don’t know why you chosen those settings.

My firewall Outpost Firewall Pro, I have virtually left it on default settings other than it runs a rules wizard and that would ask me about outbound connections where the application isn’t white listed, etc. I certainly wouldn’t set it to allow and log outbound connections as that essentially would let anything out, good or bad.

No I don’t know if that is what you meant or not, but my advice would be don’t set rules that you don’t know what the expected results are going to be. For the most part firewalls do reasonably well on their default settings. Though comodo if/when combined with defence+ might be a bit noisy (constantly asking questions about processes/connections).

So I only hope there is a comodo user than can give you some guidance on this.

So you are telling me that i should allow incoming connections to my computer when i don’t know what they are?

The source gateway on that mask will be your router - reset Comodo to it’s default settings ( I have never used it so I do not know what they are)