Malware infection I cannot remove

Hi,

I have a clever malware infection that I can’t remove with avast, malwarebytes, numerous rootkit removers… its just nasty

At first it infected my svchost file under the windows32 directory. Now it has infected a file called PID 528… It continues to call on other websites pulling in further bad items of nastiness.

First here is a snapshot of when Avast blocks its intent to contact the outside world

http://s14.postimg.org/ja5ujre01/infection.png

Avast comes up clean
Malwarebytes comes up clean
TDSSKiller comes up with nothing.

Malwarebytes log here

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 6/05/2015
Scan Time: 6:17:25 PM
Logfile: junk.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.05.06.01
Rootkit Database: v2015.04.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Jim bob

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 465085
Time Elapsed: 26 min, 15 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

hey and welcome to the avast forum

please follow this guide and attach the logs from frst+addtion.

https://forum.avast.com/index.php?topic=53253.0

good luck

Hi, thanks

Here are logs,

hey agian thanks for attaching the needed logs a malware expert will help you one is online.

Hello,

https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

[*]Right-click on
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/51a612a8b27e2-Zoek.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[]Wait patiently until the main console will appear, it may take a minute or two.
[
]In the main box please paste in the following script:

createsrpoint;
autoclean;
emptyalltemp;
bitsadmin /reset /allusers;b
ipconfig /flushdns;b

[*]Make sure that Scan All Users option is checked.
[*]Push Run Script and wait patiently. The scan may take a couple of minutes.
[*]When the scan completes, a zoek-results logfile should open in notepad.
[*]If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.

Hi Argus, thank you for helping with my problem and Mikael, thank you for showing interest in my problem.

I have run Zoek by Smeenk and attached the log.

I think this may have removed the malware but will wait until you confirm.

Re-run zoek and run this script:

bopakagnckmlgajfccecajhnimjiiedh;chr
C:\Users\Jim bob\AppData\Local\Google\Chrome\User Data\Default\Preferences;f
createsrpoint;
autoclean;
emptyalltemp;
bitsadmin /reset /allusers;b
ipconfig /flushdns;b

Post its content into your next reply.

edit.

Just this one fix

Hi Argus,
I have run the new script.

File attached.

Cheers

Is everything ok now?

Hi Argus,

Everything appears ok. Am I virus free now?

Yes.

The following will implement some post-cleanup procedures:

Download DelFix by Xplode and save it to your desktop.

[*]Run the tool by right click on the
http://www.imgdumper.nl/uploads6/51a5ce45267c1/51a5ce45263de-delfix.png
icon and Run as administrator option.
[*]Make sure that these ones are checked:

[]Remove disinfection tools
[
]Purge system restore
[*]Reset system settings

[*]Push Run and wait until the tool completes his work.
All tools we used should be gone. Tool will create an report for you (C:[B]DelFix.txt)

[SIZE=1]The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.

Thank you Argus, this has been a big help. I’ll make a donation to you know.

You Rock

Thank you :slight_smile: