AVG found Crypt.AQLW and subsequent scans found Rootkit.ZeroAccess

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by inteja, Apr 1, 2012.

  1. inteja

    inteja Private E-2

    Hi and thanks for a very helpful forum. I read through all the malware removal instructions and have completed the step-by-step cleaning process (which seems to have worked) and now would like to confirm that my system is actually clean. Please see attached logs. Note: ComboFix did run but then froze during the "preparing log report" phase, so the attached ComboFix log is just the txt I found in the folder, not the full zip log. Also, RootRepeal failed to run at all (in normal or safe mode).

    More infor about infection:
    • AVG found Crypt.AQLW but couldn't fully clean it
    • CPU & HD constantly at 100%, firewall had been disabled, internet traffic going mad & link redirection - immediately disconnected from internet
    • SUPERAntiSpyware found and cleaned Trojan.Agent/Gen-Loader
    • MalwareBytes Anti-Malware found and cleaned Exploit.Drop.CFG
    • ComboFix found and cleaned Rootkit.ZeroAccess ... but failed to generate full report. CPU dropped to normal after this!
    • RootRepeal failed to run
    • MGTools ran normally

    Note: Before finding this forum, I also found advice to run Kaspersky TDSSKiller which I did, and it did find something, but didn't fix the issue. Log for that attached as well.
     

    Attached Files:

  2. inteja

    inteja Private E-2

    More logs ...

    Note: It says in the ComboFix.txt that AVG was still enabled (and it also gave me that warning message) but I had already used the recommended AVG removal tool and AVG was no longer installed or running at the time.

    I've now updated my OS and all my software, have switched to MS Security Essentials and re-enabled firewall etc.
     

    Attached Files:

    Last edited: Apr 1, 2012
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The mglogs.zip is corrupt/damaged. I am unable to open it. Please therefore run the C:\MGtools.exe again and attach the new C:\MGlogs.zip.
     
  4. inteja

    inteja Private E-2

    Thanks Kestrel13. When I run MGtools.exe I get the following warnings:

    zip warning: missing end signature--probably not a zip file (did you remember to use binary mode when you transferred it?)

    zip error: Zip file structure invalid (C:MGLogs.zip)

    So, I suspect this new scan is going to result in the same corrupt zip ...
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do this for now:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  6. inteja

    inteja Private E-2

    Attached OTL logs as requested.
     

    Attached Files:

  7. inteja

    inteja Private E-2

    Just a side question: Is there any way to trace where an infection came from?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, can you please attach individual files FROM out of the C:\MGlogs.zip?

    I would like to see:
    • Newfiles.log
    • Hijackthis.log
    • Runkeys.log
    • sysinfo.log
     
  9. inteja

    inteja Private E-2

    See attached. I had to zip sysinfo.log as it exceeded max filesize.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK looking good. :)

    Could you just run Combofix once more and hopefully this time it will generate a log for you to attach for me.
     
  11. inteja

    inteja Private E-2

    Thanks Kestrel13. Might be about 8 hours before I can try running it again as at work right now. Stay tuned.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Will catch you tomorrow then! :)
     
  13. inteja

    inteja Private E-2

    See attached ComboFix log. It ran OK this time.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Looks good. Is everything still running okay? :)
     
  15. inteja

    inteja Private E-2

    Yes, it's all humming along nicely still :) So it's safe to call "clean" again?
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes I think so. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. inteja

    inteja Private E-2

    OK thanks so much for your help Kestrel13! You're awesome!

    I'll work through the final steps now.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are *most* welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds