Combofix reports infection by Rootkit.Zeroaccess! persistently

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sundawg74, Mar 26, 2013.

  1. sundawg74

    sundawg74 Private E-2

    Originally I had a problem where emails were sent to my Yahoo contacts, IE would shutdown shortly after being launched, and Microsoft Update would not run. Having used Combofox in the past to resolve malware issues that could not be fixed by running Anti-Malware, I downloaded the latest Combofix and ran it, and it reported that my system was infected by Rootkit.Zeroaccess and had inserted itself in the TCPIP stack.

    Subsequently I have run many scans including Malwarebyte Anti-Malware, Superantispyware, Rougekiller, TDSSkiller, Eset, Malwarebytes Anti-rootkit Utility, and some others that I'm sure I've forgotten. While Microsoft Update will now run and Malware scans are clean, every time I run Combofix it continues to report that the systems is infected with Rootkit.Zeroaccess.

    So, I stepped back and walked through the READ & RUN ME FIRST Malware guide and attached the requested logs. I then ran Combofix to see if the error message persisted, which it did. Is the Combofix reporting a false positive, or is there additional cleaning that needs to be done.
     

    Attached Files:

  2. sundawg74

    sundawg74 Private E-2

    I am also attaching the log from the Combofix I ran to determine that the Rootkit.Zeroaccess message continued to display.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\system32\tmp.reg
    
    Folder::
    c:\documents and settings\All Users\Application Data\ErrorEND
    c:\documents and settings\Mike\Application Data\SpeedyPC Software
    c:\documents and settings\All Users\Application Data\SpeedyPC Software
    c:\documents and settings\Mike\Local Settings\Application Data\Babylon
    c:\documents and settings\All Users\Application Data\Babylon
    c:\documents and settings\Mike\Application Data\Babylon
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      [​IMG]

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.


    Does Combofix continue to detect rootkit activity now?
     
  4. sundawg74

    sundawg74 Private E-2

    Yes. It continues to detect the Rootkit.Zeroaccess condition.

    I ran the Combofix as instructed and the log is attached.

    I rebooted the system and it installed one update at shutdown. I restarted and ran Combofix again (without using the CFscript) and it still detects the Rootkit.Zeroaccess, however it hangs after the last step and will not produce a log.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Run this and attach the results.

    Using ESET's Online Scanner


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  6. sundawg74

    sundawg74 Private E-2

    Requested files attached
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So, it's loking like combofix could be detecting the quarantined files belonging to the rootkit. Did Malware Bytes or something you ran before you came here remove anything of zero access/rootkit?
     
  8. sundawg74

    sundawg74 Private E-2

    MalwareBytes Anti-Rootkit removed some Uninstall files from c:\windows. I have attached the log from that run which was done before I started this thread. There were probably some other removals done by other scans, but I'm not sure any had to do with the rootkit.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So this folder no longer exists, for sure?

    c:\WINDOWS\$NtUninstallKB22796$

    Also, avg quarantined stuff:
    So....empty the quarantine and tell me if combofix conntinues to detect rootkit activity or not...
     
  10. sundawg74

    sundawg74 Private E-2

    -directories c:\windows\$NTUninstallKB22796$\ and c:\windows\$NtUninstallKB42739$\ exist but were empty
    -I emptied the AVG and Malwarebyte Anti-malware quarantined vaults and reran Combofix.
    -It still got the Rootkit.Zeroaccess message
    -I ran Malwarebytes Anti-Rootkit and it reported no errors on its scan.
    -I deleted the two empty directories listed in the first bullet
    -I reran Combofix and NO ROOTKIT.ZEROACCESS MESSAGE!!!

    So apparently Malwarebytes Anti-rootkit deleted the contents of the two directories but not the directories themselves???

    Thank you for your prompt assistance in dealing with this.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Exactly right! And combofix was going and getting all excited about it. :)

    If all is well now..

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds