ZeroAccess Found + Multiple Program Has Stopped Working Errors

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Irkd, Sep 20, 2013.

  1. Irkd

    Irkd Private E-2

    First thank you for running this site. I guess I've been downloading code from all the wrong places . . . . A week ago, I noticed that I was routinely getting the "program has stopped working" error dialog box with Notepad, Outlook, Word, Excel, Powerpoint, Adobe Acrobat and other programs. At first, I was getting a dialog box that said an add-in was the problem and asked me if I wanted to remove it by clicking. I did this a few times but still could not launch the program I was trying to open which was most often Outlook. I'm sure now that I should not have clicked. At this point, I only get the Program has stopped working dialog box with an option to close program. This all started on 9-13-13.

    I have followed the Read & Run Me First instructions to the letter. If I am reading it correctly, my RogueKiller log shows a ZeroAccess infection. Help!!

    Also, when I was backing up my Outlook.pst file following the forum prep instructions, I noticed that the file format is no longer ".pst" but rather it's in adobe acrobat "PDF" format. I think I need help in uncorrupting or resetting the format of my Outlook file.

    I have attached all five log files as requested.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Uninstall the below programs. If you do not find them or they will not uninstall, just keep going.
    Java 7 Update 11

    Now install the current version of Sun Java from: Sun Java Runtime Environment Make sure that when you see the form asking about installing Ask Toolbar that you uncheck this.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\$Recycle.Bin\S-1-5-21-3019333746-1946228393-2518998603-500\$c04b48aa4877a95f781f1d768985161d\n.
    C:\$Recycle.Bin\S-1-5-21-3019333746-1946228393-2518998603-500\$c04b48aa4877a95f781f1d768985161d
    C:\WINDOWS\TEMP\*.*
    C:\Users\Administrator\AppData\Local\Temp\*.*
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\s]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. Irkd

    Irkd Private E-2

    Chaslang - Thank you. Still have old problems and now have a new one with Internet Explorer: "Proxy Server is Not Responding." I followed your directions and rebooted. After reboot, I tried to run Outlook and got prompted to open in Safe Mode, which I did. Outlook failed to launch and I got a dialog box with the "has stopped working" error. When I tried to launch Outlook a second time, I got a dialog box saying that Outlook had failed to launch in Safe Mode, would I like to repair? Launched repair but quickly cancelled because I got scared that what I was seeing was still Malware. When I tried to launch IE to post here, I got the proxy server is not responding error in IE. So I put the logs on a thumb drive and I'm posting from a different comp. I have a sick computer I think. Thanks for your help.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Perhaps this is due to what you installed. I ignored BrowserSafeguard in your logs because I assumed you installed it. Is this a good assumption?

     
  5. Irkd

    Irkd Private E-2

    Chaslang: The only thing I installed recently is AVG 2014 Free (other than the downloads in your instructions). But I did that yesterday. When I pull up my programs log in Control Panel, BrowserSafeguard shows an install date of 8-21-13. I didn't install BS (has appropriate acronym, I suspect) on purpose in August. I did install or update CCleaner on 8-21-13. Uninstall BS?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's do the below in the order shown.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:49192;https=127.0.0.1:49192
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <-loopback>
    O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)

    After clicking Fix, exit HJT.

    Now uninstall >> BrowserSafeguard

    Reboot your PC now.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. Irkd

    Irkd Private E-2

    The instructions worked to get Internet Explorer working again. However, I still have the "program has stopped working" error. After I rebooted, I tried to launch Outlook and got the dialog box prompting a Safe Mode launch, which I did. When it tried to launch in Safe Mode, I got the Outlook has stopped working box and I closed the program. I hope there's something in the attached logs. An OS reinstall will inflict a large quantity of pain on me.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but these remaining issues are not due to remaining malware. Also may not be related to any that you had. ZeroAccess is not known to cause these kinds of problems and it was basically gone already in your first post. The one item was just a benign left over. The rest of the items we removed were just basic junkware. You may have to post in the Software Forum for the rest of your problems; however, try the below just for the heck of it.



    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
     
    Last edited: Sep 22, 2013
  9. Irkd

    Irkd Private E-2

    Chaslang - Thank you very much for your thoughts and suggestions. I ran the Windows Repair program but I still get the "program has stopped working" error for Word, Outlook, PowerPoint, Excel, Adobe, etc. I'll take this problem to the MG software forum as you recommend. One last question: do you think running ComboFix would help at all? I'm hoping that the program error I'm getting isn't like that "Display Driver has stopped working" error that sometimes pops up but can be caused by any one of 87,234 issues. I really want to avoid an OS reinstall . . . Thank you again for your help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Most likely not. It could potentially pickup some miscellaneous junk but more likely would just have a few false detections. It also would not repair your problems with Office. You should try just running the Office installer. I believe it has a repair option which could help. Otherwise, maybe a full uninstall of Office followed by a reinstall would work.


    Since you do not appear to be having malware problems, it is time to do our final steps.
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. After doing the above, you should work thru the below link:
    Note I did not have you toggle system restore just in case you want to try using it as a fix.
     
  11. Irkd

    Irkd Private E-2

    I'm trying a Windows system restore to a restore point date before the problems appeared. I hope that works. Thanks for all of your help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Okay but do remember that this could restore infections to so you may need to start malware removal over again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds