![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
|
|
#1
|
|||
|
|||
|
Noticed that the internet was slow and that I was getting a Google redirect in the last week or so.
Tried the READ ME FIRST process, but I don't think it is completely gone. Your help is greatly appreciated. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
MGTools Log
|
|
#3
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
|||
|
|||
|
Logs from TDSSkiller & MBRCheck.
|
|
#5
|
||||
|
||||
|
We need to use ComboFix by sUBs
Code:
KILLALL::
DirLook::
c:\documents and settings\Desk\Local Settings\Application Data\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}
c:\documents and settings\All Users\Application Data\F4D55F170000706500037C80D151FC4E
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
"NecUsb3Sevic"=-
File::
C:\windows\system32\USB3Nw32.dll
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Ran Combofix with the additional script. Still detected Rootkit.ZeroAccess! inserted itself in tcp/ip stack.
Combofix restarted the computer a couple of times then ran Getlogs.bat. Error occurred with Getlogs "Unexpected error has occurred at proceedure: Modregistry_IniGetstring(sFile=system.ini, sSection=boot, sValue=Shell) Error #5 invalid procedure call or argument" Your continued assistance is greatly appreciated. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit.zeroaccess | kbtrade | Malware Removal | 1 | 02-25-12 21:58 |
| Rootkit.zeroaccess | mpetro1 | Malware Removal | 12 | 12-29-11 16:04 |
| Help with rootkit.zeroaccess | elias7 | Malware Removal | 3 | 12-21-11 11:04 |
| ZeroAccess Rootkit | zq1 | Malware Removal | 6 | 12-06-11 22:39 |