MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 08-03-12, 21:49
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Repeated attempts by Zeroaccess.b Trojan today

May have other issues have attached hijackthis log for suggestions
Attached Files
File Type: log hijackthis.log (13.0 KB, 4 views)
Reply With Quote
Sponsored links
  #2  
Old 08-04-12, 13:40
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Please do the below so that we can boot to System Recovery Options to run a scan. There will be two options to choose from. One if you do not have your Windows 7 boot DVD and another when you have your DVD.

For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

Plug the flashdrive into the infected PC.

Option1: Enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

Option2: Enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:
Quote:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
  • Select Command Prompt
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #3  
Old 08-05-12, 09:03
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim
I appreciate your reply
Farbar Recovery Scan Tool Log File Attached
Attached Files
File Type: txt FRST.txt (25.6 KB, 7 views)
Reply With Quote
  #4  
Old 08-05-12, 11:09
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim I also noticed that this laptop has not had a windows update since 4/13/12. When I went to the window update program, it would not update because:
Windows update cannot currently check for updates, because the the service is not running. You may need to restart your computer.
Windows updates are set to install automatically.
I cannot view update history.
Reply With Quote
  #5  
Old 08-05-12, 14:56
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Save fixlist.txt to your flash drive.
  • You should now have both fixlist.txt and FRST.exe on your flash drive.

Now reboot back into the System Recovery Options as you did previously.
Run FRST and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt).
Please attach this to your next message. (See how to attach)

Now boot into normal Windows can continue with the below.

Running MGTools.
Attached Files
File Type: txt Fixlist.txt (639 Bytes, 6 views)
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Sponsored links
  #6  
Old 08-18-12, 16:29
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim:
I was able to complete the fix with Farbar Recovery Tool and attached the Fixlog.txt as requested.
I installed MGTools.exe and ran the program successfully. I attached the MGlogs.zip as requested.
Reply With Quote
  #7  
Old 08-19-12, 06:27
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 24,114
Thanks: 513
Thanked 2,769 Times in 2,715 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Logs did not attach.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks

Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

“The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.”
Reply With Quote
  #8  
Old 08-19-12, 07:13
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Apologies
Logs attached
Attached Files
File Type: zip MGlogs.zip (253.9 KB, 5 views)
File Type: txt Fixlog.txt (950 Bytes, 1 views)
Reply With Quote
  #9  
Old 08-19-12, 13:53
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Please run CCleaner and clean out your temp folders.

Tell me what issues you may still have, if any.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #10  
Old 09-01-12, 08:24
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim
I ran ccleaner, the laptop has been running much better, no more malware alerts
Installing the full versions of malwarebytes and superantispyware I has helped alot. I appreciate your help.

I attached a rkill.txt file after running rkill.exe today that indicates ZEROACCESS rootkit symptoms found!
However when I checked the address in the registry the entry was not there.
Please advise
Attached Files
File Type: txt Rkill.txt (3.1 KB, 5 views)
Reply With Quote
Sponsored links
  #11  
Old 09-01-12, 13:36
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Extract bfe.reg to your desktop.
Double-click BFE.reg and allow it to merge into the registry. If you get a "successfully merged into registry" type of message, reboot your PC and see if you can turn on BFE, or if it is already turned on.

You can run these commands from the command prompt.
  • net start bfe
  • sc qc bfe


Now re-run RogueKiller and attach the log.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
The Following User Says Thank You to TimW For This Useful Post:
safetydave (09-01-12)
  #12  
Old 09-02-12, 00:07
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim
Thank you for your reply
I got a "successfully merged into registry" type of message, rebooted PC, but was not able to turn on BFE after running the following from the command prompt:
net start bfe
sc qc bfe
I attached screen shots of two different errors messages I received while trying to start BFE.
Safetydave
Attached Images
File Type: jpg BFE could not be started.jpg (23.3 KB, 4 views)
File Type: jpg BFE Set to Automatic - unable to start.jpg (53.5 KB, 3 views)
Reply With Quote
  #13  
Old 09-02-12, 13:33
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Delete the BFE.reg file that exists on your desktop. Download this one to the same location.
BFE.reg


Now, boot into safe mode please to carry out the next set of instructions.

  • Now please click Start, and type regedit into the search box.
  • You should see a regedit.exe and icon appear in the Programs area of the Start Menu.
  • Right click on regedit.exe and select Run As Administrator
  • Then in the Registry Editor menu click File and select Import.
  • Navigate to the BFE.reg file saved to your Desktop and double click it. Allow it to be added to the registry.

Back into normal mode now -
Download Windows
Repair
by Tweaking.com and unzip the contents into a newly created folder on your desktop.
  • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
  • Now select the Start Repairs tab.
  • The click the Start button.
  • Create a System Restore point if prompted.
  • On the next screen, click the Unselect All button to first deselect all repairs.
  • Now select the following repair options:
    • Reset Registry Permissions
    • Reset File Permissions
    • Register System Files
    • Repair WMI
    • Repair Windows Firewall
    • Remove Policies Set By Infections
    • Repair Winsock & DNS Cache
    • Repair Proxy Settings
    • Repair Windows Updates
    • Set Windows Services To Default Startup
  • Now on the lower right side check the box to Restart/Shutdown System When Finished
  • Then make sure the Restart System radio button is enabled.
  • Shutdown any other programs that you are running now before continuing.
  • Now click the Start button.
  • Be patient while the tool repairs the selected items.
  • It should reboot automatically when finished.

After reboot, check to see if your firewall is working.
Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter

Last edited by Kestrel13!; 09-02-12 at 14:49..
Reply With Quote
  #14  
Old 09-03-12, 01:37
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim
Thank you
Ran regedit.exe as admin was able to import BFE.reg
BFE never would start in safe or normal mode
Windows repair went ok - mglogs.zip attached
Ran rkill64 log attached -
* ALERT: ZEROACCESS rootkit symptoms found!
* HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 [ZA Reg Hijack]
Safetydave
Attached Files
File Type: zip MGlogs.zip (281.9 KB, 4 views)
File Type: pdf BFE cannot be started in safe mode.pdf (83.0 KB, 0 views)
File Type: txt Rkill.txt (2.9 KB, 5 views)
Reply With Quote
  #15  
Old 09-03-12, 08:53
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Your logs look good. All the services are now running. Use RogueKiller to remove that last item. Then tell me how things are running for you.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
The Following User Says Thank You to TimW For This Useful Post:
safetydave (09-03-12)
Sponsored links
  #16  
Old 09-03-12, 09:40
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Thanks Tim
Not sure how to use Roguekiller to remove ZEROACCESS rootkit symptoms found!
When I run Roguekiller it does not seem to remove it
I deleted the item using regedit not sure if I should have done that
Reply With Quote
  #17  
Old 09-03-12, 15:05
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,626
Thanks: 377
Thanked 4,198 Times in 3,988 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Quote:
Originally Posted by safetydave View Post
I deleted the item using regedit not sure if I should have done that
That should have worked. Re-run RogueKiller and attach the new log.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
The Following User Says Thank You to TimW For This Useful Post:
safetydave (09-03-12)
  #18  
Old 09-03-12, 21:37
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Tim
Thank you
I see no change in the roguekiller log
I attached it along with a screen shot of the registry location in question.
Is it possible that roguekiller is mistaken?
Gratefully
Safetydave
Attached Images
File Type: jpg ZeroAccess Rootkit Registry Location.jpg (96.8 KB, 2 views)
Attached Files
File Type: txt Rkill.txt (2.9 KB, 8 views)
Reply With Quote
  #19  
Old 09-04-12, 05:40
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 24,114
Thanks: 513
Thanked 2,769 Times in 2,715 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Hello there. This is looking quite a mess. According to the rkill log you have lots of missing services. Then when I check other logs, it says some of those services are ok, so let's do this for now please.
Quote:
Is it possible that roguekiller is mistaken?
(You have been running rkill, not RogueKiller!!!)

SystemLook

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    Code:
    :reg
    HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32 /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks

Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

“The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.”

Last edited by Kestrel13!; 09-04-12 at 05:52..
Reply With Quote
The Following User Says Thank You to Kestrel13! For This Useful Post:
safetydave (09-04-12)
  #20  
Old 09-04-12, 21:58
safetydave safetydave is offline
Private E-2
 
Join Date: Aug 2012
Posts: 23
Thanks: 15
Thanked 0 Times in 0 Posts
Default Re: Repeated attempts by Zeroaccess.b Trojan today

Kestrel13!
I appreciate your attention to the details that I missed and for trying to help.
I am not as well versed as I should with Malware removal.
I followed your instructions hope I used the correct software this time!
Safetydave
Attached Files
File Type: txt SystemLook.txt (698 Bytes, 4 views)
Reply With Quote
Sponsored links
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zeroaccess Trojan gingerhead40 Malware Removal 11 07-17-12 23:24
Trojan.Zeroaccess!inf oldsch00l Malware Removal 1 03-15-12 20:48
Over 50 attempts of a trojan virus ... xllxdawnxllx Malware Removal 1 05-02-10 20:48
Adware Popups & Trojan Attempts to Access the Net OminousThunder Malware Removal 5 12-09-08 00:13
Jacko Attempts Suicide, Trojan Marches In Shadow_Puter_Dude Interesting Website Links 0 06-10-05 17:56


All times are GMT -5. The time now is 11:02.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger