MajorGeeks Support Forums IOBit Software

Go Back   MajorGeeks Support Forums > Majorgeeks.Com - Support Forums > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #21  
Old 09-25-12, 14:26
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Go to start / run / type in:
services.msc
When the window opens, scroll down to the Base Filtering service and tell me what it is set to.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #22  
Old 09-25-12, 15:40
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

The BSE Service is set for Startup Type Automatic. It is not started.
Reply With Quote
  #23  
Old 09-25-12, 15:47
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Set it to manual and then do the fix again.
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
  #24  
Old 09-25-12, 15:56
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Set the BFE Service to Manual.

Rebooted. Reran the BFE.reg. Opened Command prompt and tried to start BFE Service.

Same results. System Error 5. Access is denied.

Update: I checked the Services again and the BFE Service was set back to Automatic. Looks like it happened when I reran bfe.reg. I am positive I set it to Manual. Going to repeat again just in case.

Just reset BFE Service back to Manual. Reopened Services to verify. Did not rerun bfe.reg. Rebooted. Tried to Start BFE services. Same errors.

Last edited by nyt; 09-25-12 at 16:04.. Reason: Update
Reply With Quote
  #25  
Old 09-25-12, 16:12
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Got BFE Started.

Followed these instructions to get it running.

Use Regedit and goto key HLKM\SYSTEM\CurrentControlSet\services\BFE\Parameters\Policy key, and modifying the Permissions on the key to add a user “NT Service\BFE” and give it Full Control.
Reply With Quote
Sponsored links
  #26  
Old 09-25-12, 16:30
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Update to BFE Fix using better instructions.

Run regedit:
1. Browse to the location for the BFE service in the registry (HKLM\System\CurrentControlSet\Services\BFE\Parameters\Policy), right click and select permissions. (note: HKLM is short for HKEY_LOCAL_MACHINE_
2. In the “Permissions for Policy” window, click advanced | Add.
3. Once the “Select Users, Computers or Group” box appears, change the “From this location:” to point to the local machine name.
4. After changing the search location, enter “NT Service\BFE” in the “Enter the object name to select” box and click “Check names” – this will allow you to add the BFE account.

5. Give the following privileges to the BFE account:
Query Value
Set Value
Create Subkey
Enumerate Subkeys
Notify
Read Control

After adding the BFE account to the registry key, please try to start the Base Filtering Engine service.
Reply With Quote
  #27  
Old 09-25-12, 17:11
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Noticed the Security Center Service was also missing. Followed another forum's instructions to download the appropriate missing registry entries. Rebooted and it is back and running.

Still cannot get Windows Firewall or Windows Defender running. Just installed Microsoft Security Essentials so I believe I do not need Windows Defender. Still poking around for a fix on the Firewall Issue.

Thanks!

Last edited by nyt; 09-25-12 at 17:14.. Reason: Fixed mistypes
Reply With Quote
  #28  
Old 09-25-12, 17:36
nyt nyt is offline
Private E-2
 
Join Date: Mar 2009
Posts: 29
Thanks: 5
Thanked 0 Times in 0 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Windows Firewall is now running. Followed same procedure as BFE.

Imported Registry Keys for mpssvc and sharedaccess.

Gave mpssvc account same privileges as described in BFE post below in SharedAccess registry key.

That allows me to start Windows Firewall.

What do I do now to see what else needs to be done?

Thanks again for your help TimW!!
Reply With Quote
  #29  
Old 09-26-12, 13:37
TimW's Avatar
TimW TimW is offline
MajorGeeks Administrator - Jedi Malware Expert
 
Join Date: Jan 2005
Location: The recesses of my mind!
Posts: 44,610
Thanks: 377
Thanked 4,196 Times in 3,986 Posts
Default Re: ZeroAccess cannot run TDSKiller or MBAB Redirecting Issues

Quote:
Originally Posted by nyt View Post

What do I do now to see what else needs to be done?
You should be good to go now.
Quote:
Originally Posted by nyt View Post
Thanks again for your help TimW!!
You are most welcome.

If you are not having any other malware problems, it is time to do our final steps:
  1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
  2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
  3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  5. Go to add/remove programs and uninstall HijackThis.
  6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
    related to MGtools and some other items from our cleaning procedures.
  7. After doing the above, you should work thru the below link:


Malware removal from a National Chain = $149
Malware removal from MajorGeeks = $0
__________________
Major cake licker.
YCLAHTW, BYCMHD!!

Major Geeks on Facebook

Major Geeks Newsletter
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Zeroaccess among other issues Oak03 Malware Removal 9 08-22-12 12:35
wits end, zeroaccess/cryptor, tcpip issues... SmokeyHawk Malware Removal 12 01-29-12 16:26
redirecting jkb002 Malware Removal 24 09-11-11 18:55
redirecting please help sparkki Malware Removal 21 10-21-10 17:25
Wife's browser redirecting to Browser redirecting to "http://ad.yieldmanager.com/st%3 victorydoc Malware Removal 4 09-05-08 00:26


All times are GMT -5. The time now is 07:50.


MajorGeeks.Com Home Page
| Admin Tools | All In One | Anti-Spyware | Anti-Virus | Appearance | Backup | Benchmarking | BIOS | Browsers | Covert Ops |
Data Recovery | Diagnostics | Drive Cleaners | Drive Utilities | Drivers | Driver Tools Ergonomics | Firewalls | Games | Game Tweaks | Graphics | Input Devices | Internet Tools | Macintosh | Mail Utilities | Memory | Messaging | Monitoring | Microsoft | Multimedia | Networking | Office Tools | Process Management | Processor | Registry | Security | System Info | Toys | Video | Miscellaneous
|

-->
Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger