Zeroaccess and cant change windows firewall

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by andrewchap, Mar 2, 2013.

  1. andrewchap

    andrewchap Private E-2

    Hi

    My laptop has been overheating for a long time (8 months), I am pretty sure it is just a clogged fan system as I use it in a dusty environment however i have had my suspicions.

    Recently Avira started reporting zeroaccess (a few days ago), subsequent running of avira (free edition) scan removed a couple of virus's initially but after that scan runs failed to identify anything.

    After this everytime i logged in avira would block zeroaccess although it would never show in the scans.

    I updated malwarebytes and ran a full scan (log attached) which found and removed zero access and numerous other malware (29 i think). Zero access no longer showed up with avira and subsequant scans with malwarebytes were clean.

    After this I still could not change the windows firewalls settings. I tried importing the reg for BFE and fire wall and activating though system.msc however this failed when activating the windows firewall service.

    I got desperate and did what I probably shouldnt have .. .followed a post on removing zero access without reading all the readmes... I ran combofix (didnt change any settings or use scripts), ran tdskiller with default actions... then ran avenger (same again and no scripts).

    I still couldnt change the firewall settings so I decided to do the right thing and follow the readme at this site... step by step...

    logs attached....

    (is combofix still running? i am not sure... should i have uninstalled it before following the steps?).

    I need help to:
    1) see if there is still anything bad on my computer...
    2) get the firewall back under my control
    3) make sure I didnt break anything the first time i ran combo etc
    4) see if there are any bad processes causing my computer to overheat

    Thanks in advance....
    I really appreciate any help given

    Andrew
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. andrewchap

    andrewchap Private E-2

    Hi apologies.... I did attach the files and I am not sure why they are not there.....

    I will try again.... hopefully they are attached now?
     

    Attached Files:

  4. andrewchap

    andrewchap Private E-2

    I need to add That:

    After reboot I lost internet access
    When i opened iexplorer or programs like steam they wouldnt open and would give a wsa error:

    I tried instructions on another thread, these were:

    "Click Start, and then click Run.
    In the Open box, type regedit, and then click OK.
    In Registry Editor, locate the following keys, right-click each key, and then click Delete:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Winsock2
    When you are prompted to confirm the deletion, click Yes.
    Close the Registry Editor.

    Locate the Nettcpip.inf file in C:\WINDOWS\inf and then open the file in Notepad.
    Locate the [MS_TCPIP.PrimaryInstall] section. Change the Characteristics = 0xA0 entry by replacing 0xA0 with 0x80. Save the file. Exit Notepad.
    In Control Panel, double-click Network Connections, right-click Local Area Connection, and then select Properties.
    On the General tab, click Install, select Protocol, and then click Add.
    In the Select Network Protocols window, click Have Disk.
    In the Copy manufacturer's files from text box, type C:\WINDOWS\inf, and then click OK.
    Select Internet Protocol (TCP/IP), and then click OK. It will report as unsigned, this is the one we want! Do not choose Microsoft TCP/IP v6!

    Note This step returns you to the Local Area Connection Properties screen. However, the Uninstall button is now available.
    Select Internet Protocol (TCP/IP), click Uninstall, and then click Yes.
    You will be asked to reboot your PC for the changes to take affect, go ahead and do this now.

    Once you have rebooted...
    In Control Panel, double-click Network Connections, right-click Local Area Connection, and then select Properties.
    On the General tab, click Install, select Protocol, and then click Add.
    In the Select Network Protocols window, click Have Disk.
    In the Copy Manufacturer's files from text box, type C:\WINDOWS\inf, and then click OK.
    Select Internet Protocol (TCP/IP), and then click OK.
    Restart your computer.
    Test your Internet connectivity."

    I only got as far as deleting the winsock and winsock2.

    I couldnt edit the Nettcpip.inf file in C:\WINDOWS\inf as it said I wasnt a trusted installer?? I am administrator!

    Still no internet, however programs like steam and iexplorer actually open now.

    Please help (if only to stop myself from getting in even more trouble!!)

    THanks

    Andrew
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you used ComboFix, please put it directly on your desktop!! Not here:
    d:\downloads\Removezeroaccess\ComboFix.exe

    Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.


    Now let's use ComboFix to remove a bunch of malware files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    ClearJavaCache::
    KILLALL::
    File::
    c:\windows\TEMP\CWHCEF4.tmp
    c:\windows\TEMP\CWHBB56.tmp
    c:\windows\TEMP\CWHA680.tmp
    c:\windows\TEMP\CWH917B.tmp
    c:\windows\TEMP\CWH7C09.tmp
    c:\windows\TEMP\CWH6742.tmp
    c:\windows\TEMP\CWH5356.tmp
    c:\windows\TEMP\CWH3E13.tmp
    c:\windows\TEMP\CWH28EE.tmp
    c:\windows\TEMP\CWH137C.tmp
    c:\windows\TEMP\CWHFE1A.tmp
    c:\windows\TEMP\CWHE8A7.tmp
    c:\windows\TEMP\CWHD354.tmp
    c:\windows\TEMP\CWHBDE2.tmp
    c:\windows\TEMP\CWHA870.tmp
    c:\windows\TEMP\CWH954E.tmp
    C:\Windows\temp\CWH6EAA.tmp 
    C:\Windows\temp\CWH59F3.tmp
    C:\Windows\temp\CWH44DF.tmp
    C:\Windows\temp\CWH2F6C.tmp
    C:\Windows\temp\CWH1A39.tmp
    C:\Windows\temp\CWH4E6.tmp 
    C:\Windows\temp\CWHF09C.tmp
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    [​IMG]
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Note: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.

    Now rescan with RogueKiller. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [RUN][BLACKLISTDLL] HKLM\[...]\Run : RunDLLEntry (C:\Windows\system32\RunDLL32.exe C:\Windows\system32\AmbRunE.dll,RunDLLEntry) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now click on the DNS tab and have it fix these:
    [DNS] HKLM\[...]\ControlSet001\Services\Tcpip\Interfaces\{1B3EA432-EB5E-494F-8B57-8E283622F147} : NameServer (211.29.132.12 61.88.88.88) -> FOUND
    [DNS] HKLM\[...]\ControlSet001\Services\Tcpip\Interfaces\{29215CA0-9038-4414-929A-62008DC00311} : NameServer (211.29.132.12 61.88.88.88) -> FOUND
    [DNS] HKLM\[...]\ControlSet002\Services\Tcpip\Interfaces\{1B3EA432-EB5E-494F-8B57-8E283622F147} : NameServer (211.29.132.12 61.88.88.88) -> FOUND
    [DNS] HKLM\[...]\ControlSet002\Services\Tcpip\Interfaces\{29215CA0-9038-4414-929A-62008DC00311} : NameServer (211.29.132.12 61.88.88.88) -> FOUND

    Now reboot. Rescan with RogueKiller and attach that new log as well.

    Your Newfiles log did not populate, so run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\ComboFix.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!

    No not put them all into one zip file!!
     
  6. andrewchap

    andrewchap Private E-2

    Hi TimW

    Thanks again for looking into to this issue..your time it is greatly appreciated

    I have done as you said, logs attached.

    I now have access to window firewall settings
    Still no internet.
    Explorer takes ages to start (even if opening the control panel and accessing firewal settings) and has been freezing quite frequently.
    computer temprature when nothing running seems to be lower than it used to be but reached 90degrees C when I switched on high performance (I have had to run the computer in power save mode for months) and opened excel and explorer.

    Every thing else seems ok.

    Thanks again for looking into to this issue..your time it is greatly appreciated
     

    Attached Files:

  7. andrewchap

    andrewchap Private E-2

    Hi

    I need to add that the windows explorer problem became so bad that i couldnt even open files in excel etc...

    I restarted the computer in safe mode and explorer worked fine ... after this windows explorer appears to work fine now, also excel files etc open ok.

    Steam and internet explorer will not open.

    thanks
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    c:\windows\TEMP\CWH6174.tmp
    c:\windows\TEMP\CWH4C40.tmp
    c:\windows\TEMP\CWH37A9.tmp
    c:\windows\TEMP\CWH2284.tmp
    c:\windows\TEMP\CWHDCD.tmp
    c:\windows\TEMP\CWHF8A9.tmp
    c:\windows\TEMP\CWHE411.tmp
    c:\windows\TEMP\CWHCF2B.tmp
    c:\windows\TEMP\CWHBA74.tmp
    c:\windows\TEMP\CWHA5DD.tmp
    c:\windows\TEMP\CWH90A9.tmp
    c:\windows\TEMP\CWH7BB3.tmp
    c:\windows\TEMP\CWH669F.tmp
    c:\windows\TEMP\CWH516B.tmp
    c:\windows\TEMP\CWH3C47.tmp
    c:\windows\TEMP\CWH27CE.tmp
    c:\windows\TEMP\CWH12BA.tmp
    c:\windows\TEMP\CWHFF1B.tmp
    c:\windows\TEMP\CWHEA83.tmp
    c:\windows\TEMP\CWHD5DC.tmp
    c:\windows\TEMP\CWHC115.tmp
    c:\windows\TEMP\CWHACDB.tmp
    c:\windows\TEMP\CWH9824.tmp
    c:\windows\TEMP\CWH8541.tmp
    c:\windows\TEMP\CWH7117.tmp
    c:\windows\TEMP\CWH5EB0.tmp
    c:\windows\TEMP\CWH4BDD.tmp
    c:\windows\TEMP\CWH3929.tmp
    c:\windows\TEMP\CWH2627.tmp
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.
     
  9. andrewchap

    andrewchap Private E-2

    Hi

    Log attached.

    No internet still
    Internet explorer wont open

    I used the computer for a while after the OTL restart and found it to be slow. So I restarted and got the message "preparing to configure windows please do not turn off the comuter"

    once the restart was completed I still found computer to be very slow and eventually mirosoft offic word froze. I attempted to use ctrl alt del and got the message
    "logonui.exe was unable to start correctly (0xc00001d) ctrl-alt-del to close the application" then "failure to display security and shutdown process the logon process was unable to display security and logon options when ctrl alt del was pressed. if the operating system does not respond press esc or restart computer using power switch"

    I pressed esc.. used shutdown.. which resulted in slow partial shutdown... I had to use the power switch to switch off.

    restarted in safe mode.... all ok... restarted normally....

    works but still very slow
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach a log.
     
  11. andrewchap

    andrewchap Private E-2

    Doh.

    Attached now.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Sorry for the delay, sick as a dog.


    • Double click on the OTL to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  13. andrewchap

    andrewchap Private E-2

    Hi

    No need to apologise, you are doing me the favour.

    Attached are the logs

    Hope you recover quickly.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :killallprocesses
    :files
    @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:A724744F
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:AB689DEA
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.


    Now re-run Combo and attach that new log as well.

    Tell me how things are running now.
     
  15. andrewchap

    andrewchap Private E-2

    Hi

    Attached are the two new logs.

    Computer appears to be running ok since running combofix although I havent had a chance to restart since then.

    Still no internet.

    I can connect to the network however it says unidentified network no internet access..

    Thanks
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I think you will have to post in the networking forum for your internet issues:
    Code:
    Ethernet adapter Local Area Connection:
    
       Media State . . . . . . . . . . . : Media disconnected
    What is this:
    c:\program files\NoVirusThanks
     
  17. andrewchap

    andrewchap Private E-2

    Hi
    Sorry I havent got back to you yet. Life got real busy (made even harder by an antagonisingly slow computer!!) but also I wanted to try and work out what was happening with my computer performance so I could give you better feed back.

    Some points to note:

    After each fresh restart my computer is extremely slow for about 2-4 hours. It will then start performing much better but still slow. I have to restart it in the evenings and get it working by bed time then hibernate it over night so it is useable the next day!

    During the slow period numerous errors come up especially when trying ctrl-alt-del. such as "the application was unable to start correctly in safe mode 0xc000014236"

    a service "lic.agent?" (cant rememebr what it was called now) continuously starts and stops

    computer runs at 37-45 degrees C in safe mode (with no applications open)
    Computer runs at 77-85 degrees C in normal mode (with no applications open)(both on power saving setting).

    I have just noticed tonight that there were 2656 processes running and remembered that the other night I saw 4100 processes running (but thought i had misunderstood!!).

    On checking Resource monitor I saw that 98% physical memory was being used (of 6GB!!!).

    I restarted and watched the physical memory steadily get used up over the period of about 10minutes (I took screen shots every minute if you want to see it, it shows the top 10 processes as well). Eventually it settled between 97% and 100%. Services.exe was the largest at 4,904,496 commit kb and 4,721,000 working kb.

    After another day of messing around and desperation I investigated the processes running. There were hundreds of "conhost.exe" running and hundreds of processes which started with CWH followed by three or four numbers and letters ending with .tmp (eg CWH588.tmp).

    I decided to risk ending the .tmp processes as they seemed the safest to kill (based on my very limited understanding).

    eventually I killed all 1300 of them and they inturn ended the conhost.exe processes.

    There are now 74 processes running, the temperature is at 60 degrees C (balanced mode not powersave mode), Physical memory usage is at 68% and the computer is refreshingly fast and my stress levels are dropping rapidly.

    I hope you can make sense of this and help as soon as possible!!! I am too scared to restart the machine! but at least i have a temporary method of keeping the machine useable!

    Many thanks and looking forward to your response!
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run ComboFix and attach the new log. Let's see if that temp file is still acting up.
     
  19. andrewchap

    andrewchap Private E-2

    Hi

    Attached is the combofix log

    Since I killed the 1300 tmp processes restarting the computer has not resulted in the extreme slowness that was happening before (dont know if they are related or not).

    The tmp's are still being generated unceasingly but not as quickly.

    On further investigation the cwsvc.exe was linked to the temp files (chain)

    Pausing the cwsvc.exe stopped the tmp files from being generated (until restart).

    During running combofix an error popped up for update.exe... 'illegal operation attempted on a registrey key that has been marked for deletion'

    The update.exe was located in the netnanny directory. Netnanny was disabled at the time of running combofix.

    The cwsvc.exe sounds like a netnanny file as well (contentwatch is netnanny).

    I am happy to uninstal netnanny and reinstall later if you think it will help.
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, try uninstalling it and removing the remaining temp files and see if it improves your performance.
     
  21. andrewchap

    andrewchap Private E-2

    Hi

    I uninstalled netnanny, this stopped the creation of the temp files.

    I re-enabled my wireless network but still no interntet.

    Restarted computer.

    On restart the computer was very slow and 100% memory used after short time. On investigation it showed svhost.exe(networksrvicenetworkrestricted) continually restarting and ending.

    Disabled wireless internet and restarted computer.

    No svhost.exe problem. 18% memory usage, computer fast, average 61 degrees C with nothing running. So seems good when network disabled.

    So 2 problems in performance remain

    1:Svhost file problem (and no internet)

    2:Tested running a computer game... (warband mount and blade... lasted for roughly 8 minutes at around 81 degrees C, after another few minutes it overheated - i think this is at 100 degrees C and switced off). Appears that running graphic intensive programs overheat the machine.

    (also i noticed you have been thanked 0 times in this thread.. how do I thank!)
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like you need to post in both the networking forum and the hardware forum for those issues with over heating and lack of internet.
     
  23. andrewchap

    andrewchap Private E-2

    Hi

    Many thanks, I will post in those forums.

    So from your side im all clear now?

    Certainly running heaps better, I dont have to have fans blowing on it all day now!

    Big relief.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, your logs are malware free at this point. I hope you find some help with your other issues. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds