Trouble w/ poss ZeroAccess rootkit (WinXP)

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by aaron_kgs, Sep 27, 2013.

  1. aaron_kgs

    aaron_kgs Private E-2

    Any assistance is greatly appreciated.

    Desktop PC, a Nobilis (Equus) build of Win XP Pro 2002 SP2 on a workstation.
    Some tech experience, not an expert, but willing to follow instructions.
    Have been following the thread for "Windows XP Malware Removal/Cleaning Procedure". http://forums.majorgeeks.com/showthread.php?t=139313
    Did everything in order as told in that thread, or so I think.

    During an unsupervised installation of OpenOffice, an employee tried an uninstall that then caused many problems, just about making the pc useless. Problems occurred immediately following the attempted uninstall. 09/27/13. Unsure if original program installed was a genuine copy of OpenOffice.

    Folder icons for system stuff, like control panel and mycomputer and many others have been replaced by a generic icon, anti-virus program is disabled (unable to re-enable), firewall disabled (windows won't allow a re-enable), add/remove programs in control panel remains blank (unable to uninstall anything from that location as no programs appear), the 'all programs' menu in the START menu is disabled (cannot scroll programs), cannot access system restore (even in the system32 folder), and the list goes on. Cannot install most executables.

    Roguekiller ran as instructed. Log included.

    Malwarebytes tried to run/install. Got error msg preventing install right at end of progress. Code: 0x80040154 Class not registered. Run time error '372' Failed to load control 'WebBrowser' from ieframe.dll. Something about being outdated.
    No log, couldn't run program.

    TDSSKiller ran as instructed. Log included.

    Hitman Pro ran as instructed. Log included.

    MGtools ran as instructed with some resistance, however it did finish. Log/Zip included

    I'm really not interested in trying to re-install the OS as there is no optical drive and I'm not familiar with Windows OS installs from USB.

    Thanks for the help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are a few things to fix but let's first work on the ZeroAccess infection before doing anything else.


    • Exit any programs that you may have started. Shutdown protection software too.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • Rerun RogueKiller ( if running Vista,Win7, or Win8 user right-click and select Run as Administrator to run ) for WinXP and Win 2K just double click to run
    • Wait until Prescan has finished
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and attach the content of the Notepad into your next reply.
    • The log should be found in a new RKreport[x].txt on your Desktop
    • Exit/Close RogueKiller and reboot your PC.
    • After reboot attach the above RogueKiller log.
    • Now uninstall >> Search Protect by conduit
    • Now run new scans with RogueKiller and also Hitman Pro. Save the new logs and attach them too.
     
  3. aaron_kgs

    aaron_kgs Private E-2

    Roguekiller logs from before and after the scan/delete. 2 from before and 1 from after.

    Was able to uninstall the >> Search Protect by conduit --
    in the C:\Documents and Settings\current_user\Application Data\Search_Protect ---- folder.


    After the scan/delete/reboot, in RK, MS Anti-Virus (msseces.exe & msmpeng.exe) shows up in the system tray again, apparently working. However, under C:\Documents and Settings\All Users\Application Data\Conduit --- there was another similar Search Protect file structure, and I was unable to get the uninstaller located in that folder to run.

    Rebooted, ran Hitman Pro, ignored results. Log attached.

    Making progress, updated and running (currently) a full scan in MS Security Essentials, also trying to dump the Temp Files thru a disk cleanup (in progress, very slow)

    -Thank you-
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Looks much better but more to do.



    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select any of the following lines that still remain (some may be gone already ) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: Installl Converter - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - C:\Program Files\Installl_Converter\prxtbInst.dll
    O3 - Toolbar: Installl Converter Toolbar - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - C:\Program Files\Installl_Converter\prxtbInst.dll
    O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe
    O4 - HKCU\..\Run: [SearchProtect] C:\Documents and Settings\ARSIMS5\Application Data\SearchProtect\bin\cltmng.exe
    O4 - HKUS\S-1-5-21-1887795725-247674877-3292285946-1005\..\Run: [SearchProtect] C:\Documents and Settings\ARSIMS5\Application Data\SearchProtect\bin\cltmng.exe (User '?')
    O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe

    After clicking Fix, exit HJT.

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    CltMngSvc
     
    :Files
    C:\Documents and Settings\ARSIMS5\Local Settings\Temporary Internet Files\Content.IE5\GYIC2NZ9\SPSetup[1].exe
    C:\Documents and Settings\ARSIMS5\Application Data\PriceGong
    C:\Documents and Settings\ARSIMS5\Application Data\SearchProtect
    C:\Documents and Settings\ARSIMS5\Local Settings\Application Data\Conduit
    C:\Documents and Settings\All Users\Application Data\Conduit
    C:\Program Files\Conduit
    C:\Program Files\SearchProtect
    
    :Reg
    [-HKEY_USERS\S-1-5-21-1887795725-247674877-3292285946-1005\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-1887795725-247674877-3292285946-1005\Software\Smartbar]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{70D6D89D-919E-4D15-97CE-76818771D422}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6ec74131-08b2-4f67-a9bc-5914ef1edb97}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "SearchProtectAll"=-
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. aaron_kgs

    aaron_kgs Private E-2

    the other day, I had run a virus scan and the following was found and removed

    trojanDROPPER:win32/sirefef
    trojan:win32/sirefef!cfg

    also, was finally able to dump the temp files thru a disk cleanup.

    that was a couple days ago. today, I did the following:

    ran MG tools analyse.exe

    FIXED ---O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

    FIXED ---O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)

    FIXED ---O2 - BHO: Installl Converter - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - C:\Program Files\Installl_Converter\prxtbInst.dll

    FIXED ---O3 - Toolbar: Installl Converter Toolbar - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - C:\Program Files\Installl_Converter\prxtbInst.dll

    NOT FOUND IN SCAN RESULTS --O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe

    NOT FOUND IN SCAN RESULTS --O4 - HKCU\..\Run: [SearchProtect] C:\Documents and Settings\ARSIMS5\Application Data\SearchProtect\bin\cltmng.exe

    NOT FOUND IN SCAN RESULTS --O4 - HKUS\S-1-5-21-1887795725-247674877-3292285946-1005\..\Run: [SearchProtect] C:\Documents and Settings\ARSIMS5\Application Data\SearchProtect\bin\cltmng.exe (User '?')

    NOT FOUND IN SCAN RESULTS --O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files\SearchProtect\bin\CltMngSvc.exe

    after that I went to run OTM and got a system error message. Screenshots of the error message are attached (try to ignore the weird desktop in the background). Unable to run under any circumstances.

    I went ahead and ran JRT, log attached.

    also ran MGtools/GetLogs.bat --- MGlogs.zip is attached

    as far as how things are running, no appreciable change. icons are still jacked, some programs just won't open, the add/remove programs in the control panel is still just a blank icon with no description. unable to add/remove because the program list does not populate. start menu still won't allow to scroll thru programs. system restore, in safe mode, will bring up a window, but stays blank, just blank white. so, i'd say that things are just about where they were the other day.

    unsure why malwarebytes and OTM have both received error messages and were unable to run.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it did not remove it. That is what we fixed in my first fix to you. And it was successfully removed along with all the junctions it created.


    Now even though OTM did not run properly, the other steps finished removing the other junk.


    They should not be the same. According to your logs, things should be significantly better now because the infection had been removed. If it is not better then we have to check to make sure that some how you did not get reinfected. Please run new scans with both Hitman Pro and also RogueKiller and attach the new logs.


    There is still some apparent damage to the Windows Firewall service and some other services. So let's run the below in an attempt to fix these problems.


    Run the C:\MGtools\NetFWfix.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator). This will run very quickly and you may just notice a quick flash of a black command prompt window.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  7. aaron_kgs

    aaron_kgs Private E-2

    ran RK and HitmanPro, logs attached

    ran NetFWfix.bat

    ran Windows Repair and when I get to the Start Repairs tab, I get BSOD. Three or four times. Error msg -- "Stop C0000021a (fatal system error) The Windows Subsystem process was terminated unexpectedly"...and some more error codes. Then, within Windows Repair, I ran checkdisk (after a restart). Then I was able to run Windows Repair and get to the Start Repairs tab without it Windows crashing.
    Ran Windows Repair -> Start Repairs tab -> selected only those you had suggested + Icon Repair
    During the repair process I was getting an error message pretty consistently each time a new repair would run, something about a Remote Process Connection, nevertheless everything finished.
    After a restart, lost ICS, also Windows Firewall acted like it wanted to start, and then crashed/stalled. Internet connectivity has been lost. The machine seems to be speedier than before, but now no internet, still no firewall, unable to get System Restore to function (blank white window), and Star Menu still doesn't function correctly.

    Ran GetLogs.bat logs attached.

    Reran RK, log attached

    Without internet, I didn't run HitmanPro again

    Running out of ideas, I tried re-running OTM (which wouldn't work before) and now it worked. OTM log attached.
    Still no internet and so on.
     

    Attached Files:

  8. aaron_kgs

    aaron_kgs Private E-2

    Screenshots of ICS/Firewall fail attached
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Microsoft Security Essentials and then reboot your PC into safe mode to do the below. NOTE: If it does not install stop right here and tell me. Do not continue until it is uninstalled.

    Now in safe boot mode rerun Windows Repair as previously requested. Only run the repairs I ask for and nothing else. If it does not run properly, do not try it a second time. Just stop and tell me the exact word for word errors ( if any ) that you see.

    If Windows Repair ran okay, make sure that you have rebooted after running it but reboot in normal mode now and continue with the below.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    After clicking Fix, exit HJT.


    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • FSS.txt
    • C:\MGlogs.zip
     
  10. aaron_kgs

    aaron_kgs Private E-2

    Can't get MS Security Essentials to uninstall. See Screenshot. Can't find an uninstaller anywhere, not able to do it thru the control panel, so the only option was suggested to me by someone who knows more than I. That would be at this link -- http://go.microsoft.com/?linkid=9748340

    Repeat, can not figure out how to uninstall MS Security Essentials.
    Microsoft's uninstaller at the link above did not work. See screenshot.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's skip trying to uninstall MSE for now but do you have problems installing programs in general?


    Let's continue with the below steps.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - {6ec74131-08b2-4f67-a9bc-5914ef1edb97} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    After clicking Fix, exit HJT.


    Now boot in safe boot mode rerun Windows Repair as previously requested. Only run the repairs I ask for and nothing else. If it does not run properly, do not try it a second time. Just note the exact error messages and tell me the exact word for word errors ( if any ) that you see. However still continue with the below.

    Reboot your PC now into Normal Boot mode.


    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    Please attach this log to your next reply.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • FSS.txt
    • C:\MGlogs.zip
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds