Nasty bug!!!!! can't run any "READ & RUN ME FIRST"

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by schneider, Oct 22, 2011.

  1. schneider

    schneider Private E-2

    I'm desperately seeking help from all of you who are smarter than me. In fact I'm ready to call my old University up and tell them I want a refund for my Comp Sci degree! It's been a rough night.

    Computer is HP laptop, Vista 32bit

    Long story hopefully short:

    1. Browser started redirecting (ex. search for Yahoo, click yahoo, and you are directed somewhere else other than Yahoo)

    2. Bosses computer and the virus software they bought expired so I tried to download some freeware like AVG. I wasn't able too. I couldn't d/l anything. Some kind of Windows Installer problem.

    3. It took a long time but I was able to update Windows and download Service Pack 2 (Vista).

    4. I then came here and read and followed the "Read and Run me first" sticky. After the initial steps and house cleaning I was able to d/l all the tools (Superanti, Malware, MGtools, etc)

    5. When I was finally ready to run the tools they would install and start to run but immediately vanish. Ex. I would install Superanti, start the scan, then it would stop scanning and the gui would vanish. When I tried to open it back up to run I got an error message stating I don't have permission (I do have permission and was using the administrator account)

    6. This happened for all the tools except ComboFix. Combofix ran and populated a log (I can't get any other tools to run therefore no other logs.)

    Combofix tells me I'm infected with "Rootkit.zeroAcess!" in my tcp/ip stack

    I'm attaching the only log I can get. This system is business critical and I'm up a creek if I mess something up. I played around and thread the needle too much tonight. I need help and am done with IT if I can get out of this one.

    Also, I have no idea how long these problems have occurred as I just started and offered to be a nice guy and get rid of, what I thought was, a simple trojan.

    Thank you in advance to any and all that might be able to help me heal this computer!
     

    Attached Files:

    • log.txt
      File size:
      17.1 KB
      Views:
      5
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. schneider

    schneider Private E-2

    Hola,

    Thank you for the reply. After last nights frustration, I shutdown and went to bed. I powered up the system today and it's working (meaning I'm not having re-direct problems, I can download all day long, and all my virus/malware tools will finally run).

    Since I could only get ComboFix to run yesterday, I'm assuming it found and healed the infection that was preventing my from running the scanning tools.

    1. I ran a quick scan in Superanti and it found 2 Trojans. Then I ran a complete scan in SuperAnti and it found 2 more trojans.

    2. I d/l AVG free and ran a complete scan. It found 9 infections and removed them.

    3. I'm currently running Malwarebytes and it looks like it has found a few infections too.

    Should I now attach these logs? Or just d/l OTL and attach that log per your instruction?

    Thanks!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you are ready, attach all the logs.

    SAS
    MBAM
    OTL -- both.
     
  5. schneider

    schneider Private E-2

    Here are the (2) OTL logs, SAS, and MBAM.

    The MBAM log isn't from a complete scan. I was having some troubles... it scanned for over 2 hours and was getting hung up on some old IE5/temp Inet Files folder. It would still scan but was taking forever.

    I stopped the scan and let Mbam heal the 3 infections it found. That's the log you are seeing.

    I decided to run it again. This time it ran for 3 hours and slowed to a stop again at that same IE5 folder. I can't keep waiting so I ended that Mbam scan too. I'm not attaching that log.

    I think I may have to go to that folder and manually delete a ton of old Internet temp files.

    Thank you for taking the time to look at these log files for me. I really do appreciate it!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not looking that bad.

    Double-click OTL.exe to start the program.

    • Copy and Paste the following code into the Custom Scans/Fixes textbox. Do not include the word Code

    Code:
    :processes
    :otl
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
    O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    
    :files
    C:\CC86DDFA4E44E0F0C9AFCE174D
    C:\291ECBEAE5DE6029C38E
    C:\2a539a45a3b49efe1b7856
    
    :commands
    [PURITY]
    [EMPTYTEMP]
    [RESETHOSTS]
    [REBOOT]
    
    
    • Then click the Run Fix button at the top.
    • Click the OK button.
    • OTL may ask to reboot the machine. Please do so if asked.
    • The report should appear in Notepad after the reboot. Just close notepad and attach this log form OTL to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds