![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
Noticed that the internet was slow and that I was getting a Google redirect in the last week or so.
Tried the READ ME FIRST process, but I don't think it is completely gone. Your help is greatly appreciated. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
MGTools Log
|
|
#3
|
||||
|
||||
|
I want you to run TDSSKiller so refer to the below for how to do so.
TDSSkiller - How to run Please also download MBRCheck to your desktop
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#4
|
|||
|
|||
|
Logs from TDSSkiller & MBRCheck.
|
|
#5
|
||||
|
||||
|
We need to use ComboFix by sUBs
Code:
KILLALL::
DirLook::
c:\documents and settings\Desk\Local Settings\Application Data\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}
c:\documents and settings\All Users\Application Data\F4D55F170000706500037C80D151FC4E
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\userinit.exe,"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
"NecUsb3Sevic"=-
File::
C:\windows\system32\USB3Nw32.dll
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Ran Combofix with the additional script. Still detected Rootkit.ZeroAccess! inserted itself in tcp/ip stack.
Combofix restarted the computer a couple of times then ran Getlogs.bat. Error occurred with Getlogs "Unexpected error has occurred at proceedure: Modregistry_IniGetstring(sFile=system.ini, sSection=boot, sValue=Shell) Error #5 invalid procedure call or argument" Your continued assistance is greatly appreciated. |
|
#7
|
||||
|
||||
|
Now we need to use ComboFix by sUBs
Code:
KILLALL:: Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NecUsb3Sevices]
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#8
|
|||
|
|||
|
Combofix is still detecting Rootkit.ZeroAccess! inserting itself into tcp/ip stack.
Also, when I use Google to search sometimes the search results appear flush left and sometimes they appear centered in a column on the left half of the page. Perhaps I need to run the Google redirect process? (but only if & when instructed). |
|
#9
|
||||
|
||||
|
This should (hopefully) nail it. I missed this before, let's try this:
Now we need to use ComboFix by sUBs
Code:
KILLALL::
Folder::
c:\documents and settings\Desk\Local Settings\Application Data\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}
c:\documents and settings\All Users\Application Data\F4D55F170000706500037C80D151FC4E
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this. Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#10
|
|||
|
|||
|
Ran Combofix- Showed Rootkit.Access inserted itself in tcp/ip stack and rebooted
Combofix ran again upon reboot and some folders and files were deleted. Ran GetLogs.bat and unexpected error previously noted came up "ModRegistry_IniGetString (sFile=system.ini, sSection=boot, sValue=Shell) Error #5 Invalid procedure call or argument" |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Logs uploaded
|
|
#12
|
||||
|
||||
|
Now we need to use ComboFix by sUBs
Code:
KILLALL:: Driver:: NecUsb3
Note: Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#13
|
|||
|
|||
|
Ran Combofix- Detected Rootkit.ZeroAccess- Rebooted
Combofix ran at startup- no deleted files/folders- rebooted created log Reran Combofix immediately and Rootkit.ZeroAccess is still detected. Closed Cokbofix without finishing scan, but no log from initial run listed in C: |
|
#14
|
||||
|
||||
|
Hang in there, I am going to have to seek further advices with colleagues about this.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| The Following User Says Thank You to Kestrel13! For This Useful Post: | ||
mattstanfill (04-10-12) | ||
|
#15
|
||||
|
||||
|
Thanks for your patience. Chaslang has advised me on how to proceed.
![]() Download OTL to your desktop.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Attach both of these logs into your next reply.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” Last edited by Kestrel13!; 04-12-12 at 05:51.. Reason: removed unecessary steps |
| Sponsored links |
|
|
|
#16
|
|||
|
|||
|
Ran OTR without issue and have logs. However, trying to start using F8 does not give me an option to "Repair Computer" (I'm using XP).
When I start the Windows Recovery Console, I cannot enter the appropriate commands in the prompt (I only have "C:\Windows\_" Please advise about XP steps and I cannot locate my install disc. |
|
#17
|
||||
|
||||
|
Sorry my bad. Please attach the OTL log.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#18
|
||||
|
||||
|
Please download this and transer it to your PC.
Please download Farbar Service Scanner and run it on the computer with the issue.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
|
#19
|
|||
|
|||
|
OTL logs attached and ran Farbar, but it gave a log names FRST.txt (not FSS.txt as noted in your previous post).
|
|
#20
|
||||
|
||||
|
We need to run an OTL Fix
Code:
:otl
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}: C:\Documents and Settings\Desk\Local Settings\Application Data\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}\
:files
C:\Documents and Settings\Desk\Local Settings\Application Data\{3E2ACFA1-7C48-11E1-826D-B8AC6F996F26}
C:\WINDOWS\System32\itldvupd.dat
C:\WINDOWS\System32\itlsvc.dat
C:\WINDOWS\$NtUninstallKB36490$
:commands
[EMPTYTEMP]
[RESETHOSTS]
[REBOOT]
Now run Combofix again and attach the new log please. Let me know if it is still shouting about rootkit activity.
__________________
Have we been helpful and you would like to show your gratitude? Support MajorGeeks Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies “The truth is, everyone is going to hurt you. You just got to find the ones worth suffering for.” |
| Sponsored links |
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit.zeroaccess | kbtrade | Malware Removal | 1 | 02-25-12 21:58 |
| Rootkit.zeroaccess | mpetro1 | Malware Removal | 12 | 12-29-11 16:04 |
| Help with rootkit.zeroaccess | elias7 | Malware Removal | 3 | 12-21-11 11:04 |
| ZeroAccess Rootkit | zq1 | Malware Removal | 6 | 12-06-11 22:39 |