![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I am helping a friend who can't get internet access. After running all the programs you suggest (logs attached) we still can't get an IP address. I will attach MGLogs.zip on next post.
So we are not able to get an IP address and Combofix still shows the rootkit.ZeroAccess. Thank you in advance for any assistance. |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Here is the MGLogs.zip file as requested.
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
Please download Farbar Service Scanner and run it on the computer with the issue.
Now continue on with the below.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
craigceg (04-13-12) | ||
|
#4
|
|||
|
|||
|
Chaslang: Thank you for your attention to this problem. Here is the FSS.txt file as requested.
|
|
#5
|
|||
|
|||
|
I have completed the steps requested and now have Internet access again. Attached are the two files requested.
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
Okay that's good news.
Now please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
craigceg (04-13-12) | ||
|
#7
|
|||
|
|||
|
Here is the SystemLook log. It looks like there is only registry entries, but the files don't actually exist. Could that be why ComboFix keeps thinking there rootkit activity because of the registry entries?
|
|
#8
|
||||
|
||||
|
Quote:
Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
See the download links under this icon
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
craigceg (04-13-12) | ||
|
#9
|
|||
|
|||
|
Thanks again for your follow up. Unfortunately I returned the computer to my friend. But I believe it was clean as I had already removed the registry entries that were found by SystemLook. I had already run TDSSkiller after SystemLook and it did not find anything. I also ran Combofix again after removing the registry entries and it did not warn about a rootkit this time. I finished up by uninstalling combofix and MGclean.bat. I reinstalled AVG and completed all Windows updates and it appeared to be running smoothly again.
I did not get a chance to run MBRCheck, but if I hear back from him with a continuing problem I will run that. Again, thank you for your help! ![]() |
|
#10
|
||||
|
||||
|
You're welcome.
But do note that the below folder is from the ZeroAccess infection: C:\WINDOWS\$NtUninstallKB10283$
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| Sponsored links |
|
|
|
#11
|
|||
|
|||
|
Thank you for the final note. I have made note of that folder and will remove it when I speak to my friend.
|
|
#12
|
||||
|
||||
|
You're welcome. Note that there is a possibility that you may be able to see the folder if any part of the infection is still hiding it.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit zeroaccess | SparklyFudly | Malware Removal | 2 | 04-02-12 20:31 |
| ZeroAccess Rootkit | ComputerHack | Malware Removal | 8 | 03-13-12 22:52 |
| Rootkit.zeroaccess | mpetro1 | Malware Removal | 12 | 12-29-11 16:04 |
| HELP please - Rootkit.Zeroaccess | argentia | Malware Removal | 15 | 10-02-11 00:19 |