![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I've tried all I know to remove this bugger. Time for help from the experts.
Zeroaccess has infected my ipstack and I can't get an ip address frpom DHCP. Here are my logs: |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
Here is the mgtools log:
|
|
#3
|
||||
|
||||
|
Welcome to Major Geeks!
Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
Now please download OTL by OldTimer.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#4
|
|||
|
|||
|
Here is the log from Systemlook. The OTL lg is 504kb which exceeds the upload limit. Apparently there is no extra.txt log as well.
|
|
#5
|
|||
|
|||
|
I broke the OTL log into 2 parts and uploaded them.
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
Java(TM) 6 Update 16 Java(TM) 6 Update 24 Now install the current version of Sun Java from: Sun Java Runtime Environment Now shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
Code:
:OTL
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\transactional.dll -- (Xyz777b)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\oracleorahomehttpserver.dll -- (REVO)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\oracleorahome92pagingserver.dll -- (point32)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\websensepolicyserver.dll -- (oracleorahome92tnslistener)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\VAIOMediaPlatform-VideoServer-HTTP.dll -- (OracleOraHome92ClientCache)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\dac960nt.dll -- (oracleoradb10g_home1isql*plus)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\msftpsvc.dll -- (lxcr_device)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\vpcvmm.dll -- (lxcc_device)
SRV - File not found [Disabled | Stopped] -- %systemroot%\system32\https-admserv61.dll -- (lxby_device)
SRV - [2010/12/14 13:12:00 | 000,182,768 | ---- | M] (Google) [On_Demand | Stopped] -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-4077326862-4270047272-744067899-1005\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_24)
NetSvcs: 0 - C:\WINDOWS\0.log ()
NetSvcs: 1 - File not found
NetSvcs: 9 - File not found
NetSvcs: lxby_device - %systemroot%\system32\https-admserv61.dll File not found
:Files
C:\WINDOWS\$NtUninstallKB62840$
C:\Documents and Settings\Jonathan Rush\Local Settings\temp\Kno4.tmp
C:\WINDOWS\System32\drivers\i8042prt.sys|C:\WINDOWS\System32\dllcache\i8042prt.sys /replace
:Reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
:Commands
[PURITY]
[EMPTYTEMP]
[EMPTYFLASH]
[REBOOT]
Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
chipndale (04-16-12) | ||
|
#7
|
|||
|
|||
|
You are the wind beneath my keyboard!!! The Internet is back up and no more error messages. I will install a retail version of Kaspersky I have next.
Thank you again so very much! |
|
#8
|
||||
|
||||
|
You're welcome. Your logs are clean.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Rootkit.zeroaccess | kbtrade | Malware Removal | 1 | 02-25-12 21:58 |
| Rootkit: ZeroAccess | jschaf01 | Malware Removal | 15 | 02-25-12 18:39 |
| Help with Rootkit.ZeroAccess! | christophersquid | Malware Removal | 30 | 02-22-12 12:48 |
| Rootkit.zeroaccess | mpetro1 | Malware Removal | 12 | 12-29-11 16:04 |
| Help with rootkit.zeroaccess | elias7 | Malware Removal | 3 | 12-21-11 11:04 |