Rootkit.zeroaccess!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Greynthewolf, Feb 14, 2013.

  1. Greynthewolf

    Greynthewolf Private E-2

    I was tempted to just try and follow one of the other threads on this, but the guide says to make a post with a detailed description, and to not try and jump any steps ahead, so that's what I'm doing.

    About a week ago I noticed videos and games that require flash started to make firefox really laggy. A flash object would start to load, then firefox wouldn't respond {(not responding)} for 30 seconds to a minute. As the week went on, it got gradually worse, now when I switch between any two windows like firefox to windows explorer, it will stop responding for a minute or two.

    I used malwarebytes' and superantispyware, as well as my antivirus program, Avira, but the only bugs I found were small (such as tracking cookies) and one trojan. I started looking deeper into my computer, the error logs, and I noticed I was getting errors having to do with my startup and shutdown speeds.

    I did some research, and someone suggested I try updating my windows drivers. That's when I noticed the windows update service wasn't able to do anything. In fact, in the service file, it's missing all together. I looked around for some answers, and it lead me to trying to unregister and re-register 5 dll files. When I tried to do that I got the error code 0x080070005, which I found out is supposed to mean I wasn't elevated (admin mode) when I tried registering the dll's. But I was! So I figured something fishy was going on, like a bad virus.

    I was all out of ideas, so I went to what, in my mind, was my last resort, Combofix. I've dealt with a few bad ones before, like the kind that hijack your browser, and fixed it with combofix. Well, when I ran Combofix, it told me that rootkey.zeroaccess! was in my tcp/ip. It then said it needed to restart, and to try again if it doesn't fix it. Is combofix supposed to start back up when the computer reboots? cuz it didn't, either time. Also, Combofix never made a log.

    I searched Rootkey.zeroaccess! and majorgeeks.com forum was the first result. I've gone through the Read and run me first guide, and the vista malware removal guide, and I followed the instructions. I'm still having the problem, so here's my log files.

    It hasn't disabled any other programs that I'm aware of, and I can get online

    BTW thanks for the detailed how-to guides and the organized layout. I'm learning quite a bit.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [TASK][SUSP PATH] OpenCandyHelperRunOnce : RunDll32.exe "C:\Users\Michelle\AppData\Roaming\OpenCandy\F7F512A300BB4E2786EC540234535317\OCBrowserHelper_1.0.3.85.dll",_OCRestartDll@16 [x] -> FOUND
      [STARTUP][SUSP PATH] NexDef Plug-in.lnk @Michelle : C:\Users\Michelle\AppData\Local\Autobahn\nexdef.exe [-] -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now click the Files/folders tab and locate these detections:


    • [Tr.Karagany][FOLDER] shed : C:\Users\Michelle\AppData\Roaming\Adobe\shed --> FOUND
      [ZeroAccess][FILE] @ : C:\Windows\Installer\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\@ [-] --> FOUND
      [ZeroAccess][FILE] @ : C:\Users\Michelle\AppData\Local\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\@ [-] --> FOUND
      [ZeroAccess][FOLDER] U : C:\Windows\Installer\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\U --> FOUND
      [ZeroAccess][FOLDER] U : C:\Users\Michelle\AppData\Local\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\U --> FOUND
      [ZeroAccess][FOLDER] L : C:\Windows\Installer\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\L --> FOUND
      [ZeroAccess][FOLDER] L : C:\Users\Michelle\AppData\Local\{0fe012a7-5b9a-258f-298f-d41e79b29c85}\L --> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now re-run Hitman and have it fix everything it found.

    Then reboot and rescan with both RogueKiller and Hitman and attach both those logs as well.
     
  3. Greynthewolf

    Greynthewolf Private E-2

    Thanks for the help. It took two separate scans to find the registry items you mentioned, and I couldn't find the folder/file items you listed. I scanned a few extra times, just to be sure. Here's the logs.
     

    Attached Files:

  4. Greynthewolf

    Greynthewolf Private E-2

    Here's the last two logs, after I rebooted.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re-run RogueKiller and have it remove this item:
    [STARTUP][SUSP PATH] _uninst_01792744.lnk @Michelle : C:\Users\Michelle\AppData\Local\temp\_uninst_01792744.bat [-] -> FOUND

    Reboot and rescan. Attach the new log and be sure to tell me what issues you may still be having, if any.
     
  6. Greynthewolf

    Greynthewolf Private E-2

    Wow, big difference in performance, thank you!

    The only issues I seem to be noticing is slow boot-up and shut-down times. Any tips?

    Here's the log. And thanks again, you're awesome!
     

    Attached Files:

  7. Greynthewolf

    Greynthewolf Private E-2

    Thanks for the help. Major improvement in performance.

    The only thing I'm still having issues with are slow start-up and shut-down speeds. I watched several youtube videos with minimal lag. Oh, but all of a sudden as I was typing this, firefox froze up on me several times. Hmm, any tips?

    Thank you, again, your help is much appreciated.

    Here is the last log, after reboot.

    BTW, I posted (I thought I did anyway) basically this same post about 30 min before this, but when I went to check for a response, I couldn't find it. Weird.
     

    Attached Files:

  8. Greynthewolf

    Greynthewolf Private E-2

    Sorry for the triple post. I'm finally able to see my first of the three (dunno if it's a problem with these forums, or if it's just on my end).

    Just an update on my pc's performance. I was trying to watch church online this morning, and my pc crashed. I finally got it to play though. Then after church, I tried watching a youtube video, but it froze up several times, finally crashing firefox. My pc is running a little better than before, as long as I don't use the internet (more specifically anything with flash).

    Oh and one more thing, typing this post was total hell. I was only able to type one or two words at a time, in between firefox freezing.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  10. Greynthewolf

    Greynthewolf Private E-2

    Unfortunately, no change, and afterwards when firefox was reloading, it crashed my computer, bsod. Also, after my post I noticed it even did it on a plain text web page. Also, I've discovered another problem I didn't have before all this. I went to play a game of Spider solitaire and got this message:
    Critical Error
    No suitable graphics devices found

    And this is a game I play frequently with no problems.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Those are system issues, not malware. I suggest you post in the software forum for assistance with that.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds