Suspecting Acess Zero part 2

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by blink10, Nov 23, 2011.

  1. blink10

    blink10 Private E-2

    I Apologize for disturbing you guys. i ran Combofix just to be on the safe side because I did not want to format this PC again.You will find the log here
     

    Attached Files:

    • log.zip
      File size:
      2.7 KB
      Views:
      1
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If this is for your brother's PC, then you need to stay in the thread you already started for it, but more importantly, we cannot help you by just seeing a ComboFix log. While it is useful, it does not provide all the information required to analyze a PC's malware status. In addition, it should NEVER be the first thing you run.
     
  3. blink10

    blink10 Private E-2

    Ok, Chaslang I shall dedicate this thread to my PC. I ran SAS and MBAM but now I dont know if I should run combofix as your "Read and Run me" says because I already ran it the first thing when access zero crippled the PC.

    The logs of Combofix , SAS, and MBAM

    Should I run Combofix again or not?
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just skip ComboFix and continue with RootRepeal and MGtools.

    Also explain what problems you are having with your PC.
     
  5. blink10

    blink10 Private E-2

    I ran Rootrepeal it said 8 hidden processes are running under the files button even though in the report it doesnt mention that. Sometimes when I reboot the PC reaches the desktop but it just freezes there , that happened more than 4 times now.
    Kaspersky my antivirus caught a file called wbem.exe and many other programs that seem to be of low importance (because I set it to scan for legal programs with the possibility to endangering the PC)
    Kaspersky made a full scan and then it is nagging me about a post infection system restore.
    Now for the first time since this problem started , I had to resort to safemode with networking.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on all the logs attached here, you do not appear to be having malware problems. We will run two more scans just to be sure, but you may just be having problems with Windows itself.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  7. blink10

    blink10 Private E-2

    It is strange , I posted a reply and now I cannot find it!!
    Anyway , here are the reports.
    On rebooting safe mode, I opened msconfig and found 2 instances of rundle32.dll in start up , so I unchecked both of them. PC has been working normally ever since. Should I uninstall combofix now? and kasper is requesting a post infection system restore
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually there were the below three and all are valid
    Whether you need them or not is a different topic, but they are not malware and all of your logs were clean.


    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds