Help with possible trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by bobd, Jul 21, 2012.

  1. bobd

    bobd Private E-2

    I think I may have ZeroAccess or a similar infection on my Windows 7 Ultimate 64 bit laptop.

    I had ZoneAlarm anti virus and firewall installed and it picked up a problem with some files after I ran a downloaded executable. It seemed to clear things up, but after a reboot I have problems connecting to the internet. (Due to uninstalls and other installs I have since done to try to fix the problems, I no longer have the log files that say what was infected or with what, but I think I saw something like GAC64/desktop.ini and some other files).

    The laptop can now see the router and can see that the router can see the internet, but cannot connect to anything itself. If I turn off the ZoneAlarm firewall then everything works. If I try to turn on the windows firewall, I get a screen with Use Recommended Settings, but clicking that comes up with 80070424 error.

    I have run a ZoneAlarm scan, a Sophos Scan, a MalwareBytes scan, and none of them pick anything up (and I have since uninstalled Sophos as per the instructions so I only have one AV installed).

    I have noticed that my services.exe in c:\windows\system32 has a modified date and time of around the time of the infection, and that Windows Firewall does not appear in my list of services.

    I have also found that my registry has one of the entries that Google suggests are related to ZeroAccess (HKCU/Software/Classes/CLSID/{42aed.......feabec1} which is set to look at a locally downloaded file.

    I am working through the process if getting my logs to attach, but when I try to run RogueKiller my laptop complains that "The version of this file is not compatible with the version of Windows you are running. Check your computer's system information to see whether you need an x86 (32-bit) or x64 (64-bit) version" (though I have downloaded the version from the READ & RUN ME FIRST post which did not have a 32 bit and 64 bit version).

    I am generating the other logs, but I am not sure if it is important to run them in the exact order specified, but I have attached them all anyway so as to give as much information as possible.

    Although I can get internet access (by disabling the firewall) I ran all the scans without internet access, as I am too alarmed by the possibility of further infections or bot activity.

    All files have been transferred to and from the laptop to another fully working laptop on a USB key.

    Please help! :)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    There are no signs of an active ZeroAccess infection but you do show signs of having had one. i.e., the broken internet access, broken Windows Firewall, and several other services. Let's see if we can fix this.

    First see if you can delete the below left over folders:
    C:\Windows\installer\{bff0f490-87a6-5ec4-8874-d9184deff207}
    C:\Users\BobD\AppData\Local\{bff0f490-87a6-5ec4-8874-d9184deff207}


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  3. bobd

    bobd Private E-2

    Hi chaslang, thanks for the reply.

    Before I get onto the results, some more information from the original state oif the machine that I forgot to include in the first post (sorry!).

    I tried doing a system restore to a date before the infection, but this failed as it was "unable to update some files". I tried it in Safe Mode too and had the same error. My firewall and antivirus were off at the time of trying.

    OK, so I tried following your instructions below, and had a few problems. I downloaded the windows repair zip on my working laptop and put in on a USB to transfer to the bad one. When unzipping it to the desktop I got a an error copying msinet.ocx, and it refused to copy it at all (even in Safe Mode). To get round this, I unzipped things on the USB on the good laptop, and then copied all the unzipped files over to the bad laptop.

    I then ran it as instructed. On stage 1 I had problems with subinacl.exe stopping working (with the choice to search for a solution or close the program). I chose to Close it. This happened 4 times in stage 1.

    The rest of the process completed without errors and very quickly, about 10 minutes at most for the whole thing.

    My firewall was off after the reboot, and when I tried the Turn Firewall On or Off thing again I got just a page with Use Recommended Settings. Pressing this then gave me "Can't change some of your settings" and 80070042c, which is I think the same message as before but with 42c rather than 424.

    Looking in my services, Windows Firewall is there now, which it wasn't before the repair. Base Filtering is also there, though I didn't check before to see it was there or not. Both are listed as Automatic, but neither is running. I have not hit Start on either of them, as I thought I would wait for further instructions.

    C:\windows\system32\services.exe is still showing as last modified on the date and time of the original infection.

    My laptop is now running with (I think) a plain scheme, it is not my customized Aero scheme, nor the default one, so some elements of my customization have been applied. I think it is running in non Aero mode. Again I have not tried resetting it back to my theme yet.

    I have not yet tried the internet access or turned on ZoneAlarm firewall, as much of the above still suggests (to me at least!) that I may still have problems, and the repair was suspiciously fast (after your warnings that I should go to bed while it ran!)

    New logs attached.

    Thanks.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The ZIP file you attach was corrupted and of no use. Let's try a different fix using the same tool but with no permissions fixes. Please boot into safe mode first before running it this time.


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Boot in normal mode for the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).




    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. bobd

    bobd Private E-2

    Hi.

    Sorry, don't know happened with the zip file. I have checked this one before uploading it and it seems fine.

    I have done as requested, and again it all ran in about 5 mins.

    No noticeable changes after running it.

    Firewall is in the the Services list as before, as Automatic but not running. Trying to Start if from Services gave "Error 1068 The dependency service or group failed to start".

    The Base Filtering Engine is also listed as Automatic but not Started. Trying to run it from Services gives "Error 5. Access is denied"

    Trying to start the firewall from Windows Firewall in Control Panel still gives "0x8007042c" error.

    services.exe still has a modified date/time of around the time of infection.

    Thanks for your help so far.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We need to get the permissions issues fixed so that these services can be started. We will try a different way.

    Not a problem. It is the one we used to replace the infected one.




    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  7. bobd

    bobd Private E-2

    OK. I just mentioned the services.exe timestamp as I don't think it has ever changed since the infection, (so it had this timestamp before we started dealing with it), so I assumed the modification was caused by the infection, not by attempts to fix it.

    I have done as you requested. Whilst running the cmd file I could see lots of fails in the permission resetting. Just in case it doesn't remain on screen when done, it has currently done 42000, and failed on about 9000 of them, give or take.

    Now it is up to Done 185000 Failed on 47561.

    Had to take a phone call and missed the screen changing to show something else, but now it is back to the red banner and counting up registry entries again. Possibly doing a different branch of the registry. It is now on HKCR, didn't notice what it was on before.

    It is currently on Done 78000, Failed 21600

    OK, that pass has finished, and there was briefly a screen of normal white next on black, which did have an "error 5" displayed. I didn't catch it for long enough to read more.

    Now started on setting file permissions.

    (You probably don't need or want any of this stuff, sorry!)

    Missed out on watching the rest.

    After reboot, Base Filtering Service is running, and so is Windows Firewall! :)

    New logs attached. Hey, SteelWerX WhoAmI didn't stop working this time!

    I still haven't tried accessing the internet, with or without firewall, even though things seems to have improved.

    Thanks
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Looks good now.

    You have ZoneAlarm running.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  9. bobd

    bobd Private E-2

    Brilliant!

    Things all seem to be working again. :)

    Thank you very much indeed!

    Quick question about the "Protect yourself from malware" post. As you know, I have Zonealarm Free AntiVirus + Firewall, version 10.x I think. This is not mentioned on that post, and the Zonealarm version that is there is not recommended. Is the version I have good enough to keep, or should I switch to an AV and a Firewall mentioned in the post?

    Thanks so much for getting things sorted.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    It's not high on my list. Nor on Matousec ( link was in the How to Protect thread in the firewall section ) But see http://www.matousec.com/projects/proactive-security-challenge/results.php#products-ratings

    Are you happy with it? I would suggest Avira for antivirus and one of the better higher rated free firewalls.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds