ZeroAccess virus...???

Discussion in 'Malware Help (A Specialist Will Reply)' started by Fhoosa, Jul 15, 2013.

  1. Fhoosa

    Fhoosa Private E-2

    I had this virus/infection a couple of weeks ago and thought it was gone.
    I am unable to access MS Security Essentials. It shows that it is stil running but I can't get into it. Other problems that I have noticed isare: 1) I can't access my shared files/folders. Discovery won't stay on. 2) The "In-bound Rules" in my firewall are gone. 3) My Listen Port of TCP is being locked by my Firewall and 4) My NAT Port failed (UPNP device not found.

    I'm sure there are other things wrong but these are all I remember right now.

    Thanks in advance for your help.

    Fhoosa
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run Hitman Pro again and this time allow it to remove the Malware Remnants of ZeroAccess and also allow it to perform the Repairs on Microsoft Esseential Securities and Windows Defender. Those junctions are the cause of your problems.

    Then immediately reboot your PC.

    After reboot, run a new scan with Hitman Pro, save a new log and attach it to your next message. Also tell me if things are working any better.
     
  3. Fhoosa

    Fhoosa Private E-2

    Hi...Thanks for getting back to me so quickly.

    I won't be able to use HitManPro to remove or repair any files. I used the program before and when I try it, it tells me that my trial period has ended.

    What do I do now?

    Fhoosa
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    • Exit any programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • Rerun RogueKiller ( if running Vista,Win7, or Win8 user right-click and select Run as Administrator to run ) for WinXP and Win 2K just double click to run
    • Wait until Prescan has finished
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and attach the content of the Notepad into your next reply.
    • The log should be found in a new RKreport[x].txt on your Desktop
    • Exit/Close RogueKiller and reboot your PC.

    Any change?
     
  5. Fhoosa

    Fhoosa Private E-2

    Here is the report that you requested.
     

    Attached Files:

  6. Fhoosa

    Fhoosa Private E-2

    I thought I'd let you know that after I re-booted the computer I was still not able to access Microsoft Essentials. Do I have to uninstall it and then re-install it?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well per your logs it did not even show as installed anymore. See if you can even find it to uninstall it. If you can then uninstall it. But do not try to reinstall yet.

    First I want you to run a new scan with Hitman Pro and attach the new log. I want to double check that RogueKiller was successful.


    Other than the problem with Microsoft Essential Security, how are things working.
     
  8. Fhoosa

    Fhoosa Private E-2

    Hi,

    I was just wondering if you got the last report that I sent you.

    Fhoosa
     
  9. Fhoosa

    Fhoosa Private E-2

    Hi,

    Well, here's the report. Doesn't look too good, does it?

    As for the other problems I was having, my file sharing is back up and working and my listen port on BitComet is back, also.

    Microsoft Security Essentials is still listed in my Add/Remove Programs but when I tried to uninstall it, it said that the files weren't there.

    So, what do you think?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well it is better than it was before but still not all fixed.

    Please run the below anti-rootkit tool from Malwarebytes.

    http://blog.malwarebytes.org/news/2013/05/malwarebytes-anti-rootkit-beta-1-06/

    Attach a log from the above.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\$RECYCLE.BIN\S-1-5-18\$cfe03e2d765475ba7fa69eb3d6b04dc3\L
    C:\$RECYCLE.BIN\S-1-5-18\$cfe03e2d765475ba7fa69eb3d6b04dc3\U
    C:\$RECYCLE.BIN\S-1-5-18\$cfe03e2d765475ba7fa69eb3d6b04dc3
    C:\$RECYCLE.BIN\S-1-5-21-3197802315-1125251100-3617295894-1000\$cfe03e2d765475ba7fa69eb3d6b04dc3\L
    C:\$RECYCLE.BIN\S-1-5-21-3197802315-1125251100-3617295894-1000\$cfe03e2d765475ba7fa69eb3d6b04dc3\U
    C:\$RECYCLE.BIN\S-1-5-21-3197802315-1125251100-3617295894-1000\$cfe03e2d765475ba7fa69eb3d6b04dc3
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • The Malwarebytes AntiRootkit log
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. Fhoosa

    Fhoosa Private E-2

    Hi,

    I've got the first report for you but am having a problem with th OTL one. You said to copy/paste the line into the codebox, which I did. But I'm having trouble understanding the next part. I don't see a MOVE IT button.

    What am I doing wrong?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download OTM not OTL. ;)
     
  13. Fhoosa

    Fhoosa Private E-2

    Ok, I feel really stupid at this point. I did download the correct one this time but I'm running into a problem finding the moved files.

    Let me tell you first that all the programs that you had me download, I couldn't do it from my computer. It kept telling me "Service Returned Unexpected Status Code" Error: Download stopped.

    So I had to use my husband's computer and download them to a flash drive. I know that this is the problem because I found the MovedFiles folder in the flash drive, but it was empty.

    Please tell me I didn't screw things up.
     
  14. Fhoosa

    Fhoosa Private E-2

    I found out what the problem was in regards to the OTM Report. I didn't let it run its entire course. I thought it was done when it wasn't. So all the reports are attached (except Malwarebytes that I sent you earlier). I still am puzzled why I wasn't able to download the 4 programs on my computer. Any suggestions why?
     
  15. Fhoosa

    Fhoosa Private E-2

    Sorry...forgot to attach the files. Here they are.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't really know. What browser were you trying to use to do your downloading?

    Your logs are looking pretty good now. Let's double check on the junctions we have been trying to remove. Please run new scans with both RogueKiller and Hitman Pro and attach new logs.
     
  17. Fhoosa

    Fhoosa Private E-2

    I am using IE9, like I always have. All other downloads work, except for the .exe ones.

    How does everything look? And what should I do about Microsoft Essentials?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You could be blocking EXE downloads. Have you tried downloading them with another browser? Also try disabling your firewall temporarily to see what happens.

    Please complete what I requested in my last message.
     
  19. Fhoosa

    Fhoosa Private E-2

    I sent you all 4 reports. Is that what you are talking about?
     
  20. Fhoosa

    Fhoosa Private E-2

    I somehow overlooked your request. Here are the reports.

    Also, how do I go about getting the .exe files to dowload?
     

    Attached Files:

  21. Fhoosa

    Fhoosa Private E-2

    Turning off Firewall allowed me to download the .exe programs.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so we have at leaste proved that this issue is not related to malware. You have somehow managed to configure your firewall to block this.

    The junctions to Microsoft Security Client still appear. Let's try a few things.

    First shutdown ALL protection software before continuing. Now we are going to try using RogueKiller and Hitman Pro again.

    • Exit any programs that you may have started.
    • Please disconnect any USB or external drives from the computer before you run this scan!
    • Rerun RogueKiller ( if running Vista,Win7, or Win8 user right-click and select Run as Administrator to run ) for WinXP and Win 2K just double click to run
    • Wait until Prescan has finished
    • Then Click on "Scan" button
    • Wait until the Status box shows "Scan Finished"
    • click on "delete"
    • Wait until the Status box shows "Deleting Finished"
    • Click on "Report" and attach the content of the Notepad into your next reply but do not send this reply until later at the end of the below.
    • The log should be found in a new RKreport[x].txt on your Desktop
    • Exit/Close RogueKiller and immediately reboot your PC.
    Shutdown protection software again.

    Now rerun Hitman Pro and if the below still appear, allow Hitman to repair these
    Code:
     
       Redirection: Backup -> c:\windows\system32\config
       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)
       Redirection: Drivers -> c:\windows\system32\config
       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)
       Redirection: en-us -> c:\windows\system32\config
       Disables Microsoft Security Essentials (C:\Program Files\Microsoft Security Client)
    
    If Hitman Pro found those and your tried to repair then immediately reboot your PC.



    Now please download Win32kDiag to the root of your C:\ drive. It must be saved here or the below will not work!
    • Now press and hold the http://img849.imageshack.us/img849/4325/windowkey.gif Windows key on your keyboard, then press the letter r on your keyboard.
    • This opens the Run dialog box.
    • Then copy the below bold text and paste it into the Open: text-field and press ENTER.
      C:\win32kdiag.exe -f -r
    • When it's finished, there will be a log called Win32kDiag.txt on your desktop.
    • Attach this log to your next message. (How to attach items to your post)
    Now we need to rerun Hitman Pro and create another new log.



    Attach the log below logs now:
    • the new log from RogueKiller
    • the Win32kDiag.txt log
    • the new Hitman Pro log
     
  23. Fhoosa

    Fhoosa Private E-2

    I'm having a problem with downloading Win32diag.exe. It won't let me. It's funny. It will let me download some .exe programs, but not others. Do you want me to send you the two reports now?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps it does not want to let you save it to your root folder? Is that what you mean? If so then save it to your Desktop and then copy it to the root folder afterwards.
     
  25. Fhoosa

    Fhoosa Private E-2

    It dosn't seem to want me to download it at all. Everytime I clicked on the link, it brings me to a blank screen.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you shutdown ALL protection software? Try a different browser instead of IE.
     
  27. Fhoosa

    Fhoosa Private E-2

    Finally got it to work. Here are the reports.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay it looks like those junctions were finally removed. How are things working now?
     
  29. Fhoosa

    Fhoosa Private E-2

    Everything seems to be ok. What do I do about Microsoft Essentials?
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you uninstall it now?

    Try the below to uninstall it if necessary:

    Revo Uninstaller 1.95
     
  31. Fhoosa

    Fhoosa Private E-2

    Good Morning...

    Yes, I was able to uninstall it and I went ahead and installed a different security program. Have you heard of 360 Internet Security 2013? I decided I wanted to try something else so read up on this one and it sounded ok. Do you have any suggestions for a security program that works super good? I'd love to hear your thoughts.

    So, is my computer clean?
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They all have good points and bad points. And they are constant works in progress. What is the best this month, could be the worst next month. Sadly they are all extremely far from perfect. Security begins and ends with the end user as you will see in my final instructions. ;)

    Yes.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  33. Fhoosa

    Fhoosa Private E-2

    Ok. I uninstalled what I could and read everything you sent me.

    I want to thank you for all the time and effort you put into this project of mine. You are very knowledgeable and that made it all the more comfortable for me to put my computer in your hands. Thanks...!!!

    Fhoosa
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and thanks! :) Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds