W32.Zero.Access cant delete - crashes computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by erezb, Aug 24, 2013.

  1. erezb

    erezb Private E-2

    Hello,

    First of all I would like to thank you for taking your time reading this.

    So, my problem is as mentioned :
    I have found using "Webroot" that i have 16 threats which are
    W32.Malware.Gen
    W32.Zero.Access
    W32.Malware.Heur.Dkvt

    Trying to remove it from the Webroot caused in blue screen memory dump crash.

    Then i went to this thread:
    http://forums.majorgeeks.com/showthread.php?t=261433

    Following their advice i tried (with no help of course):
    1) Trend Micro HiJackThis
    2) REGEDIT4

    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{6CAE6703-1615-428A-A613-035F0E5A8B31}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{6CAE6703-1615-428A-A613-035F0E5A8B31}]

    3) Windows Repair.
    4) RougeKiller
    5) Hitman Pro.

    Non of the above helped, would be very happy to get your help!

    Thanks,
    Erez.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. erezb

    erezb Private E-2

    Hello,

    As Tim requested I have attached all the logs from the softwares, and I have followed all the steps, and did not skip ANY step.

    Thank you very much!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Before we look at any malware, please do the following:

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.

    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  5. erezb

    erezb Private E-2

    Thank you for dedicating your time!

    Attached the requested log.
     

    Attached Files:

    • JRT.txt
      File size:
      35.7 KB
      Views:
      2
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and attach the new log. Tell me what issues you may still be having, if any.
     
  7. erezb

    erezb Private E-2


    Hey, As you requested I ran another scan with the hitman, found nothing
    in specific, but the webroot seems to find that virus again. (added its log)

    I split the webroot's log into 3 files because it would not let me upload
    them as one file.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please uninstall the below:
    Ask Toolbar
    DefaultTab
    J2SE Runtime Environment 5.0 Update 21
    Java 7 Update 15
    Java(TM) 6 Update 17
    uTorrentControl2 Toolbar
    YTD Toolbar v7.4

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\Users\Erez\AppData\Local\PunkBuster
    C:\Users\Administrator\AppData\Local\AskToolbar\ 
    C:\Users\Administrator\AppData\Local\AskToolbar\Downloaded Program Files\ 
    C:\Users\Administrator\AppData\Local\AskToolbar\Downloaded Program Files\nero.inf 
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\ 
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\cache.dat 
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\config.xml 
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\nero.cab 
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\Nero.config
    C:\Users\Administrator\AppData\LocalLow\AskToolbar\osearch.xml 
    C:\Users\Administrator\AppData\LocalLow\Conduit\ 
    C:\Users\Administrator\AppData\LocalLow\Conduit\Community Alerts\Dialogs\ 
    C:\Users\Administrator\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog
    
    :Commands
    [purity]
    [ResetHosts]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.

    Now rerun JRT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Attach the logs for:
    OTM
    JRT
    C:|mglogs.zip
     
  9. erezb

    erezb Private E-2

    Hey,

    First of all thanks a lot for all your time!

    I have done what you have asked only one issue:

    I couldn't find the Ask Toolbar, so I did not remove it...

    attached are the requested logs.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The Ask Toolbar is in your add/remove programs list.

    What issues are you having?

    Your logs are clean.
     
  11. erezb

    erezb Private E-2

    Hey,

    Still couldn't find that toolbar in the add/remove programs.

    My issues are that the computer is slower than before.

    Also, the viruses are discoverd only by the Webroot antivirus.. and are still
    being discoverd.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing anything in the webroot logs of concern. Perhaps you can tell me what it is complaining about.
     
  13. erezb

    erezb Private E-2

    yes of course, thank you.

    I have attached the screen shoot of the scan results screen.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Based on your other logs, they are false positives.
     
  15. erezb

    erezb Private E-2

    The problem is when ever I let the webroot continue with its tasks (meaning deleting the "viruses" or quarantining them) I get a blue screen with windows memory dump, should I just ignore the messages?

    Thank you very much for your time dear friend :)
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you uninstall Webroot and go with another AV program. It is trying to remove services.exe which is what is giving you the crashes.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds