ZeroAccess and perhaps other problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by 151henry151, Nov 8, 2013.

  1. 151henry151

    151henry151 Private E-2

    Hello there folks, thanks in advance for any assistance.

    The symptoms:
    Cannot access download.microsoft.com
    cannot access malwarebytes.org
    cannot access media.kaspersky.com

    command prompt/terminal popping up out of nowhere with title such as "01230948098234.exe" and running for a moment before disappearing (the title is not an actual example, I couldn't catch a screenshot quickly enough to see the exact name but they are always different sequences of numbers about that long).

    random files appearing in C:/ drive such as bgrlyrcyxl.xdl and amcxtnvyy and ifxhvefus.fgo and tuqyklrz.ylj

    I couldn't download TDSSKiller or Malwarebytes, but I downloaded and ran HitmanPro and RogueKiller. I've attached the log file for roguekiller, but the hitmanpro log was too large, so I've uploaded it here: https://drive.google.com/file/d/0B-rI7xATjeTrOXdFYzVoV0I4UVU/edit?usp=sharing They both found all kinds of crap. I'm not going to act on any of it until I get some feedback from you folks, because I am afraid to go deleting registry keys and such without knowing for sure whether they are actually malware.

    I don't want to screw this computer up. Also, this is on a LAN and the other three computers on the LAN have had similar symptoms, I am assuming they are all infected, and I wanted to know the correct procedures for cleansing the whole LAN.

    This is the computer system at the motorcycle shop where I work, and we're a fairly new business, so I'm trying to use my limited computer ability to take care of this so that we don't have to spend big money having somebody come out and take care of it for us.

    Any help greatly appreciated. I know what it's like to be always helping people with their computer problems for free, I do it myself all the time, but this infection is beyond my capabilities to deal with on my own, especially considering that the computers involved are my work computers and so the stakes are much higher if I screw something up.

    I even have a few dollars worth of bitcoin to send if somebody really makes the difference and makes it possible for me to get this whole network cleaned out.

    Thanks folks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun RogueKiller and have it fix these items:
    Code:
    ¤¤¤ Registry Entries : 19 ¤¤¤
    [RUN][SUSP PATH] HKUS\S-1-5-21-796845957-1123561945-1417001333-500\[...]\Run : pilpiw ("C:\Documents and Settings\Administrator\Application Data\Microsoft\Ytzkcufv\ytzkcufv.exe" [-]) -> FOUND
    [RUN][ZeroAccess] HKUS\S-1-5-21-796845957-1123561945-1417001333-500\[...]\Run : Google Update ("C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Desktop\Install\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\???\???\???ﯹ๛\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\GoogleUpdate.exe" >) -> FOUND
    [RUN][ZeroAccess] HKUS\S-1-5-21-796845957-1123561945-1417001333-500\[...]\Run : Google Update ("C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Desktop\Install\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\???\???\???ﯹ๛\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\GoogleUpdate.exe" >) -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-796845957-1123561945-1417001333-500\[...]\Run : mnqb ("C:\Documents and Settings\Administrator\Application Data\Microsoft\Ytzkcufv\ytzkcufv.exe" [-]) -> FOUND
    [SERVICE][ZeroAccess] HKLM\[...]\CCSet\[...]\Services : ???etadpug ("C:\Program Files\Google\Desktop\Install\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\   \   \???ﯹ๛\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\GoogleUpdate.exe" < [x]) -> FOUND
    [SERVICE][ZeroAccess] HKLM\[...]\CS001\[...]\Services : ???etadpug ("C:\Program Files\Google\Desktop\Install\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\   \   \???ﯹ๛\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\GoogleUpdate.exe" < [x]) -> FOUND
    [SERVICE][ZeroAccess] HKLM\[...]\CS002\[...]\Services : ???etadpug ("C:\Program Files\Google\Desktop\Install\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\   \   \???ﯹ๛\{5a5c7a06-42c2-810c-dcb0-285ae1ac0849}\GoogleUpdate.exe" < [x]) -> FOUND
    [HID RUN][Hidden from API] HKCU\[...]\Run : slphdmb ("C:\Documents and Settings\Shop\Application Data\Microsoft\Xeieop\xeieop.exe") -> FOUND
    [HID RUN][Hidden from API] HKCU\[...]\Run : vommakyy ("C:\Documents and Settings\Shop\Application Data\Microsoft\Xeieop\xeieop.exe") -> FOUND
    [HID RUN][Hidden from API] HKCU\[...]\Run : xgryup ("C:\Documents and Settings\Shop\Application Data\Microsoft\Xeieop\xeieop.exe") -> FOUND
    [HID RUN][Hidden from API] HKCU\[...]\Run : vbszlutf ("C:\Documents and Settings\Shop\Application Data\Microsoft\Xeieop\xeieop.exe") -> FOUND
    Code:
    ¤¤¤ Startup Entries : 1 ¤¤¤
    [Administrator][SUSP PATH] ytzkcufv.lnk : C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ytzkcufv.lnk @C:\DOCUME~1\ADMINI~1\APPLIC~1\MICROS~1\Ytzkcufv\ytzkcufv.exe [-][-] -> FOUND
    Code:
    ¤¤¤ Particular Files / Folders: ¤¤¤
    [ZeroAccess][Folder] Install : C:\Documents and Settings\Shop\Local Settings\Application Data\Google\Desktop\Install [-] --> FOUND
    [ZeroAccess][Folder] Install : C:\Program Files\Google\Desktop\Install [-] --> FOUND

    Now rerun Hitman and have it fix everything it finds.


    Reboot and rescan with RogueKiller and Hitman and then finish following these instructions if you are able:
    READ & RUN ME FIRST. Malware Removal Guide
     
  3. 151henry151

    151henry151 Private E-2

    I did as suggested, however after the second scan (with hitmanpro) when I rebooted the computer, I got a "DISK BOOT FAILURE - INSERT SYSTEM DISK AND PRESS ENTER"

    Any suggestions? I guess I damaged the MBR somehow? Oh boy... here we go...
     
  4. 151henry151

    151henry151 Private E-2

  5. 151henry151

    151henry151 Private E-2

    So from the recovery console, here's what I get from various commands:

    C:\> dir
    Directory of C:\
    There is no floppy disk or cd in the drive

    C:\> chkdsk
    The volume appears to contain one or more unrecoverable problems

    C:\> fixmbr
    C:\>

    C:\> fixboot c:
    Fixboot cannot find the system drive, or the drive specified is not valid


    I can't understand how any of the actions taken with RogueKiller or Hitman Pro could have caused this situation, or even how any trojan or other malware could have done this--it looks like a straight-up hardware failure, like the hard disk has failed in some way. Am I wrong to draw that conclusion?

    Thanks again in advance for any help, I surely appreciate it.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Neither RogueKiller or Hitman is to blame. I suggest at this point that you go to the software forum for further assistance. :(
     
  7. 151henry151

    151henry151 Private E-2

    Just to confirm--Could I state with certainty that neither RogueKiller nor Hitman could cause these symptoms? Even if, say, I clicked the wrong buttons, or didn't uncheck the right registry keys, or whatever--are either of these programs capable of causing these symptoms?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This could be an indication of a failing hard drive or serious corruption with the drive. Neither RogueKiller nor Hitman harmed you. They removed infections, especially RK, the zero access infection is renowned for getting it's nasty hooks in and screwing with systems, even when all malware is gone, damage to the OS can remain.

    You can take a look at this How to perform a Repair Install of Windows XP
     
  9. 151henry151

    151henry151 Private E-2

    Thanks guys. The next morning the computer booted up just fine--I assume that the hard drive worked again after cooling down, or something along those lines. I am backing up all data and we will be replacing the computer entirely. Thanks again for the help with Zeroaccess, I will perhaps be posting again when we move on to the other computers in the network (which appear to be suffering from either the same or very similar malware problems).
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds