Combofix Removed Rootkit.AccessZero! and now network laptop Can't find Printer

Discussion in 'Malware Help (A Specialist Will Reply)' started by Eaglegame, Feb 8, 2012.

  1. Eaglegame

    Eaglegame Private E-2

    I have been working on this issue for 4 days now and maybe someone has the answer as I'm about to shoot myself. My main PC running Windows XP Pro (SP 3) was infected with Rootkill.AccessZero! I was able to run combofix and and malwarebytes and it seemed to get rid of the problem. The computer seems to be working fine and I have access to the HP Laserjet 1320 that is hardwired to the PC. I have a 2Wire router/modem running and I have two macbook pro's in the house, both running Lion 10.7.2. I am not running a print server so I need to have my pc on to be able to print. Before the virus, both printers were able to use the HP printer without any problem. Last week I turned on my macbook and tried to print and it kept on pausing and erroring out. Not knowing I had a virus on the pc I thought the smart thing to to was to delete the printer and just add it again. Well, after doing that the macbook couldn't see any printer to add. I checked my wifes computer and it had the same problem that it couldn't print, but I didn't delete it. As I said, I ran combofix and Malwarebytes and all seemed to be good. I checked my wifes computer and now she can print fine on the laserjet. Keep in mind, both computers can connect to the internet without a problem. Now, when I try to add a printer to my macbook, it can't find any printer whatsoever. I know that printer sharing is on as my wifes computer seems to work fine and I've checked it as well. I even went to apple and they connected my computer wirelessly to their instore network, opened the printer preference and clicked the plus and immediately found a printer and was able to print. So, it seems it's not my macbook. I checked the router and it can see my computer.
    I've turned off all firewalls (Windows and microsoft security essentials just to see if it's blocking it by chance). No go. I went to network connections and looked at local network and all that comes up is an icon called 'WORKGROUP" (the icon has a circle of computers) which allows me to look at properties, but each computer isn't appearing. I even tried uninstalling the printer via system devices (the printer is on port DOT 4 if that makes a difference) and reinstalled it and while it worked with my pc, my wifes computer wouldn't print and kept pausing. I did a system restore on the main pc to the day before and now her computer prints again. I am knocking my head against the wall as I've called ATT and they say their firewall isn't effecting it since the other macbook pro works so it has to be the PC.
    Sorry to be so wordy ... it's my first post and you can imagine how frustrated I am. I'm sure I left something out that's important, but any help that anyway could provide would be greatly appreciated.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I may have to send you off to the software forum to sort this out, however I think it would be wise to check for any possible remaining malware first, which could be the cause, so let's rule that out. You said you already ran some tools such as Combofix, so skip that step if you still have the log from it. Make sure you go through this though and complete any steps you have not already taken.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Eaglegame

    Eaglegame Private E-2

    Thank you for the information. I'll go through the process this weekend and keep you up to date on my progress.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  5. Eaglegame

    Eaglegame Private E-2

    Ok ... thank you so much for your patience. I followed your post line by line and ran all the reports. I will attach them here. As an aside, I set up my wife's macbook pro for printer sharing which can wirelessly use the HP Laserjet 1320 physically attached to the Windows XP computer and I was able to add the printer on my macbook pro (under her name) and use the printer. Of course, once her computer is turned off, I lose the ability to use the printer.

    I hope I'm attaching the log files correctly and thank you again for your help.
     

    Attached Files:

  6. Eaglegame

    Eaglegame Private E-2

    One more log ... I think it was included in the MGlogs.zip file, but I just wanted to be sure that you got the combofix log.

    After running all of these files, when I go to my macbook's system preferences, printer tab and try to add a printer, it still shows no printer whatsoever. Seems that something may have been removed or changed since I removed rootkill.ZeroAccess with combofix. I tried deleting the printer completely and then reinstalling it with the original installation cd. While the PC worked fine, my wife's macbook would not work anymore. I did a system restore to a day earlier and her computer was once again able to print normally. I even tried updating the printer drivers and still unable to see the printer from my macbook.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix by sUBs

    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\Tasks\XoftSpy.job
    C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\0p70vx0i78n161
    C:\Documents and Settings\Compaq_Administrator\Local Settings\Application Data\62074q4e3ln8117s8j
    C:\Documents and Settings\All Users\Application Data\0p70vx0i78n161
    C:\Documents and Settings\All Users\Application Data\BlAE5X.dat
    C:\Documents and Settings\Compaq_Administrator\Templates\0p70vx0i78n161
    C:\Documents and Settings\Compaq_Administrator\Templates\62074q4e3ln8117s8j
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.



    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  8. Eaglegame

    Eaglegame Private E-2

    Thanks so much. I'll work on this as soon as I get off work today!
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  10. Eaglegame

    Eaglegame Private E-2

    Ok ... I've followed all of the steps exactly as you laid them out. It didn't seem, at least from what I noticed that anything was found. I think TDSSKiller found 8 suspicious objects and I as the instructions suggested, I left the default to skip. Ran the MBRCheck and it didn't find any problems. Lastly, I ran the C:\MGtools\GetLogs.bat file and it did create a C:\MGlogs.zip file. I wasn't sure what you meant by "attach", but I assumed you meant to attach it to my response to you.
    In the end, everything ran pretty smoothly. During the Combofix run (by dragging the CFScript.txt file over it, at one point it rebooted the computer. Not sure if it was meant to do that, but the system did come back on normally. The only thing it did was relocate some of the desktop icons from where they were before the reboot. In the end, I rebooted the machine (PC) and then turned on my Macbook Pro, opened system preferences, printers and fax and tried to add a printer. It still did not find anything at all.

    Just as a test I went to my wife's macbook pro which as I said before does show the HP printer hooked up to the PC and set it to share printer with everyone. Went back to my computer and hit the add printer and up popped the HP Laserjet on my wife's system. Not sure if I want to test it, but I'm not sure if I deleted the printer from her computer if it would allow me to find it again though. I don't think I want to deal with my wife's wrath considering it works fine on her computer.

    Still think that it may be some kind of issue specifically related to my network settings. Seems like that rootkill.ZeroAccess! may have somehow effected my network or it's ability to see or allow other computers to access it. When I go to "my network places" and then click "Entire Network" and then click "Microsoft Windows Network" I just see an icon called "Workgroup". If I double click it, a window opens, but there's nothing to be seen. Not sure if that's normal, but I don't seem to be able to see any computers on my network.

    In any case, I want to once again thank you for all your support and help with this. Quite a process and still have no idea what it can be since my wifes computer seems to work fine and mine doesn't. Hope I didn't mess up any steps or if I needed to attach the C:\MGlogs.zip file to something or run it in some way.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I cannot help you with anything to do with your printer. You can post in the software forum regarding that if you'd like.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  12. Eaglegame

    Eaglegame Private E-2

    Kestrel ... thank you so much for all your help. Sorry we didn't get the problem worked out, but at least we know that there isn't a virus on that PC anymore. Where should I post this issue on the site so that I can get to the bottom of this problem and figure out what could possibly be the problem? Thanks again!
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)

    Yes, I agree. That's my job, to get rid of malware, there is a whole other section here to sort out Software issues.

    Software Forum

    Feel free to post there regarding your printer. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds