Computer Infected please help I got the logs!

Discussion in 'Malware Help (A Specialist Will Reply)' started by OblivionIchigo, Sep 19, 2011.

  1. OblivionIchigo

    OblivionIchigo Private E-2

    Ok well it all started today. I jump on firefox and went to google and went to search up about dreams as I had a bad one and wanted to see what could of cause it. Strange thing was when I searched it and clicked a link it would take me to a complete different page. Every single thing I searched did this.

    I thought malware was the cause so I loaded up my Anti-Malwarebytes and started to scan when it just went away shut down without any notice.

    I tried to bring it back up and I got this message.

    Windows cannot access the specified device, path, or file. You may not have the appropiate permissions to access the item.

    Which I knew was bad. I tried all the programs you had for removing malware and everyone was shut down. I did get logs from Combofix, MGtools, and Rootreply


    While Combofix was scanning it pop up that I was infected with Rootkit.zeroAccess! which I guess is very bad lol.

    Here are the first two logs one from combo fix the second is the root and ill have to do the mgtools in my next post as it got a lot of logs.
     

    Attached Files:

  2. OblivionIchigo

    OblivionIchigo Private E-2

    Here the first part of the MGtools logs.
     

    Attached Files:

  3. OblivionIchigo

    OblivionIchigo Private E-2

    Here second part of MGtools log.
     

    Attached Files:

  4. OblivionIchigo

    OblivionIchigo Private E-2

    wont let me upload the rest at the moment..so if someone can please help me out...
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the entire C:\MGLogs.zip, not individual logs. We also still need the logs from running:

    SAS
    MBAM

    Now do this:
    Download and run Win32kDiag per the below instructions:

    • Download this Win32kDiag and save to C:\Win32kDiag.exe. You must save it here!!!!
    • Click on Start->Run, and copy-paste the following command (the bolded text) into the "Open" box, and click OK. When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please attach this log

    C:\win32kdiag.exe -f -r



    Now download Junction,zip to your Windows folder

    • Please download Junction.zip and save it to your Windows folder (i.e, C:\Windows\Junction.zip This assumes C:\ is your Windows boot drive.)
    • Now unzip it and put junction.exeinto the Windows folder (i.e., C:\Windows\junction.exe)
    • Do not try to run it right now. We will run something that uses it later.

    Now we need to reset the permissions altered by the malware on some files.

    • Download and save inhertit.exe to your Desktop: Inherit.exe
    • It must be in your Desktop or the below fix will not work!

    Now run the C:\MGtools\FixPerm.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    • A command prompt window opens and also a license agreement from SysInternals will appear for Junction.
    • Accept the license agreement and the scan will begin.
    • Wait until it finishes we can take a while to run since it scans your whole harddisk. e patient and don't do anything else while it is scanning.
    • The command prompt window should close when it finishes.
    • While this is running, you will get several/many popups that have a title Finish and say OK. Just click the OK button each time. This is an indication that it has found a file and has attempted to fix permissions. Depending on how many files that need to be fixed, you could get only a few or many of these popups.

    And one more scanning tool I want to use to collect more information is OTL per the below.

    Please download OTL by Old Timer to your desktop.
    See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif

    1. Double-click OTL.exe to run (Vista and Win7 right click and select Run as Administrator)
    2. When OTL opens, change the Output (at the top-right portion of the program) to Minimal Output.
    3. Put check-marks in LOP Check and Purity Check.
    4. Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.



    • When the scan is complete, two logs entitled OTL.txt and Extras.txt will be created on your desktop.
    • Attach both of these logs to your next message.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please Disable Spybot's TeaTimer --> Should have been done as per the R&R instructions!

    * Run Spybot and click Mode
    * Select Advanced Mode.
    * Then click Tools and select Resident.
    * Now in the right window pane, uncheck TeaTimer.
    * Also while this is open, in the left column now select IE Tweaks
    * and then in the right pane make sure all the Miscellaneous locks are unchecked.
    * Now quit Spybot!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds