Need help removing remnants of zeroaccess

Discussion in 'Malware Help (A Specialist Will Reply)' started by cowbrains, May 12, 2012.

  1. cowbrains

    cowbrains Private E-2

    Seems like I have gotten most of it, the computer is more responsive and google seems to work as it should and every thing that checks it comes up clean(the eset tool to remove zeroaccess crashes.. all others say i dont have it) but combofix. Every time it says it found zeroaccess, and to run it again if it doesnt work the first time.. similar to other posts here. Had mcafee on it, but have removed it, due to a similar post. Never been a fan.

    thanks in advanced.. here are some logs
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the other logs requested in out cleaning procedure from the below scans.

    SUPERAntiSpyware
    Malwarebytes
    RootRepeal.


    Also are you editing the log files??? You seem to have changed the user acount name in MGlogs.zip to USERPROFILE=C:\Documents and Settings\TEMP and this is not a use name on your PC. It does not equal the user id in the ComboFix log. We cannot give you fixes if you make changes to the log files. Also all scans must be run on the same user account. Also you must move ComboFix.exe directly onto your Desktop so that future instructions will work properly. You ran it from a My Documents\Downloads folder


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
     
  3. cowbrains

    cowbrains Private E-2

    No I did NOT edit any logs.

    I probably ran mgtools from the usb stick instead of the root of the windows drive.

    this time I ran comboxfix from the desktop and mgtools from the proper place.
     

    Attached Files:

  4. cowbrains

    cowbrains Private E-2

    and more logs...(i got a ton more if you want from a2squared to webroot spysweeper, though comboxfix is the only app that finds it anymore(and yes I know you can still get data from logs from things that dont necessarily find it, just saying everything else says clean))

    Thanks for the help
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2
    Java(TM) 6 Update 20
    Viewpoint Manager (Remove Only)
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

    After clicking Fix, exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. cowbrains

    cowbrains Private E-2

    Thanks for the prompt and detailed help.
    Combofix still complains(ran it another time after following all instructions)

    hijackthis has an error when run but continues and appears to work fine otherwise, I suppose it is due to no boot section in the system.ini but not sure.

    Code:
    an unexpected error occurred at procedure  modregistry+IniGetSTring(sFile=system.ini, sSection=boot,sValue=SHell)
    error#5 invalid procedure call or arguement.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista or Win7 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      netsvcs
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      lsass.exe
      nsiproxy.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      tdx.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemdrive%\*.*
      %systemdrive%\MGtools\*.*
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.sys /90
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      %windir%\assembly\GAC\*.ini
      %windir%\assembly\GAC_MSIL\*.ini
      %windir%\assembly\gac_32\*.ini
      %windir%\assembly\gac_64\*.ini
      %windir%\assembly\temp\*.ini
      %windir%\assembly\tmp\u /s
      %allusersprofile%\application data\*.exe
      hklm\system\currentcontrolset\services\dhcp
      hklm\system\currentcontrolset\services\afd
      hklm\system\currentcontrolset\services\tdx
      hklm\system\currentcontrolset\services\tcpip
      hklm\system\currentcontrolset\services\nsiproxy
      hklm\software\microsoft\windows\currentversion\run
      hklm\software\microsoft\windows\currentversion\runonce
      
    • Now click the Run Scan button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)
     
  8. cowbrains

    cowbrains Private E-2

    OTL doesnt like this computers desktop. This computer belongs to a friend and has obviously seen a few techs before me. Their profile seems to be called temp. I'm not sure how or why(It seems to me that having your profile called temp could cause problems but that isnt the issue at hand or i dont think so anyways). So i ran the OTL from the root instead.

    it only gave me the OTL.txt, nothing minimized or anywhere in the root dir(same dir as otl.exe and otl.txt.)
     

    Attached Files:

    • OTL.Txt
      File size:
      283 KB
      Views:
      3
  9. cowbrains

    cowbrains Private E-2

    Ok I have been playing with this OTL,as it bugs me it wasnt providing an extra.txt

    Did you forget to ask me to change 'extra registry' from "none" to "all"?

    when I start OTL unlike most options extra registry is set to "none" and not "Use safe list". I have ran otl several times following your instructions to the letter, on a different machine without a "temp" profile problem and the only way I can get an extra.txt is to change that extra registry setting.

    anyways here are the two most recent logs.

    Thanks again for the help
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this is why back in message # 2 I stated the below
    There are no signs of ZeroAccess or other infections. Are you having any malware symptoms?
     
  11. cowbrains

    cowbrains Private E-2

    nope, not any more. I think it is mostly gone.

    The only symptom is combofix saying I am infected. Everything else seems fine. Just I wonder what is triggering combofix.

    I figure it is just a left over file or registry entry and most likely harmless now, but it still concerns me. as in if something is extra hidden there is probably a reason for it.

    either way for the most part the computer feels fixed.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have experienced couple of cases where ComboFix has been saying this but there are no signs showing anywhere in any logs that a ZA infection is present. And also like you, no symptoms of ZA were present either. In all cases, we just ignored it and proceded to final steps like below as there was nothing we could find to fix. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Oh but one thing I did notice is that you may have some system file missing. I saw the below:

    NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found

    You may want to run SFC.

    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
     
  14. cowbrains

    cowbrains Private E-2

    cool, thanks again for the help. Will run sfc and clean up my mess better than those before me. :)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. And about the TEMP folder name instead of the normal user account name. You may want to look into fixing the below environment variables which are why this is happening. Someone changed them.


    HOMEPATH=\Documents and Settings\TEMP
    USERPROFILE=C:\Documents and Settings\TEMP
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds