Need help with a Zero Access infection.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Sky Blue, Jul 3, 2012.

  1. Sky Blue

    Sky Blue Private E-2

    Hi,

    I have managed to get what I think is a Zero Access infection on my computer yesterday. I noticed it when my Windows Firewall, running through Microsoft Security Essentials did not work, and when I attempted to start it, it said the service could not be found. It then came up with a window saying the computer would restart in one minute, and it continued to say this every time I restarted in normal mode.

    I ran Malwarebytes in Safe mode and although it said it had removed the files causing this, the same thing still happened in Normal mode. Running Malawarebytes a few more times showed that one of the files was not actually being deleted. I have uninstalled Microsoft Security Essentials, which seemed to be triggering the virus, so Normal mode is working for now, but I'm not sure for how long, and I don't relish the idea of using my computer knowing it has a virus on it, and not being able to have any Antivrus software running.

    I was wondering if I could get some help with this, as I have reached the limit of my abilities! I have gone through the steps in the READ & RUN ME FIRST guide, and have attached the the files required from that below.

    Thanks in advance for the help!

    Nick.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, Nick :)

    http://img805.imageshack.us/img805/9659/rktigzy.gif Open RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button again.
    Now click the Files tab and find the following detections:
    • [ZeroAccess][FILE] @ : c:\windows\installer\{a7397042-a93b-1034-ca30-70aa3c0746ff}\@ --> FOUND
    • [ZeroAccess][FOLDER] U : c:\windows\installer\{a7397042-a93b-1034-ca30-70aa3c0746ff}\U --> FOUND
    • [ZeroAccess][FOLDER] L : c:\windows\installer\{a7397042-a93b-1034-ca30-70aa3c0746ff}\L --> FOUND
    • [ZeroAccess][FILE] n : c:\users\nick\appdata\local\{a7397042-a93b-1034-ca30-70aa3c0746ff}\n --> FOUND
    • [ZeroAccess][FOLDER] U : c:\users\nick\appdata\local\{a7397042-a93b-1034-ca30-70aa3c0746ff}\U --> FOUND
    • [ZeroAccess][FOLDER] L : c:\users\nick\appdata\local\{a7397042-a93b-1034-ca30-70aa3c0746ff}\L --> FOUND
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)

    __

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif - Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    Leave the other detections alone (Ignore them).
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    _


    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (How to attach)
     
  3. Sky Blue

    Sky Blue Private E-2

    Hi thisisu,

    Thanks for the reply, I've attached below the logs you asked for. They are RKreport(3) and hitmanpro(2) though, since I didn't think to delete the previous ones, sorry!

    Also, for some reason my Documents folder opened during the Rogue Killer scan, is this normal?

    Thanks,

    Nick.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    No that doesn't sound normal. If you scan again with RogueKiller does it open My Documents?

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)
     
  5. Sky Blue

    Sky Blue Private E-2

    I tried scanning again with Rogue Killer and it opened my Documents again. It seemed to happen while it said it was trying to find fake files, but I don't know if that helps at all.

    I have attached the updated MGLogs below.

    Thanks,

    Nick.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    I'll ask the developer.

    http://img196.imageshack.us/img196/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run

    http://img205.imageshack.us/img205/1894/otl.gif Please download OTL by OldTimer.

    • Save it to your desktop.
    • Right mouse click on the OTL icon on your desktop and select Run as Administrator
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
      Code:
      activex
      netsvcs
      %windir%\$ntuninstallkb*. /120
      %windir%\system32\drivers\*.sys /lockedfiles
      
    • Now click the http://img171.imageshack.us/img171/2405/runscanotl.png button.
    • One report will be created:
      • OTL.txt <-- Will be opened
    • Attach OTL.txt to your next message. (How to attach)
     
  7. Sky Blue

    Sky Blue Private E-2

    I've attached the two files you asked for below. There was also an Extras.txt file generated after OTL had finished scanning which I can upload if you need it.

    Thanks,

    Nick.
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    Thanks but I do not need it ;)

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Java(TM) 6 Update 32

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:otl[/COLOR]
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:33440
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:33440
    IE - HKU\S-1-5-21-2611499473-1605654319-980004263-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.ask.com/?l=dis&o=15179
    IE - HKU\S-1-5-21-2611499473-1605654319-980004263-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=PF&o=15176&src=crm&q={searchTerms}&locale=&apn_ptnrs=RW&apn_dtid=YYYYYYYYGB&apn_uid=e082c82a-c37d-4d3a-b273-a9d0c807f59e&apn_sauid=1EBABFDA-E111-45C2-817A-B9AC2EF7BA99&
    FF - prefs.js..browser.search.defaultengine: "Ask.com"
    FF - prefs.js..browser.search.defaultenginename: "Ask.com"
    FF - prefs.js..browser.search.order.1: "Ask.com"
    FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
    O3 - HKU\S-1-5-21-2611499473-1605654319-980004263-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
    O3 - HKU\S-1-5-21-2611499473-1605654319-980004263-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
    O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)
    O33 - MountPoints2\{ca9a83dc-78d2-11dd-ad35-0021707c57fa}\Shell\AutoRun\command - "" = F:\wd_windows_tools\setup.exe
    O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\setup.exe
    [1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
    @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
    @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
    [COLOR="DarkRed"]:files[/COLOR]
    type C:\rkill.log /c
    [COLOR="DarkRed"]:reg[/COLOR]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "startup"=dword:00000000
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    [COLOR="DarkRed"]:commands[/COLOR]
    [clearallrestorepoints]
    [emptytemp]
    [resethosts]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know how your system is running after you have completed the above steps.
     
  9. Sky Blue

    Sky Blue Private E-2

    I have uninstalled the Java Update, and ran OTL and MGtools as you described, and have attached the logs below.

    When you said to click the OK button upon reboot, OTL was not actually running when it restarted, but the log from it was open.

    My system seems to be running fine, though as I said in my first post, it was was originally triggered by Microsoft Security Essentials, which I uninstalled so I could have the computer on for more than a minute to seek help, so the problem could still be there.

    Also I'm not sure if this is relevant, or just relates to the fixes that OTL did, but it did take a rather long time at the "Logging off..." screen before it finally restarted.

    Thanks,

    Nick.
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Your latest logs are clean.
    The restarts were due to MSE failing to remove the infection upon reboot. We successfully removed the infection using RogueKiller and HitmanPro ;)

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  11. Sky Blue

    Sky Blue Private E-2

    That's good to hear! Thank you very much for your help, I really appreciate it, and thank you for being so quick in replying to my original post, and walking me through the process.

    I will post again in this thread if for some reason the same problem happens again.

    Thanks again for all your help!

    Nick.
     
  12. thisisu

    thisisu Malware Consultant

    You're welcome.
    Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds