"No" Net access - ZeroAccess found / deleted

Discussion in 'Malware Help (A Specialist Will Reply)' started by BaldEagle, Nov 6, 2015.

  1. BaldEagle

    BaldEagle Private E-2

    Acer Aspire one V1.03
    Windows XP Home Edition Service Pack 3 (build 2600)
    2 GB memory - because that's the max for this system architecture.

    Booting in Normal Mode doesn't allow access to the internet with anything but surprisingly SeaMonkey browser is still able to connect just fine.

    So I tried Firefox, and that doesn't even OPEN. It starts a process that's visible in task manager, but doesn't use any cpu cycles. VERY strange.

    Other odd behaviour is my cursor frequently "jumping" to different parts of a sentence that I'm typing, some programs being abnormally slow, hanging, not closing either with [x] or ending the process in Task Manager, mouse clicks don't always register the first time or two, opening or changing directories is SLOW.

    I've also gotten a popup message that something is trying to trick SeaMonkey into accepting insecure updates.

    When I boot into Safe Mode, I can access the internet just fine and it seems that the browsers I've tried all work, and I can update the XYZ-ware scanners as well.

    I had run a scan and it popped up a lot of hits for ZeroAccess in $NTUninstall directories, and I deleted and rebooted.

    After that I tried to follow the full Malware Removal guide - had some problems getting some of the programs to work properly to generate log files, save them in the right format, or even switch directories to save them all in one place. Had to copy them manually and rename to .txt format.
     

    Attached Files:

  2. BaldEagle

    BaldEagle Private E-2

    Rogue Killer scans:

    Sorry this is all a hot mess - IRL has been a thermonuclear mess.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please see here for instructions on how to get a correct log for Malware Bytes. Then attach it.
    Did Hitman Pro run?
     
  4. BaldEagle

    BaldEagle Private E-2

    I did read the instruction page for MWB AW - but there was no "export to txt" blue button to click. I can reboot into Safe Mode if you want, to see if that helps any.

    Hit Man Pro started, but could not connect to the internet during its 5 minute try, then aborted - no special windows or modes started, no special options were available.
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Start the process again.... just re run Malware Bytes (in normal mode) and try again following the instructions I linked to, to get me a log. Attach the log whether Malware Bytes found anything or not.
     
  6. BaldEagle

    BaldEagle Private E-2

    It detected a bunch of PUPs - prefs.js files.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am not seeing any malware...

    You have a cracked microsoft office installed, please see our sticky regarding this http://forums.majorgeeks.com/showthread.php?t=178565

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Please download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version for your PC. Only the correct version will work.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you let Malware Bytes fix what it found? :confused Please do so if you haven't done so already.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which scanner detected zero access?
     
  10. BaldEagle

    BaldEagle Private E-2

    Glad you don't see any malware - although from reading about this Zeroaccess, it seems like it's "removal" was all too easy. Hopefully it was THAT easy.

    msconfig run and set to normal (haven't rebooted yet)
    Farbar run and files attached.

    Looks like I ought to sift and purge whatever accumulated junk is on here as well - I personally use Open Office, so torching that MS crapware really won't affect my life :)

    I'm sure this might be material for a post in a different forum section, but:

    It seems that GeekBuddy thing got installed with Comodo at some point - I'd like to remove them both and try using something installed clean, and after removing installed applications, I'm guessing I should clean the registry to remove any orphaned entries.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Which scanner detected zero access?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete these: (it's just junk)
    • C:\WINDOWS\Tasks\ReimageUpdater.job
    • C:\Documents and Settings\All Users\Application Data\Reimage Protector
    • C:\WINDOWS\Reimage.ini


    You can use Revo Uninstaller to remove them.
     
  13. BaldEagle

    BaldEagle Private E-2

    I believe it was Rogue Killer. See RKreport_SCN_10272015_171834.txt, it has some entries such as:

    {snip}
    "vendors": [
    "ZeroAccess"
    ],
    "status_choice": 2,
    "processed": [
    {
    "type": 2,
    "name": "$NtUninstallKB2079403$",
    "path_expanded": "C:\\WINDOWS\\$NtUninstallKB2079403$",
    "path_compressed": "%SystemRoot%\\$NtUninstallKB2079403$",
    {snip}
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just to be sure can you do a fresh scan with RogueKiller (again, see the instructions in the Read and Run Me First for obtaining the correct log. ;) Attach it here )
     
  15. BaldEagle

    BaldEagle Private E-2

    Rogue Killer seemed to run ok, and the scan log is attached.

    Hope it's the correct one. ;)
     
  16. BaldEagle

    BaldEagle Private E-2

    or it will be once it's actually attached. [facepalm]
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK, I'm seeing no signs of zero access now. And nothing else of concern. Did you let Malware Bytes fix what it found??

    Run these:

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Does this file exist?

    C:\Windows\System32\mswsock.dll
     
  19. BaldEagle

    BaldEagle Private E-2

    ADW wouldn't run - guess it needs network access, so I rebooted into safe mode and it ran successfully.
    Tried to get Revo uninstaller from your link - it wouldn't work, and I don't know where it went on this laptop, but I used to have it - nice tool.
    JRT ran and then stopped/shutdown - and didn't create any log that I could find. :confused

    mswsock.dll does exist - version 5.1.2600.5625 created on 3/11/09
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I believe these are false detections by RogueKiller. It is false detecting all the old hotfix uninstallers for Windows updates. It seems to be doing these on all PCs still running the very outdated and not secure Windows XP.
     
  21. BaldEagle

    BaldEagle Private E-2

    Thanks chaslang. That would be excellent if it never got on my machine in the first place.
    Any ideas what line of analysis I ought to be pursuing to determine why SeaMonkey works and nothing else can access the network?

    I tried lspfix a while back, and that killed everything, and I had to go back to a restore point.
    There's a winsockxpfix as well - but I'm hesitant to try it.

    If it works in Safe Mode, is it a driver issue of some sort?
     
  22. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Have Adwcleaner remove what it finds.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your internet is working.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did see the below issue in your logs from MGtools
    Code:
       Windows Firewall Service     is NOT running  
            C:\WINDOWS\system32\ipnathlp.dll exists  
       Network Connections Service  is running  
       WMI Service                  is running  
       Remote Procedure Call {RPC}  is running  
    
    Maybe the Windows Repair program that Kestel13! suggested using will fix the firewall. You will need to get a new log from MGtools to know.


    Also FRST did show an issue with Winsock
    It also showed the below issues
     
    Last edited: Nov 7, 2015
  24. BaldEagle

    BaldEagle Private E-2

    I ran that tool in safe mode without networking as per the instructions it gives.
    It didn't have a "Repair winsock & DNS cache" option.
    rebooted - still no connection when I tried Opera.

    It DOES have a "Fix Network" option - same/equivalent thing?
    The tool suggests it be run twice anyway - check that box this time around?

    I can see how a bad winsock path variable could contribute to a problem - it's been a long time since I've amended the path. Advise if I should fix that, and probably HOW I should fix that.

    I suppose the issue with Hosts should be addressed.

    I'm not sure what the IP address lease issue is about - it's still curious that ONE browser works, and everything else doesn't Why would one application be able to access the string of things needed to get from the laptop, out the wireless internal modem, through the router, and out the gateway - but everything else sits dead in the water?

    Thanks so much for your patience and continued assistance. :)
     
  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes go ahead and run it again this time allowing it to 'fix network' (it's instructions say: Also resets Winsock entries & resets TCP/IP stack. )

    With the Host File issue you should follow the instructions here to reset it.
     
  26. BaldEagle

    BaldEagle Private E-2

    OK,
    I deleted Comodo firewall with Revo - figured I might as well do that before anything else tried to fix the system, lest uninstalling broke it again...

    I then ran MicrosoftFixit50267.msi, then ran the windows repair tool again with the fix network checked.
    Rebooted, that seems to have rectified [most of] the problem, as Opera is able to load the Google home page.

    Thank you both, Kestrel13! and chaslang for the invaluable help.

    What should I do now to follow through?
     
  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome.

    For starters, let me know about Internet Explorer and Mozilla Firefox. Are they working now?


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Re run FRST....
    • Double-click FRST to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  28. BaldEagle

    BaldEagle Private E-2

    Also, the MS Update window pops up asking is I want to install updates.
    I was under the impression that XP is "no longer supported", so I likely had auto updates turned off. Should I install these updates? (Belarc Advisor had a long list of missing security updates in its output)
     
  29. BaldEagle

    BaldEagle Private E-2

    MG tools was run, and so was FRST. Logs attached.
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please let me know about other browsers, eg: Internet Explorer and Mozilla Firefox.
    After you tell me about them, I will post another small fix we can make with FRST.
     
  31. BaldEagle

    BaldEagle Private E-2

    arg. I did run both of those and they both seem to working just fine.
     
  32. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Really? ALL browsers now work just fine in NORMAL mode? :confused
     
  33. BaldEagle

    BaldEagle Private E-2

    Yep.
    Avant
    SeaMonkey
    Firefox
    Opera (both versions)
    Internet Exploder
    Slim Browser
    Qupzilla
    Safari
    HitmanPro
    Malwarebytes
    Spybot
    Irfanview
    FormatFactory
    Skype

    All access the network and seems to operate as normally as anything ever does.

    ADW crashed when I tried to run it - see attached crop of screenshot.

    Haven't tried to do the windows updates, but I figure if it's finding they exist, then that "works" too.
     

    Attached Files:

  34. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh my goodness! That is fantastic!! :) I would imagine running Windows Repair was what fixed it.

    Save fixlist.txt to your desktop

    You should now have both fixlist.txt and FRST.exe on your desktop.

    • Run FRST and press the Fix button just once and wait.
    • The tool will make a log on the desktop (Fixlog.txt).
    • Please attach this to your next message.
     

    Attached Files:

  35. BaldEagle

    BaldEagle Private E-2

    Yes - it's always pretty good when things all run more or less the way they ought to. :)
    I ran FRST - and it ran for a while and then crashed. See attached.
    Should I just try to run it again?
     

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm.... try and run it again yes.
    Once done, try and run the following and attach logs from them:
    • Malware Bytes
    • RogueKiller
    • Hitman Pro
     
  37. BaldEagle

    BaldEagle Private E-2

    OK,
    Ran FRST, it ran fine, then rebooted.
    Malware bytes ran
    Rogue Killer updated to 10.11.4.0
    As this was done through Opera, AdBlock plugin installed itself. Interesting.
    HitmanPro ran, then deleted some junk after I activated the 30 day trial.


    Logs attached.
     

    Attached Files:

  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning :)

    Did you let Malware Bytes remove what it found? I asked you this before but you never answered me about it. You need to re run it and let it remove what is found.
     
  39. BaldEagle

    BaldEagle Private E-2

    Good morning to you, Kestrel13!

    I did indeed let it remove the several .js files that it found this time.

    I didn't do it the first time around because I was running several scans, and I wasn't told to remove anything, so I didn't as per the general malware removal instructions.
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So apart from Adwcleaner and JRT not running (crashing) how is eveything else running at this point?
     
  41. BaldEagle

    BaldEagle Private E-2

    So far so good. :) I appreciate all the help you and chaslang have given over the past several days, and am glad that it seems to not have been an actual malware-related problem.

    Is there anything I need to do now to make sure everything is ok?
    If ADW and JRT suddenly stopped working, is there something that still needs to be addressed?

    Also, I'm sure I ought to be running something other than XP's Windows firewall since I nuked comodo.
     
  42. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;)
    Do Adwcleaner and JRT still not run? Do they run in SAFE MODE? Is there any other software that crashes or does not run?
    You can post in the software forum about installing protection software.
     
  43. BaldEagle

    BaldEagle Private E-2

    I ran JRT and it ran without an error, then disappeared and I don't see a log anywhere.

    ADW would not run due to an error, so I thought I'd reinstall it.
    The installation file popped up a window saying it was outdated version, and I should download an updated version.

    Clicking OK opened Opera to a URL that redirected to
    https://toolslib.net/downloads/viewdownload/1-adwcleaner/

    Seemed pretty sketchy to me, so I stopped there.
     
  44. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • Did JRT run in normal mode? Let me know about running it in safe mode (unless you did try safe mode previously)
    • Try running it again in both modes and let me know what happens.
    • I am sure the link is safe, but go to this link to download Adwcleaner afresh and try and run it. Let me know what happens.
    • Also address my previous question about other softwares, does anything else crash or not run? :confused
     
  45. BaldEagle

    BaldEagle Private E-2

    Re-downloaded ADW installation file. Interestingly enough - the last one "deleted itself" when I hit [OK]. Disturbing.
    ADW ran in Safe mode, but still gave a popup saying it was outdated. This time I hit cancel, and it proceeded to run.
    Log file attached.

    JRT would not run in safe mode. Couldn't make a restore point.
    Runs in normal mode, but just disappears without explanation.
    Output to the CMD screen shows some file permission issues.

    All other programs seem to run normally. I tried running everything from resource-intensive or network-intensive programs to simple programs from '80's and '90's that require Dosbox. :cool

    PovRay
    Paint.Net
    IrfanView
    Audacity
    ISISDraw
    ChemDraw
    ChemWindow
    OpenOffice
    InkScape
    ChemSketch
    OpenSCAD
    Arduino
    FreeCAD
    Blender
    GIMP
    BitPim

    Various games
     

    Attached Files:

  46. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Adwcleaner log is clean as a whistle. I really wouldn't worry about JRT and Adwcleaner not running in normal mode. I am happy that all your browsers are running and that other programs seem to be running just fine. Ready for final steps? :)
     
  47. BaldEagle

    BaldEagle Private E-2

    Yes, thanks.
    After that I'll head over to the software section and see about firewall software and other stuff.
    Thanks a lot for keeping this little old laptop running.

    The disposition of the old one is a Tale Of Woe such as to make reality Stranger and More Terrifying than Fiction.
     
  48. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. ;)


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    3. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    8. After doing the above, you should work thru the below link:
     
  49. BaldEagle

    BaldEagle Private E-2

    Thanks again.
    Should I do whatever pending XP updates are in the toolbar?
    I'm just asking, because M$ tends to "fix" things like a bull fixes things in a china shop <cough> Skype </cough>.
     
  50. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I wouldn't think it would hurt, but again, you should ask about this in software. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds