wits end, zeroaccess/cryptor, tcpip issues...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by SmokeyHawk, Jan 12, 2012.

  1. SmokeyHawk

    SmokeyHawk Private E-2

    Hello MG!

    I've tried tried tried to fix this on my own.
    I've gone through the "read me" (going through the 1-5 steps again now to post logs in the follow up post).

    Cleared my system of zeroaccess(even though combofix says i still have it every time I run it, tdsskiller shows no signs)

    My main issue is rebuilding the tcp/ip stack(therefore I believe there is a file somewhere which doesn't propagate; but effs stuff up) . I used to be able to at least rebuild it(the tcp/ip stack) manually every time I rebooted. Now that I've "combofix /uninstalled" I can't, It's completely broken.

    Initial finding:
    2012 pop up/system tray....
    ran SB, found cryptor and a few other things.....
    ran AA, found cookies.
    downloaded and ran AVG, found a few other things, did what it said, effed up my nvidia drivers.
    Searched internet with other computer(G5 Mac, not connected to broken comp) and found cryptor saviors(combofix etc)
    Ran combofix, found zeroaccess rootkit, keeeeps finding it no matter what.
    Broken net access.

    So,
    I need help to restore this PC.
    If I have to wipe and reinstall, no biggie as it's just a gaming rig. (albeit a pain in the arse; but I want to beat this bugger! I got the kits by viewing a pic linked through a frikin car web site.)

    I'm starting clean:
    No AV
    All cleaning programs removed(although I still have them on CDROMs)
    Tell me what logs to post and I will.

    Thanks in advance!

    Next post will have read me XP steps 1-5 logs posted.

    -SH
     
  2. SmokeyHawk

    SmokeyHawk Private E-2

    Logs attached.

    Thanks in advance!

    -SH

    p.s. I did run RR before CF, is that a problem?
     

    Attached Files:

  3. SmokeyHawk

    SmokeyHawk Private E-2

    MGTools logs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Let's try the below to fix you networking problem.

    1. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • The above file will open in the notepad.
      • Under TCP/IP Primary Install section find the following: Characteristics = 0xA0
      • Edit 0xA0 and replace it with 0x80 (replace A with 8)
      • Under File menu click Save and close the notepad.
    2. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install a popup window opens.
      • Select Protocol from the list and then click Add.
      • A new window opens, click Have Disk....
      • In the browse... box type c:\windows\inf
      • Click OK.
      • Select Internet Protocol (TCP/IP), and then click OK.
      • On the Local Area Connection Properties screen select Internet Protocol (TCP/IP) and click Uninstall, and then click Yes.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    3. Go to Start ==> Run (or Windows key+R)
      • Type the following in the run box and click OK: notepad c:\windows\inf\nettcpip.inf
        (note that there is space after notepad)
      • A file opens in the notepad. Under TCP/IP Primary Install section find the following: Characteristics = 0x80
      • Edit 0x80 and replace it with 0xA0 (replace 8 with A)
      • Under File menu click Save and close the notepad.
    4. Go to Start ==> Control Panel. Double-click Network Connections. Right-click Local Area Connection, and select Properties.
      • On the General tab, click Install
      • A popup window opens. Select Protocol.
      • A new popup window opens. Select Internet Protocol (TCP/IP), and then click OK.
      • Wait until it asks to restart, and then restart as requested. Continue with the below after restarting.
    5. After restart please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    6. Then attach the below logs:
      • C:\MGlogs.zip
     
  5. SmokeyHawk

    SmokeyHawk Private E-2

    Here is the MGTools log, after doing the above changes to nettcp.inf
    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks like that took care of your problems with TCPIP. Are you having any other problems?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also see uf you can find and delete the below files. Make sure they do not come back after a reboot. Let me know if you cannot see them. They are present.


    C:\Documents and Settings\hec\Local Settings\Application Data\oid711gu8xhb03rf7p358s0cbgfia7nt8yyel
    C:\Documents and Settings\All Users\Application Data\oid711gu8xhb03rf7p358s0cbgfia7nt8yyel
    C:\Documents and Settings\hec\Templates\oid711gu8xhb03rf7p358s0cbgfia7nt8yyel
     
  8. SmokeyHawk

    SmokeyHawk Private E-2

    Hello,
    I have deleted the 3 files listed above. They did not come back after(the 1st) or several reboots.
    However, when I reboot the computer, the tcpip problem persists.
    I can manually run the fix you posted and it works; but it apparently doesn't "stick". I've retried the tcpip fix after deleting the 3 files above and it still doesn't "stick".

    The last MGToolslog.zip file i attached was run after the 1st time I did the tcpip fix(while I could access the net using the affected computer). Would it help if I posted a log from before I manually fix it and then a log from after I manually fix it? (By manually fix it I mean I can get the net to work again after a reboot; but I have to run the fix you posted every time I reboot the computer).

    Also, here are some changes I notice from when the net is and isn't working on this PC:

    When the net works(ie after a manual tcpip fix) after reboot and the desktop loads I get the Windows Security Alert popup that AV is not installed(note: this is the legit system popup, NOT 2012 virus popup).

    When the net doesn't work I get the same popup; but about 3-5 minutes later I get a new popup(these popups come from the system tray) that says "Firewall is not running". I've checked and when the net is working the Windows firewall is "on". When the net isn't working Windows firewall is "off".

    When the net isn't working I can't start the Windows firewall and get an error that mentions Firewall/ICS can't be found (or the parent process).

    Thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Reset Registry Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.
    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click onresetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.


    Now if necessary to get your network interface working, rerun my fix from message # 4.


    Then please run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Also let me know if your status has improved, stayed the same, or gotten worse.
     
  10. SmokeyHawk

    SmokeyHawk Private E-2

    Ok,
    I've ran everything up to the point where I need to run "resetperm-x64.cmd".
    I'm leary to run it; as the name suggests I think it's for a Win64bit system, which mine is not(proc is 64bit capable, my XP as far as I know is 32bit?). You also say to run as admin (on right click there is no option, however, my account at the moment is running in admin mode; and from my understanding "rclick, run as admin" is a vista/win7 command, I am on XP32bit).
    If you still want me to run "resetperm-x64.cmd" I will, just wanted to make sure.

    after running tweaking.com fix tool i rebooted and installed the subinacl.msi file, just waiting on a reply to run the afore-mentiond "resetperm-x64.cmd" file.

    Thanks!
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry about that. I copied in the wrong boilerplate for your Windows version. Use the below instead. I'll start with running the command script file since you already installed SubInAcl.

    • Now download the below file and save it to your Desktop:
    • Now double click on resetperm.cmd to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.

    Then continue with the remaining instructions from my previous message
     
  12. SmokeyHawk

    SmokeyHawk Private E-2

    Ok,
    I ran the "resetperm.cmd" script and still no "sticking" of the fix.
    I can still manually rebuild the stack by uninstalling/installing tcp/ip protocol which is nice; but annoying :)

    Here is the getlogs.bat file. (I ran getlogs.bat after manually fixing the net connection. Would it help if I ran getlogs.bat while the net connection is not working?)

    Thanks!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes this may be a good idea. Also I would like you to run the below while it is not working so you will need to download it while you have a connection.


    Now please download Farbar Service Scanner and run it on the computer with the issue.
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds