zaccess infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by kciuci, Jul 16, 2012.

  1. kciuci

    kciuci Private E-2

    I have been fighting this &^%&%^* zaccess infection for almost a week now. The initial manifestation was after watching a youtube video: CA AV reported the win32.zaccess.ee Trojan every 5 - 10 seconds. I've worked my way through your readme and step by step, the only miss being that with the excruciating hang up times for opening files, I had troubles getting some of the "sub" instructions and missed getting the initial Hitman Pro log. I ran hp a second time just to give you something; the first time, it did need to delete and replace the system.exe file and the desktop.ini. the mb scan took about 60 hours to complete.

    The AV messages have stopped, but the hang times continue and I suspect lingering infection and file damage.

    I will be offline most of the day (working) but will be checking in mornings and evenings.

    Thanks for all you hard work, sometimes you must feel like Mother Theresa in a leper colony.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.

    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  3. kciuci

    kciuci Private E-2

    thank you.

    ran Farbar successfully, here is the log
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have multiple antivirus programs installed. CA Antivirus and Ad-Aware. You need to uninstall both of these immediately. You should never install more than one antivirus protection program. Then reboot your PC. Then continue on.

    You also have something from Webroot installed. Exactly what is installed?

    Download this >> View attachment fixlist.txt


    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows can continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. kciuci

    kciuci Private E-2

    ok. here are the logs.

    Current status is apps and web page loads are still hanging up, but no AV reporting zaccess.

    I had installed and run the Ad-Aware early in this process, but the system hangs have been preventing me from running the uninstall. I've got the uninstall running now, hopefully this will have a positive impact.

    continued, gigantic thank you's for all your help!
     

    Attached Files:

  6. kciuci

    kciuci Private E-2

    sorry, another update. I was able to uninstall Ad-Aware, Webroot, and some toolbars that I believe were a result of zaccess.

    After reboot, applications and web sites are no longer hanging up; however, I got a message (same after retrying) on startup "Failed to connect to the System Event Notification Service". Checked services and SENS service status is "Starting" and can't be changed.

    thanks again, Kathy
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall CA Antivirus too as I specified? If not, you have to!!! Having multiple AV installed can cause all kinds of problems and the best way to remove all the effects of them is to uninstall ALL of them first. DO NOT reinstall any until requested.



    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


     
  8. kciuci

    kciuci Private E-2

    Okay, I ran the windows repair this morning. It got to:

    Reset Registry Permissions 02/03
    HKEY_LOCAL MACHINE & Sub Keys

    then I got an error: Execute processes remotely has stopped working.

    And Windows Repair reported "Working...", but made no progress.

    I let it be and checked it 6 hours later; still in the same state.

    I stopped it; kicked it off again, it got past permissions, then the Execute processes remotely error came up again multiple times.

    Closed out and reran Windows repair, and hit Cancel each time the error appeared until it finished. It wasn't able to Restart, it prompted me to do so.

    I restarted and ran the Getlogs batch file, log file attached.

    I did in fact uninstall CA antivirus yesterday as directed.

    Windows startup is the same (takes awhile) and services are still an issue, no networking.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I know you are just trying to help get your PC fixed, but please do not do anything that I do not ask you to do. For example, if you try to run something as instructed and it does not work, then stop and report back. If I don't ask you to run something twice, don't run it twice.....etc. Those repeated attempts to run the tool have made things much worse. Let's see if we can recover from this.

    Reboot your PC into safe boot mode and see if you can complete the below where I have left off the Reset Registry and File Permissions parts of the fixes.

    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  10. kciuci

    kciuci Private E-2

    That helped

    Windows repair ran, rebooted normally, networking restored. So far, no error messages re services.

    Logs attached!

    Kathy
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may be but at least couple are not running per your logs
    Code:
       Base Filtering Service               is NOT running  
    ===================================================================================== 
    Checking Windows Firewall Service -MpsSvc- State
      Windows Firewall Service is NOT running   

    Now please click Start and type services.msc into the Search box. Up above, you should see a gear icon appear with services.msc next to it. Right click on it and select Run As Administrator. Click Continue if prompted to allow it to run. This will open up the Services form. Scroll down to the Windows Firewall service and double click on it. If the Service status: shows Stopped or Disabled, click the Start button. Does it Start? Make sure that the Startup type is set to Automatic.

    Now if the above service starts continue with the below. If it does not start, stop and tell me exactly what happened.

    Now locate the Base Filtering Engine service and Start it and set the Startup type to Automatic, Did this Start?
     
  12. kciuci

    kciuci Private E-2

    Windows Firewall service did not start:

    "Windows could not start the Windows Firewall service on Local Computer.

    Error 1068: the dependency service or group failed to start."
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay, this time try to start Base Filtering Engine service and tell me exactly what error message you receive.
     
  14. kciuci

    kciuci Private E-2

    "Windows could not start the base filtering engine service oo on Local Computer.

    Error 5: access i denied"
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! It seems we still have registry permissions issues. Too bad we could not get that first run of Windows Repair to run properly. It may have made this much easier.


    Now download SubInACL.msi from Microsoft.
    • Now double click on SubInACL.msi to run the installer. Accept any prompts you get about installing this.
    • Now download the below file and save it to your Desktop:
    • Now right click on resetperm.cmd and select Run As Administrator to run this script. Be patient as this may take awhile to run. Also it is imperative that you Run As Administrator. This is not the same thing as your user account having administrator priviledges.
    Once it finishes, reboot your PC.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!



    Also please download Farbar Service Scanner and run it by using right click and selecting Run As Administrator
    • Put a check mark in each option box on the left side.
    • Click "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please attach this log to your next reply.
     
  16. kciuci

    kciuci Private E-2

    okay. all three run. Logs are attached.

    Kathy
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did the resetperm-x64.cmd run thru to completion?
    Did you have any problems running it?
    How long did it take?

    It did not do what we wanted based on your logs; however, try the below anyway.


    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  18. kciuci

    kciuci Private E-2

    Yes, the reset-perm-x64.cmd ran and closed in less than a second, so it definitely ran into an issue, but because it closed I could catch any messages.

    Windows Repair seemed to run without any issues.

    Ran Getlogs, file attached.

    Thanks!

    Kathy
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should take quite a while to run. Please try one more time but this time, reboot your PC into safe boot mode first. Then run it. Let me know if this runs better. A command prompt type window should open where you will be seeing output showing permissions being changed on registry hives and files.

    Also do the below.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now rerun Farbar's Service Scanner as previously run and attach a new log.
     
    Last edited: Jul 29, 2012
  20. kciuci

    kciuci Private E-2

    ok, sorry for the delay, I was checking my email for your reply but either I missed it or it didn't make it.

    Reran reset_perm in Safe Mode; it ran in the cmd window, but again finished in about a second.

    The registry merge gave me a 'successful' message.

    Ran FSS, log attached.

    thx, Kathy
     

    Attached Files:

    • FSS.txt
      File size:
      3.8 KB
      Views:
      3
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you use Right Click and select Run As Administrator?

    Download the below file and save it to your Desktop

    kciuci.reg

    Then right click on it and select Merge. If prompted, allow it to be added to your registry. Then reboot.

    After reboot, rerun Farbar's Sevice Scanner and attach a new log.

    Also run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
     
  22. kciuci

    kciuci Private E-2

    definitely ran reset_perm as Administrator.

    Tried to Merge kciuci.reg: error, Cannot import kciuci.reg: Error accessing registry.

    Kathy
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try it again after booting into safe boot mode. Even if you get an error continue on, but get the new logs from FSS and MGtools in normal boot mode.
     
  24. kciuci

    kciuci Private E-2

    would not run in Safe Mode either.

    there may be something different about the file - Windows was determined to recognize it as an MP3 (???) when I downloaded it.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I figure out that it is some weird bug in the forum that just started recently. Just right click on the file you downloaded and rename it to be kciuci.reg
    instead of kciuci.mp3

    Then try the procedure from normal boot mode.
     
  26. kciuci

    kciuci Private E-2

    same result:( (downloads correctly from the forum, though)
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download and save a current copy of combofix.exe and save it directly onto your Desktop folder. Then right click it and select Run As Administrator. Do not disturb it by clicking in the window that opens or it may stall. After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.
     
  28. kciuci

    kciuci Private E-2

    combofix log attached.

    Registry error when opening Firefox browser: iilegal operation attempted on registry key that has been marked for deletion.

    No error when Firefox is opened using Run as Administrator.

    Kathy
     

    Attached Files:

  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This error is normally cleared by simply rebooting your PC again.

    You managed to get yourself reinfected again with ZeroAccess.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  30. kciuci

    kciuci Private E-2

    Not surprised about a reinfection - no av/anti-malware has been turned back on yet. Hopefully once things are fixed I can find a program that will work better than my old AV at stopping this infection.

    Here are the logs; things seem to be working much better; networking is back. Not seeing any permissions issues yet. Fingers crossed.

    Kathy
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks much better and the BITS ( Background Intelligent Transfer Service ) is fixed too. I do notice that the Windows Defender service is not running. Are you having problems with Windows Defender? Any other problems? Check to see if Windows Update works.


    Also reinstall your protection software now.
     
  32. kciuci

    kciuci Private E-2

    Windows update partially successful (5 of 9). Reran as Administrator, same result (attached image shows errors).

    Manual Start of Windows Defender service was unsuccessful (access denied).

    Some other issues still cropping up, especially browser hang ups.
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please rerun Farbar Service Scanner and attach a new log.


    Click Start, Run, and enter sfc /scannow and click OK. There is a space after the sfc. This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.


    Now please download OTL by OldTimer.
     
  34. kciuci

    kciuci Private E-2

    ok, here are the logs.
     

    Attached Files:

    • OTL.Txt
      File size:
      255.2 KB
      Views:
      1
    • FSS.txt
      File size:
      2.6 KB
      Views:
      1
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    IE:[B]64bit:[/B] - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = [URL]http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL]
    IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = [URL]http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL]
    IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = [URL]http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF[/URL]
    IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = [URL]http://blekko.com/ws/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb_031&u=AD3ADA896EEE2CE8ADA65E4FDB562C0C&q={searchTerms[/URL]}
    IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = [URL]http://mystart.incredibar.com/mb139/?search={searchTerms}&loc=IB_DS&a=1&i=26[/URL]
    FF - prefs.js..browser.search.order.1: "Blekko"
    [2012/07/17 18:53:30 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\Mom's Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\weakgga5.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
    [2012/06/28 09:08:16 | 000,002,185 | ---- | M] () -- C:\Users\Mom's Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\weakgga5.default\searchplugins\MyStart Search.xml
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
    [2012/08/07 17:07:57 | 000,011,092 | ---- | M] () -- C:\Users\Mom's Laptop\Desktop\k ciuci.reg
    [2012/07/26 06:47:21 | 000,000,087 | ---- | M] () -- C:\Users\Mom's Laptop\Desktop\resetperm-x64.cmd.URL
    :Files
    C:\Users\Mom's Laptop\Desktop\k ciuci.reg
    C:\Users\Mom's Laptop\Desktop\resetperm-x64.cmd.URL
    dir C:\Users\Mom's Laptop\AppData\Local\{2BE80C37-7A3D-4077-8971-A2D7690B3EB1} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{29AD918C-F336-43E7-AE68-3516F0EB6E51} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{FF8BA615-1566-4D51-88FE-BC41E1A44497} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{35212DA6-4CEE-4274-AAAA-F1981D4B0BC1} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{41448B4A-8662-4617-A50F-B7C846D583D2} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{58DB986A-1D43-4D9E-AE21-FF746045A735} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{04034552-4DAF-4B4C-94DC-8C310906BE24} /c
    dir C:\Users\Mom's Laptop\AppData\Local\{54B9F462-9F21-4AC4-888C-A4B81FC449EA} /c
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend]
    "DisplayName"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-103"
    "ErrorControl"=dword:00000001
    "Group"="COM Infrastructure"
    "ImagePath"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
      32,5c,73,76,63,68,6f,73,74,2e,65,78,65,20,2d,6b,20,73,65,63,73,76,63,73,00
    "Start"=dword:00000002
    "Type"=dword:00000020
    "Description"="@%ProgramFiles%\\Windows Defender\\MsMpRes.dll,-3068"
    "DependOnService"=hex(7):52,70,63,53,73,00,00
    "ObjectName"="LocalSystem"
    "ServiceSidType"=dword:00000001
    "RequiredPrivileges"=hex(7):53,65,49,6d,70,65,72,73,6f,6e,61,74,65,50,72,69,76,\
      69,6c,65,67,65,00,53,65,42,61,63,6b,75,70,50,72,69,76,69,6c,65,67,65,00,53,\
      65,52,65,73,74,6f,72,65,50,72,69,76,69,6c,65,67,65,00,53,65,44,65,62,75,67,\
      50,72,69,76,69,6c,65,67,65,00,53,65,43,68,61,6e,67,65,4e,6f,74,69,66,79,50,\
      72,69,76,69,6c,65,67,65,00,53,65,53,65,63,75,72,69,74,79,50,72,69,76,69,6c,\
      65,67,65,00,00
    "FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
      00,01,00,00,00,60,ea,00,00,01,00,00,00,60,ea,00,00,00,00,00,00,00,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\Parameters]
    "ServiceDllUnloadOnStop"=dword:00000001
    "ServiceDll"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,6e,64,\
      6f,77,73,20,44,65,66,65,6e,64,65,72,5c,6d,70,73,76,63,2e,64,6c,6c,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\Security]
    "Security"=hex:01,00,14,80,04,01,00,00,10,01,00,00,14,00,00,00,30,00,00,00,02,\
      00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\
      00,00,02,00,d4,00,07,00,00,00,00,00,28,00,ff,01,0f,00,01,06,00,00,00,00,00,\
      05,50,00,00,00,b5,89,fb,38,19,84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,\
      00,0b,28,00,00,00,00,10,01,06,00,00,00,00,00,05,50,00,00,00,b5,89,fb,38,19,\
      84,c2,cb,5c,6c,23,6d,57,00,77,6e,c0,02,64,87,00,00,14,00,fd,01,02,00,01,01,\
      00,00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,\
      05,20,00,00,00,20,02,00,00,00,00,14,00,9d,01,02,00,01,01,00,00,00,00,00,05,\
      04,00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,00,\
      00,28,00,15,00,00,00,01,06,00,00,00,00,00,05,50,00,00,00,49,59,9d,77,91,56,\
      e5,55,dc,f4,e2,0e,a7,8b,eb,ca,7b,42,13,56,01,01,00,00,00,00,00,05,12,00,00,\
      00,01,01,00,00,00,00,00,05,12,00,00,00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend\Enum]
    "0"="Root\\LEGACY_WINDEFEND\\0000"
    "Count"=dword:00000001
    "NextInstance"=dword:00000001
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware"=dword:00000000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Scan]
    "CheckForSignaturesBeforeRunningScan"=dword:00000000
    "AutomaticallyCleanAfterScan"=dword:00000000
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Spynet]
    "SpyNetReporting"=dword:00000000
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  36. kciuci

    kciuci Private E-2

    new logs attached!
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No yet! ;)
     
  38. kciuci

    kciuci Private E-2

    errr, where'd they go?? Here they are again!
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have done all we can do to repair Windows Defender. It still is not running. You could try just installing Microsoft Security Essentials ( MSE ) which has built-in antivirus and antispyware and the antispyware is just a form of Defender and normally Microsoft will disable Defender when MSE is installed anyway.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key http://forums.majorgeeks.com/chaslang/images/Windows_Logo_key.gif and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  40. kciuci

    kciuci Private E-2

    thanks for all you help. A week ago the I got a HD failure, which has probably had something to do with some of the odd recurring issues. Still under warranty, so I was able to get a new HD and have spent the past few days restoring my programs and data.

    You guys are best, and I mean that! Again, thanks for all your help!

    Kathy
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds