zero access virus + daicy.exe

Discussion in 'Malware Help (A Specialist Will Reply)' started by boogieman, Aug 11, 2013.

  1. boogieman

    boogieman Private E-2

    Hi

    OS: Win 7 x64

    1) The logs told me I got the zero access virus, but I dont get the "FBI warning" (I used to get FBI maybe 6-12 months ago but I managed to clear that virus, I think since the warning disappeared).

    What happens NOW to my PC is that every now and then (once a week?) when surfing (IE9) a prompt comes up telling me that i should reboot with a timer. Regardless of answer the PC reboots either when pushing any button or timer runs out, whicever comes first.

    2) Before going here I tried to remove daicy.exe related files but its still seen in the logs (no info on google about this one)

    3) My windows firewall is broken due to some virus. Error code 0x6D9 in advanced sercurity. Several services missing like base filter engine

    4) The 5 logs are attached.


    As allways I am thankful for your support.
    Best regards
    Boogie
     

    Attached Files:

    Last edited: Aug 11, 2013
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [RUN][SUSP PATH] HKCU\[...]\Run : Ocpeegcyi (C:\Users\oh\AppData\Roaming\Bouw\dayci.exe [x]) -> FOUND
      [RUN][SUSP PATH] HKUS\S-1-5-21-3059713504-1430434574-985119653-1000\[...]\Run : Ocpeegcyi (C:\Users\oh\AppData\Roaming\Bouw\dayci.exe [x]) -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-21-3059713504-1430434574-985119653-1000\$41f5ec203a97abd9e9ffa35d25eac14f\n. [x]) -> FOUND
      [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$41f5ec203a97abd9e9ffa35d25eac14f\n. [x]) -> FOUND
      [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$41f5ec203a97abd9e9ffa35d25eac14f\n. [x]) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Do not reboot your computer yet.

    Now rerun Hitman and have it delete everything under:
    Malware remnants

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Use windows explorer to find and delete:
    C:\Users\oh\AppData\Roaming\Bouw

    Now run CCleaner to clean out your temp folders.

    Reboot and rescan with both RogueKiller and Hitman and attach those logs as well.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Attach the new C:\MGLogs.zip.
     
  3. boogieman

    boogieman Private E-2

    Hi Master Tim

    1. I did all that You asked me to do.

    2. The Reg edits were added fine

    3. All remanents targeted seems gone from what I can see of the scans.

    4. I could not find the folder "C:\Users\oh\AppData\Roaming\Bouw", but if I remember it right I have removed it together with daicy.exe long ago.
    What I do have though is a folder called cyqe in the same place with similar file names daila.bav and .temp - see attached png thumbnail.

    5. When running MGlogs.bat I forgot to turn off avira that alerted that it had protected my hosts file. I turned avira off directly at the warning and no other warnings were seen.

    6. After restarting the PC and entering IE I got a prompt about disabling add-ons to speed up the browser that looked "real". I chose "ask me later". I have not seen that one before so I am guessing it has been supressed by the virus?
     

    Attached Files:

    Last edited: Aug 11, 2013
  4. boogieman

    boogieman Private E-2

    this is not a bump, I just wanted to add to previous post (edit button was gone):

    My firewall still does not work and I have a bunch of errors regarding this in the event viewer as well.
    See attached file for the selected event viewer errors (I only copied the errors)


    Best regards
    Boogie
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I suggest you pursue the firewall issue in the software forum or try installing a third party firewall.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ &
      RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall,
      don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking
      on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if
      running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any
      others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and
      deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore
      points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which
        could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.

    After doing the above, you should work thru the below link:




    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  6. boogieman

    boogieman Private E-2

    Hi again

    I managed to the get the fireweall back online BUT Unfortunatelly it seems like the virus is not gone.
    The popup windows keeps appearing and shutting my PC down.

    I might have found a way to "TRIG IT" though.
    I noticed that when I ran the ServicesRepair.exe from ESET the pop up imediatelly appeared and shut down my PC when timer had run out so I guess there is still an infection :-(

    The virus had shut down several services but I have managed to restart most of them but still not:
    - Netwok discovery (file sharing)
    - Default policy for firewall is broken and can not be repaired.
    and since I have at least ONE virus left I need to focus on that first.

    Any ideas? Combofix?
     
    Last edited: Aug 18, 2013
  7. boogieman

    boogieman Private E-2

    I made a scan with ESET online scanner and found 3 threats.
    See attached file
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, we can try Combo:

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  9. boogieman

    boogieman Private E-2

    Hi

    1. Combofix completed with Avira real time protection off (though I forgot to "show hidden files,folders and drives & protected OS files" in explorer) - log attached
    2. After combo had restarted and posted the log my PC was bananas.
    Internet explorer and firewfox did not work (i.e. I could not post here) and I also could not copy paste shortcuts nor text.
    3. I restarted the PC which took AGES but now IE seems to work again.

    Anyway here is the log
    Boogie
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK, so how are things running now?
     
  11. boogieman

    boogieman Private E-2

    At the moment it runs fine, but it normally did before too, I mean
    the infection showed very sporadically, sometimes once a week and now the last time it showed (posts below) it must have been two weeks. Sometimes several times a day.

    But at the moemnt it seems fine.
    Keep the thread open for now and Ill post if I get the shutdowntimer again.

    Thanks a lot for the help
    Boogie
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just be aware of the sites you are visiting and let me know.
     
  13. boogieman

    boogieman Private E-2

    Hi

    I got the popup about PC being rebooted again. It is for sure not windows popup.
    I was visiting my financial brokers site and I hope that one is not infected.

    Its a black text on white background floating over all windows but if i select a window it gets hidden behind them so there is no "stay on top" feaute.
    A 30sec timer runs.
    Does not matter if I leave it alone or press the x to cancel, the system reboots.

    Any ideas what kind of virus this is?

    Thank You
    Boogie
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's been MONTHS since you were working in this thread, so my suggestion now to you is to make a fresh thread and attach all of the requested logs for one of us to review. Thanks.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds