Zero Access Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Rheyy, Jul 4, 2012.

  1. Rheyy

    Rheyy Private E-2

    When I conduct a a full scan (McAfee) it indicates the computer is clean. However, McAfee continues to detect Zero Access and Generic Dropper virus and request that I restart my computer. This problem has been occuring for about a week.
     

    Attached Files:

  2. Rheyy

    Rheyy Private E-2

    Can anyone assist me with removing the zero access virus, I think I have uploaded the necessary information requested, just not sure I uploaded it in the correct format?
    Thanks
     
  3. thisisu

    thisisu Malware Consultant

    Hello Rheyy :)

    Please attach the log from RogueKiller.
     
  4. Rheyy

    Rheyy Private E-2

    Here is the RogueKiller log.
    Thanks
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    http://img805.imageshack.us/img805/9659/rktigzy.gif Open RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button again.
    Afterwards, press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[3].txt
    Attach RKreport[3].txt to your next message. (How to attach)

    __

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif - Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    Leave any other detections alone (Ignore them).
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    _

    http://3.bp.blogspot.com/-tH5H1icUyOc/T1XP6r4puoI/AAAAAAAAAQE/jLwmqQECjCg/s1600/hitmanpro.gif Once you are back in Windows, run another scan with HitmanPro and then attach the latest hitmanpro.zip log. (How to attach)
     
  6. thisisu

    thisisu Malware Consultant

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • CA Yahoo! Anti-Spy (remove only)
    • Java(TM) 6 Update 29
    __

    Manually delete the following files:

    • C:\Users\Keith\AppData\Roaming\Microsoft\Windows\Templates\8q1gjv45b1b2ny58w4voq16g4u2
    • C:\Users\Keith\AppData\Roaming\Microsoft\Windows\Templates\yd3PCdCL75y

    __

    http://img205.imageshack.us/img205/4783/regeditb.gif Open Notepad and copy everything in the code box below into it.
    Code:
    Windows Registry Editor Version 5.00
    
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "services"=dword:00000000
    "startup"=dword:00000000
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    • File -> Save As -> Save as type: "All Files" -> File Name: fixme.reg > Save.
    Now merge this into the registry by double-clicking it.
    Let me know if the merge was successful or not.

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know what problems remain after you have completed these steps.
     
  7. Rheyy

    Rheyy Private E-2

    For some reason I was unable to uninstall Java update 29; it stated the resource was unavailable. While running the MGtools a message appeared " The ordinal couldn't be located in the dynamic library wsock32.dll
     

    Attached Files:

  8. thisisu

    thisisu Malware Consultant

    You need to follow the instructions in post #5 first.

    Then you should retry all the instructions in post #6.
     
  9. Rheyy

    Rheyy Private E-2

    I apologize for missing post # 5; I ran the Rogue killer, however when I ran Hitman Pro it stated that my license has expired and it has not been thirty days?
     
  10. thisisu

    thisisu Malware Consultant

    You may want to try downloading a new copy of HitmanPro.
    Sometimes though you do have to click the Activate free license prompt a few times before it finally works. So try it about 5 more times and see if that works.

    If not we can repair the remaining items another way.
     
  11. Rheyy

    Rheyy Private E-2

    I have tried over five times with the Hitman Pro what is the next course of action?
     
  12. thisisu

    thisisu Malware Consultant

    http://img225.imageshack.us/img225/760/blitzblank.gif Please download BlitzBlank to your desktop.
    • Double-click BlitzBlank.exe to open (Vista/7 right-click and select Run as Administrator)
    • Press OK at the warning prompt.
    • Click the Script tab
    • Copy the text inside the code box below and paste it into the text-field.
    Code:
    [COLOR="DarkRed"]DeleteFile:[/COLOR]
    c:\windows\assembly\gac\desktop.ini
    [COLOR="DarkRed"]DeleteFolder:[/COLOR]
    C:\Users\Keith\AppData\Local\{8de78918-66ca-9563-8d0f-8956fcfeb58e}
    c:\windows\installer\{8de78918-66ca-9563-8d0f-8956fcfeb58e}
    • Now click the Execute Now button.
    • The fix will require a reboot in order to complete successfully.
    • Upon reboot, locate C:\blitzblank.log and attach this log to your next message. (How to attach)

    __

    http://img205.imageshack.us/img205/1894/otl.gif Fix items using OTL by OldTimer

    Double-click OTL.exe to run. (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Copy the text in the code box below and paste it into the http://img14.imageshack.us/img14/66/otlcustomfix.png text-field.
    Code:
    [COLOR="DarkRed"]:files[/COLOR]
    C:\Users\Keith\AppData\Local\{8de78918-66ca-9563-8d0f-8956fcfeb58e}
    c:\windows\installer\{8de78918-66ca-9563-8d0f-8956fcfeb58e}
    c:\windows\assembly\gac\desktop.ini
    C:\Users\Keith\AppData\Roaming\Microsoft\Windows\Templates\8q1gjv45b1b2ny58w4voq16g4u2
    C:\Users\Keith\AppData\Roaming\Microsoft\Windows\Templates\yd3PCdCL75y
    C:\windows\system32\services.exe|C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe /replace
    [COLOR="DarkRed"]:reg[/COLOR]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
    "services"=dword:00000000
    "startup"=dword:00000000
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    [COLOR="DarkRed"]:commands[/COLOR]
    [clearallrestorepoints]
    [emptytemp]
    
    Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    If the fix needed a reboot please do it.
    Click the OK button (upon reboot).
    When OTL is finished, Notepad will open. Close Notepad.
    A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    Attach this log to your next message. (How to attach)

    __

    http://img17.imageshack.us/img17/3214/baticonvista7.gif Now run C:\MGtools\GetLogs.bat by right-mouse clicking it and then selecting Run as Administrator
    This updates all of the logs inside MGlogs.zip.
    When it is finished, attach C:\MGlogs.zip to your next message. (How to attach)

    __

    Let me know how the system is running after you have completed these steps.
     
  13. Rheyy

    Rheyy Private E-2

    Here are the requested documents.
     

    Attached Files:

  14. thisisu

    thisisu Malware Consultant

  15. Rheyy

    Rheyy Private E-2

    Zero Access and Artemis virus is still showing up in the quarantined folderof McAfaee; I sent the three attachments in the previous post just wanted to make sure you received them. It stated the post was invisible.
     
  16. Rheyy

    Rheyy Private E-2

    I ran the Combofix and the note pad appeared as stated; I no longer have internet access and when I click on anything this message appears "Illegal operation attempted on a registry key that has been marked for deletion".I used another computer to attach the combofix log and send.
     

    Attached Files:

  17. thisisu

    thisisu Malware Consultant

    Reboot the infected computer. What you are describing is a bug in ComboFix. A reboot fixes it.
     
  18. thisisu

    thisisu Malware Consultant

  19. Rheyy

    Rheyy Private E-2

    Attached is the MGlogs zip file.
     

    Attached Files:

  20. thisisu

    thisisu Malware Consultant

    Hello,

    Your latest logs are clean. Let me know what problems remain, if any.
     
  21. Rheyy

    Rheyy Private E-2

    I ran a full scan and it detected a Generic Dropper.p virus (Trojan) located C:\Qoobox|Quarantine\C\Windows\assembly\GAC\_Desktop_.ini.zip
     
  22. thisisu

    thisisu Malware Consultant

    The Qoobox folder is ComboFix's Quarantine folder. The final instructions below will remove this folder and the rest of our tools.

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  23. Rheyy

    Rheyy Private E-2

    Thank you for all of your assistance!!!!!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds