ZeroAccess, Agent3, Sirefef, Win64/Patched.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by djonma, Nov 22, 2012.

  1. djonma

    djonma Private E-2

    Hiya folks,
    Sorry but I need to ask for expert help.
    This is for my boyfriend's PC, so I don't have access to it to run regular maintenance, and it ended up pretty badly infected.

    It does have internet access still, but the first thing I did was to remove the net access as he has a rootkit and I didn't want it stealing data, so it's currently isolated.

    AVG reports the following:
    vIRUS Identified Win64/Patched.A
    c:\Windows\System32\services.exe

    Virus Identified Win64/Patched.A
    c:\Windows\System32\services.exe

    Trojan horse BackDoor.Generic15.CGSY
    c:\Windows\assembly\GAC_32\Desktop.ini

    Trojan horse Agent3.CJQI
    c:\Windows\Installer\{73804ea0-5d19-4ab8-45f9-b99dc5d186e}\U\80000064.@

    Trojan horse Anget3.CJQI
    c:\Windows\Installer\{73804ea0-5d19-4ab8-45f9-b99dc5d186e}\U\80000064.@

    Found Luhe.Sirefef.A
    c:\Windows\Installer\{73804ea0-5d19-4ab8-45f9-b99dc5d186e}\U\80000000.@

    Found Luhe.Sirefef.A
    c:\Windows\Installer\{73804ea0-5d19-4ab8-45f9-b99dc5d186e}\U\80000032.@

    Though it seems to have managed to get rid of the Sirefef with just AVG and Malwarebytes.

    I ran TDSSKiller in an attempt to remove the zeroaccess and it didn't work, hence you can see stuff in TDSS quarantined zones.

    It's a pretty old system running Windows Vista Home Premium 64, dual core processor - I can get full sysinfo if needed.

    Logs are attached.

    When I ran MGTools I had the following popups:

    MGTools - nslookup.exe - Ordinal Not Found
    The ordinal 1108 could not be located in the dynamic link library WSOCK32.dll


    Microsoft Windows
    nslookup has stopped working
    A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available.


    I was thinking of running FARBAR but the only way I can get into safe mode is to force it with MSConfig - F8 held down does absolutely nothing, though I'm not sure if that's because he has a USB keyboard and mouse and during boot he has to press F1 to make it continue without PS/2 mouse. So trying to force recovery with F is currently impossible. I have thought of grabbing a cheapie PS/2 keyboard to see if that solves that issue.

    We don't know where his vista dvd is, which doesn't help, though if it's needed, we shall search high and low!

    I did a separate Hijack this log, as I wasn't sure whether the hijack this during MGTools was the same full log, but since only 5 logs can be attached I haven't attached it. If anyone wants to see it, I can post it.

    Thanks for any and all help, if we can get this fixed without a full OS install, I'll be delighted!

    Kind regards to all who read,

    Nicola
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    djonma scratchpad 11-22-12

    Welcome to MajorGeeks!

    Please disable Spybot's TeaTimer as instructed in the NOTES: at the beginning of the Malware Removal/Cleaning Procedure.
    How to disable Spybot's TeaTimer

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button, then select the Registry tab and then select any of the below that exist and then click the Delete button.
    • [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    • [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
    Then select the Files tab and if the below exist, click the Delete button again.
    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND
    • [Susp.ASLR][FILE] services.exe : C:\Windows\system32\services.exe --> FOUND
    When it is finished there will be a log on your desktop called RKreport[6].txt, attach it to your next reply. (*Noting multiple previous log numbering.)
    Then immediately reboot your PC.

    After reboot, run new scans with both RogueKiller and Hitman Pro, attach those new logs to your next reply.

    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • RKreport[6]
    • updated HitmanPro log.
    • JRT.txt
     
  3. djonma

    djonma Private E-2

    Thank you for the quick response and advice.

    I did have teatimer disabled, it showed up again this time I ran scans - it wasn't in the sys tray, but was in running processes, I killed it and it still showed up in the Hitman Pro report. I'm not really sure what's going on there.

    Here are the latest logs, thanks again for the help!

    Nicola

    PS: RGlog is 8 not 6, simply because it seems to turn UAC back on, so I had to stop a scan, reboot the UAC Off again and scan again.
     

    Attached Files:

  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    You must uninstall all but one antivirus program. Choose which you want to keep and uninstall the other one:
    C:\Program Files (x86)\Ad-Aware Antivirus
    C:\Program Files (x86)\AVG

    *Other than the tools (and their generated logs) our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\Rob\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Your Mozilla FireFox version (16.0.2) is outdated, as the latest is v.17.0
    Uninstall these outdated Java versions:
    Java(TM) 6 Update 22
    Java(TM) 6 Update 7

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished). *Make sure TeaTimer is dis-abled:


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Now copy the bold text below to notepad. (Do not include any space above the word "REGEDIT4")Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" . Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me whether or not you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Download this to your desktop and double click it to allow it to merge with the registry. Let me know if you receive a success
    message or not.

    BITS.reg

    *Note:The fixes performed by the following tool can sometimes take quite awhile to run, so please be patient. Do NOT run anything else while the repairs are going on.

    Now downloadWindows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Go to Start Repairs tab.
    • Then click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now download and install the latest Sun Java Runtime Environment

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip file... also the last created RogueKiller log -> C:\Users\Rob\Desktop\RKreport[9]_S_11242012_02d2042.txt to your next reply.

    * Make sure you tell me if you had any problems running this procedure and how your machine is working now.

     
  5. djonma

    djonma Private E-2

    Hiya again, thanks for the help!

    I uninstalled Adaware, sorry didn't realise it was installed as bf said he'd tried to install it purely for malware detection but it wouldn't install as AVG is running.

    FixMe and Bits both added successfully to the registry.
    I updated Firefox - his pc has been offline because of the infection, so it hadn't had a chance to update. Also removed the old Jre's and installed the new one.

    Everything ran ok, though the Windows Repair from Tweaker took a very long time, which I hadn't expected. I've not used that before though, so I wasn't really prepared for how long it would take.

    AVG isn't popping virus found up every few minutes anymore, but when I run RK or MGTools, AVG notices the virus as they're being scanned and pops up again.
    I ran a new RK after the Windows Repair had finished. Sorry for the number convention change - I tidied the desktop up a bit, so it created [1]. The date's in the file name though so that's ok.

    It looks like the viruses are still all there unfortunately.
    I have found my own Vista disk, so if it comes to it I could reinstall, just would like to get away with not doing that!

    Thanks again for all the help!

    Nicola
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, Nicola

    Please refer to my instructions that state "Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished)."
    Tell me the filepaths that AVG is alerting on.

    Please attach the new RKreport.txt and C:\MGlogs.zip to your next reply.

    dr.m
     
  7. djonma

    djonma Private E-2


    I'm so sorry! I'm dealing with a nasty virus of my own (as in I'm ill) and I temporarily disabled AVG til restart, then rebooted and forgot as my head is fuzzy :-( That's my own fault for not being extra vigilant since I knew I was ill and groggy.

    I had my bf do an AVG scan just so you can see everything that's being reported. AVG is only reporting WinPatched.A rather than ZeroAccess for services, but RK still shows ZeroAccess.
    Sirefef seems to have gone, at least AVG isn't reporting it, but it's reporting new stuff in the Java things that I removed yesterday, so unsure of what's going on there.

    Here's the text from AVG:

    "";"Virus identified Win64/Patched.A, C:\Windows\System32\services.exe";"Cannot be cleaned
    Remove manually"


    "";"Trojan horse Java/Exploit.ACV, C:\Users\Rob\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5\2daa945-2a87137c";"Moved to Virus Vault"


    "";"Trojan horse Exploit.Java_c.TN, C:\Users\Rob\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49\523ebdb1-7b930f99";"Moved to Virus Vault"


    "";"Trojan horse Exploit.Java_c.TN, C:\Users\Rob\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45\3a81f6d-4d1546b2";"Moved to Virus Vault"


    "";"Trojan horse Exploit.Java_c.CTB, C:\Users\Rob\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11\6f5ab50b-425e04f2";"Moved to Virus Vault"


    "";"Trojan horse Exploit.Java_c.BOK, C:\Users\Rob\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43\3d3aec6b-250e081d";"Moved to Virus Vault"

    And the reports from MGTools and RK are attached.

    Again, thanks so much for all the great help and putting up with my being dim!

    Nicola
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Nicola
    Sorry to hear that you're fighting off a virus - I'm abit under the weather myself.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished).

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button, then select the Registry tab and then select any of the below that exist and then click the Delete button.

    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
    [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
    [HJ DESK] HKCU\[...]\ClassicStartMenu : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> FOUND
    [HJ DESK] HKCU\[...]\NewStartPanel : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> FOUND​
    Then select the Files tab and if the below exist, click the Delete button again.

    [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
    [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND​
    When it is finished there will be a log on your desktop called RKreport[9].txt, attach it to your next reply.

    *Please do the below so that we can boot to System Recovery Options to run a scan while Windows is offline.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Type the below bolded text in the edit box after "Search:".

      services.exe

    • It will make a log (Search.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  9. djonma

    djonma Private E-2

    Well now I'm even more confused.
    I ran RK, it rebooted after the registry delete, and then I ran it again to do the file delete and it wanted to reboot, so I let it.
    Instead it shut down, and now the pc will not turn on at all. No one touched the pc at all physically whilst it was rebooting, and I'm unsure of how playing with Windows system files would affect the physical boot up -if Windows was corrupted, it would still boot up past the bios and then refuse to boot into Windows.

    Any ideas? Or are we looking at a brick?

    Thanks!

    Nicola
     
  10. djonma

    djonma Private E-2

    OK ignore last post. It suddenly came on again and threw a fit about the overclock having failed (it wasn't overclocked).
    So.. back to it.
     
  11. djonma

    djonma Private E-2

    OK so his pc is now bricked due to hardware fail, so it's definitely end of life for it.
    Thanks for all the help trying to clean up the OS.
    I still do need some help though... I will attempt to get all of his files off his various HDs for his next pc, but I need to do that safely.
    I have VirtualBox and can set up a box for things, but I could do with some help making sure this virus stuff doesn't get into my pc whilst I do this.
    Or I could set up a separate hd with whichever linux variant on it would do, just to pull files off. The virus stuff seemed to all be windows sys files, would the rest of the files be safe to pull off the hdds?

    Thanks!

    Nicola
     
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :(
    I'm sorry to hear about the hardware failure, Nicola.
    I have not used VirtualBox but have used Puppy Linux with an external USB hard-drive with good results. Here's a tutorial guide that shows the basic steps:

    http://www.geekstogo.com/forum/topic/274691-use-puppy-linux-live-cd-to-recover-your-data

    Best Wishes, dr.m
     
  13. djonma

    djonma Private E-2

    Sorry this is so late, I was ill over Christmas and ridiculously busy. I just wanted to say thank you very much for the link, I'm going to get started on that now :)

    Nicola
     
  14. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're very welcome, Nicola.

    My "Best Wishes for the New Year",
    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds