ZeroAccess.ch, and other trojans - XP prof 32bit

Discussion in 'Malware Help (A Specialist Will Reply)' started by katornus, May 30, 2012.

  1. katornus

    katornus Private E-2

    Hi there, I’m really glad that I found your forum!

    I would like to ask you for help.
    When running a regular virus-scan on my comp last night (using AVG2012 on XP pro 32bit) couple of treats were found.
    Trojan: generic28.bddx
    Trojan: cryptic.ect
    Trojan: generic_r.awx
    Trojan: ZeroAccess.ch

    They were related to such files/processes according to my avg2012:
    explorer.exe(2940)
    Rentia.dll
    Rundll32.exe (3272)
    explorer.exe(2940):\memory_03610000
    explorer.exe(2940) :\memory_014f0000

    It was not such a big surprise since a day before my webrowser (opera) behaved in a strange way (it crushed couple of times without any reason) and windows prompted me couple of times [at the system start?] about blocking some functions of “explorer.exe” – which was really strange.

    Btw I usually run the system on a limited account (not an administrator account).

    So I got worried, searched for answers and finally found your forum.

    Using administrator account, I went through all the steps from your “read me first” and “manual” (quarantine, configsys-normal; disabling CDemul; updating java etc.).

    I also ran scans: firstly with SAS and then with MB (at that point my AVG was still installed). Later on I uninstalled my AVG using avg-remover and run ComboFix. After that I ran RootRepeal and MGtools (all 5 logs attached – although RR log was empty…..).
    Please, help me out to check if the system is already clean or requires more actions.
     

    Attached Files:

  2. katornus

    katornus Private E-2

    and one more log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hello. :)

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run


    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
     
  4. katornus

    katornus Private E-2

    Thanks Kestrel13! for your answer.

    i ran both TDSSkiller and MBRCheck

    here are the logs
     

    Attached Files:

  5. katornus

    katornus Private E-2

    i can see that strange things are still going on with my machine. For instance when logging off from a given profile the background screen doesn't go blue but i can still see a wallpaper from an account from which i just logged off and a pop-up window saying "press ctrl+alt+del+ to log in" etc. normally it was blue.

    as well, when i log in again to a given profile, all desktop items are automatically reshuffled, they are ordered on the left hand side of the desktop, although previously i had arranged them all over the desktop.
     
  6. katornus

    katornus Private E-2

    and one more observation, windows explorer seems to have problem all the time (it was initially detected as being infected). Explorer doesn't "remember" settings of the folder view, i.e. i open a folder and set the view as "list" (right now the custom view is "details"). then i exit this folder and re-enter it and the view is again back to "details" instead of "list", which i set. Any clue on that?
     
  7. katornus

    katornus Private E-2

    i also did a full scan with Malwarebytes Anti-Malware and it found couple of things, see the attached log.
    what could i do next, should i kill those detected files or leave them for now?
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes! Let MalwareBytes kill them and then reboot and see if avg is still complaining. :)
     
  9. katornus

    katornus Private E-2

    thanks for your further support.

    OK, i'll scan again with MB in admin mode and then will kill what it finds. at the moment i don't have avg as i uninstalled it before running ComboFix.

    can you recommend me some online scanner to do so, or should i go on with re-installing avg (any other recommendable AV)?
     
  10. katornus

    katornus Private E-2

    Full scan log with MB attached.

    i didn't reinstall avg yet but downloaded "spybot-search and destroy", which found couple of things, among others some registry changes, which i didn't allow to fix (i was hesitant about messing up with them without advice from someone more experienced). - log attached.

    still my windows explorer malfunctions i.e. when i'm logging to my "user account" it doesn't remember desktop setting from the previous session (it orders automatically all the desktop items on the left hand side of the screen). on the other hand, when i log in to my "admin account" then desktop is OK, and icons are arrange all over. btw, my computer got infected when i was using my "user account" (i'm 95% sure of that).
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Reinstall avg at this point and let me know if it alerts you to anything.
     
  12. katornus

    katornus Private E-2

    Hi Kestrel13! thx again for you help.
    i reinstalled avg and ran a full scan in the admin mode. nothing was found. what should go next?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What problems remain?
     
  14. katornus

    katornus Private E-2

    windows explorer - still doesn't "remember" the last view in folders or on desktop. otherwise, i cannot see anything else at the moment.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  16. katornus

    katornus Private E-2

    Hi Kestrel13!,
    i wasn't at the computer for some time and couldn't answer your post.

    i've followed your instructions - newly installed AVG does not find anything wrong. MB doesn't find anything either. At the moment, i removed most of the soft, which we used to clean up my computer, re-enabled cd-emul and flushed system restore.

    I still have two questions:
    1) should i change my msconfig settings? i changed it before to "normal startup mode". if yes, how should i do that?

    2) what to do with windows explorer, which still doesn't function right?

    your further support is much appreciated.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MSConfig should ALWAYS be set at normal start up, any other mode is primarily used for troubleshooting and diagnostic purposes.
    You can always ask about this in the software forum. :)
     
  18. katornus

    katornus Private E-2

    Kestrel13!
    thanks a lot for your time and helping me out. i really appreciate your time and effort. as you said, i'll check out soft forum now - hope it'll go as smooth as here :)
    have a good one.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are *most* welcome. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds