Zeroaccess/desktop.ini Trojan Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by andrewr47, Oct 10, 2012.

  1. andrewr47

    andrewr47 Private E-2

    Hello Helpers!

    I need some help in getting rid of this desktop.ini Trojan. I did go through your tutorial and finished getting all my logs. I went through each step as instructed. There are couple of things I wanted to point out however:

    1. I ran HitmanPro prior to finding this site and had attempted to delete the trojans (hopefully this did not make anything worse, but it was done prior to seeing any of your instructions).
    2. Upon running MGTools, I had an error popup when nslookup.exe was running and stated that WSOCK32.dll was not found. I hit "OK" and MGTools resumed running and finished running
    3. Upon running TDSSKiller, a malware was found on services.exe, and I hit "Continue" with the default option ("Cure") as per your instructions, but the program did NOT ask me to reboot. Instead it stated that the malware was not processed, and I had to just close the program.

    Please help, thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:


    • [HJPOL] HKLM\[...]\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableTaskMgr (0) -> FOUND
      [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND
      [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND
      [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
      [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    Now click the Files/folders tab and locate these detections:

    • [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini --> FOUND
      [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini --> FOUND
      [Susp.ASLR][FILE] services.exe : C:\Windows\system32\services.exe --> FOUND
    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach[/URL])
    Do not reboot your computer yet.

    Rescan with HitmanPro, when it finds services.exe - Virus, allow it to Replace by clicking the down arrow next to the detection and choosing Replace.
    Choose to Delete these files if they are detected:

    • C:\Windows\assembly\GAC_32\Desktop.ini
      C:\Windows\assembly\GAC_64\Desktop.ini
    Ignore all other detections.
    Afterwards, click the Next button.
    HitmanPro may want to reboot the PC in order for the changes to take affect, please do so.

    Now re-scan with both RogueKiller and HitmanPro and attach those new logs also.
     
  3. andrewr47

    andrewr47 Private E-2

    Thank you Malware Jedi!

    I went ahead and followed your instructions. There were some variations as to what happened, as the program made more logs than expected:

    1. After scanning with RogueKiller, RKreport[2] was made
    2. After deleting stated files in registry, RKreport[3] was made, and asked for reboot, which I declined.
    3. After deleting stated files in files/folders, RKreport[4] was made, and asked for reboot, which I declined.

    I did everything that was instructed for HitmanPro, and I rebooted. The log attached is the one made after rebooting.

    RKreport[5] was made after rebooting.

    Thank you!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looks good. What other malware issues are you having, if any?
     
  5. andrewr47

    andrewr47 Private E-2

    Great! so the Trojans are gone?

    I don't have any other malware issues currently but I have couple questions:

    1. I now have two desktop.ini files on my desktop. Can I delete those?
    2. I also have a RK_Quarantine folder on my destop. Can I delete this?

    If not, please instruct on what to do with those.

    Thanks!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Go to the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:
    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. andrewr47

    andrewr47 Private E-2

    Thanks Jedi Master,

    I still have the two desktop.ini files on my desktop even after running MGClean. What should I do with those?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go to the control panel and click on Folder options. When that opens, click on View and change to "Do not show hidden files and folders".
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds