ZeroAccess

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by sammy711, Aug 23, 2012.

  1. sammy711

    sammy711 Private E-2

    Please help... it appears I have the ZeroAccess malware per the scans & logs I ran after going through the "READ & RUN ME FIRST" thread.

    Signs are that my browser redirects after searching on Google... what's interesting is when I search for a keyword the first time it redirects when I click on a link, and then when I search for the same keyword again it no longer redirects when I click on a link.

    Also, I cannot get an updated virus definition for MSE, it says connection failed although I have an internet connection to start this thread so something must be blocking MSE from getting updates.

    Thank you in advance for your help!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What exactly do you have installed from Comodo? Is it the full security suite with antivirus, antispyware and firewall? Or is it just the firewall?

    Rerun RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select the Files tab and if the below exist, click the Delete button[/B]

    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).
    Then attach the below logs:
    • the new RogueKiller log
    • C:\MGlogs.zip
     
  3. sammy711

    sammy711 Private E-2

    I have the firewall installed from Comodo.

    For antivirus/malware I use MSE which isn't able to get an update at the moment saying no internet connection... so something (probably the malware) is blocking it from getting an update.

    I also have Comodo's CCE and System Utilities for scanning along with Malwarebytes... after I got the virus/malware I went through MajorGeeks tips for preventing virus/malware and decided to get Comodo's free firewall and disable Windows Firewall.

    I completed what you said to do and attached are the scans... thank you for your help!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try shutting down all of Comodo, especially the firewall and then see if MSE will update. If not then continue with the below.


    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  5. sammy711

    sammy711 Private E-2

    I noticed yesterday that Windows Firewall was turned "ON" for some reason, I am sure I turned it off when I installed Comodo Firewall... anyways, I have turned off Windows Firewall.

    With Comodo Firewall on, I attempted to update MSE with latest virus definitions and it updated without any problems.

    I did receive a "success" message for adding the code to the registry.

    Then I performed a search on Google's search bar on Mozilla and I was redirected when clicking on a link. I did a couple additional searches and no redirection occurred. Then I tried "fat burner" and got redirected.

    Attached is the latest log.
     

    Attached Files:

  6. sammy711

    sammy711 Private E-2

    I just ran a scan with MSE and it didn't find anything new... but I checked the "History" tab and found a list of quarantined items.

    Attached is a jpg of the list. I did not remove any of the items... I figured I'd let you know and then wait for instructions.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Old info! Just remove all of them.


    Are you still having redirection issues? If yes, answer the below:
    1. With which browser? Is it occurring on multipe browsers ( test it )? Only have one open at anytime!
    2. When exactly do they occur and where are you redirected too?
    3. Does it happen in safe boot mode too?
     
  8. sammy711

    sammy711 Private E-2

    On Firefox with only Firefox open:
    I searched for "burn fat" via the Google search bar, then clicked on an about.com link and it re-directed me to hoetogetabbs.com/ (fyi, not a typo... it was hoetogetabbs.com).

    When I then click on the back button and click on another link, no re-direction occured.

    I then searched for "home loan" and clicked on a lendingtree.com link and no re-direction occured.

    It seems like it will re-direct once and then I cannot get it to re-direct again... but if I come back to the computer a few hours later it will re-direct once again.

    It's like it re-directs just once intermittently to not be a nuisance or "alarm" anyone.

    On IE with only IE open:
    I searched for "burn fat" via the Google search bar, then clicked on a link other than about.com and no re-direction occurred.

    I searched for "home loan" via the Google search bar, then clicked on a link other than lendingtree.com and no re-direction occurred.

    After about 4-hours... I got back on my computer but re-started in Safe Mode.

    In Safe Mode with only Firefox open:
    I searched for "home mortgage" via the Google search bar, then clicked on a link and it re-directed to joinmcatoday.com. Before it was finished with the re-direct it hung up for a second on a website... the url was bidvertiser.com.

    I did not do a search with IE... I forgot. Let me know if you want me to do an IE search in Safe Mode.

    Thanks!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then it seems that your problem is not malware but Firefox which is quite common. And one of the easy ways to clear this up is to remove Firefox, remove folders from it, and reinstall. Since you have an old Firefox, we will also install a more current version.



    We are going to be uninstalling your old version of FireFox and installing the new version. So do the below to save bookmarks:
    • Run FireFox and click Bookmarks.
    • Then select Organize Bootmarks.
    • Then on the next window click File and then select Export. Save the bookmarks.html file to your Desktop for later use in importing.
    Now download and save the installer for the current version of FireFox but DO NOT install it yet. Get it here: Mozilla Firefox 14.0.1 Final


    You will need exit FireFox now and use Internet Explorer to continue with the below until we reinstall FireFox.

    Start by uninstalling FireFox and then reboot. Do not skip the reboot.

    After reboot, delete the below folders:
    C:\Program Files\Mozilla Firefox
    C:\Documents and Settings\johnjr.MDFRWS03\Local Settings\Application Data\Mozilla

    Now reinstall FireFox from the file previously downloaded.
    Import your bookmarks file. (similar process to exporting).

    Does this fix your problems?
     
  10. sammy711

    sammy711 Private E-2

    I followed your instructions from the previous post.

    I ran a test & searched for "fat burning workout" and was re-directed to the following URL: makesyourdietwork.com

    The problem remains... what should I do next?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall Firefox and then delete those folders again. Do not reinstall Firefox yet until requested. Then (only after you have uninstalled Firefox and delete the folders ) run the below sets of scans and attach new logs.


    Please download OTL by OldTimer.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • OTL.txt
    • C:\MGlogs.zip
     
  12. sammy711

    sammy711 Private E-2

    I un-installed Firefox and have not re-installed Firefox as you said. Attached are the logs you requested.

    Thanks!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now shut down your protection software (antivirus, antispyware...etc) to avoid possible conflicts.
    Code:
    :OTL
    SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
    SRV - File not found [Disabled | Stopped] --  -- (Ccdroxy)
    [2012/08/28 22:00:56 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Firefox.lnk
    [2004/08/04 05:00:00 | 000,002,048 | -HS- | C] () -- C:\WINDOWS\Installer\{4146b9ba-c22d-f2da-e831-7727c92df06d}\@
    @Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    @Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FA5F15C4
    :Files
    C:\WINDOWS\installer\{4146b9ba-c22d-f2da-e831-7727c92df06d}\U
    C:\WINDOWS\installer\{4146b9ba-c22d-f2da-e831-7727c92df06d}
    C:\Documents and Settings\All Users\Application Data\036E18DF03CB5D4318636B167B07D287
    :Commands
    [PURITY]
    [EMPTYTEMP] 
    [EMPTYFLASH]
    [REBOOT]
    • Now click the http://img3.imageshack.us/img3/407/otlrunfix.png button.
    • If the fix needed a reboot please do it.
    • Click the OK button (upon reboot).
    • When OTL is finished, Notepad will open. Close Notepad.
    • A log file will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.
    • Attach this log to your next message. (See: How to attach)

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • the log from OTL
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. sammy711

    sammy711 Private E-2

    Attached are the logs. You said to let you know how things are now working but haven't given direction to re-install Firefox yet... do you want me to re-install Firefox and test?
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    IF you are not being redirected with Internet Explorer then yes, reinstall Firefox now and test it out.
     
  16. sammy711

    sammy711 Private E-2

    I reinstalled Firefox and tested it out... I am no longer being redirected so looks like I am cured! Thank you!!!

    Is there anything I should do now? Create a restore point? Other?

    Should I continue to test over the next week or so? I recall there being something in the "READ ME FIRST" process that disabled something but said I could enable it after the malware/spyware was removed.

    Thank you so much for your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  18. sammy711

    sammy711 Private E-2

    All final steps complete... thanks again for your help!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds