ZeroAccess

Discussion in 'Malware Help (A Specialist Will Reply)' started by davidchu, Sep 11, 2012.

  1. davidchu

    davidchu Private E-2

    My computer has ZeroAccess according to Malwarebytes Anti-malware.
    I started noticing it when my Microsoft Security Essentials started to try to "update" itself, and my Flash Player tried to as well. (both failed)
    Then, there was a weird sound in my computer, so I thought something was funny. The Microsoft Security icon disappeared, so I dug it out, and found that it was disabled. I couldn't enable it, as I got this error: 0x80070424
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello davidchu,

    http://img805.imageshack.us/img805/9659/rktigzy.gif Delete items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Once the scan is complete, go to the Registry tab and checkmark everything except the below items:
    • [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0)
    • [HJ] HKLM\[...]\System : EnableLUA (0)
    Now press the Delete button.
    RogueKiller typically requires a reboot in order to fully remove some of the offending entries, please do so if prompted
    Upon reboot (if you did reboot), rescan and press Delete again with RogueKiller.
    Attach the latest RogueKiller logs from your desktop to your next message. (How to attach)
     
  3. davidchu

    davidchu Private E-2

    Thanks!
    I did as you asked, and RogueKiller didn't need me to reboot, so I skipped that part.
    I unchecked 4 items in total, since there were 2 that were ConsentPromptBehaviorAdmin (0)
    and 2 that were
    EnableLUA (0)
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

  5. davidchu

    davidchu Private E-2

    Done~
    btw
    just so you know
    MSE still can't open
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

  7. davidchu

    davidchu Private E-2

    Did as asked....though there's a little problem
    I couldn't find the 1ClickDownloader in program files
    and I searched online, but most sites were red in WOT
    and MSE was down
    so I didn't do anything about it...
     

    Attached Files:

    • FSS.txt
      File size:
      3.8 KB
      Views:
      2
  8. thisisu

    thisisu Malware Consultant

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to the Start Repairs tab.
    • Press the Start button
    • Create a System Restore point if prompted.
    • In the Repair Options window, choose the following repairs:
      • Reset Registry Permissions
      • Repair Windows Firewall
    • Place a checkmark in Restart/Shutdown System When Finished
    • Fill in the Restart System bubble
    • Now click the Start button.
    • Be patient while the tool repairs the selected items. Your computer should automatically restart when finished.

    __

    • Download each of the 3 files below onto the desktop of the computer with the issues:
    • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
    • Let me know if you received a successful message for all four files.
      • If all were successful, reboot your computer and rescan with Farbar Service Scanner. Attach its latest log.
      • If they weren't successful, let me know but rescan with Farbar Service Scanner too.
     
  9. davidchu

    davidchu Private E-2

    Everything worked (except MSE)
    thanks for the trouble though
    (and wow you're fast!)
     

    Attached Files:

    • FSS.txt
      File size:
      2.7 KB
      Views:
      2
  10. thisisu

    thisisu Malware Consultant

    A couple more registry merges, see below. Retry MSE afterwards.

    • Download both of the files below onto the desktop of the computer with the issues:
    • Now double-click each of them, one at a time, and allow each one to merge into the Windows registry.
    • Let me know if you received a successful message for both files.
      • If all were successful, reboot your computer and rescan with Farbar Service Scanner. Attach its latest log.
      • If they weren't successful, let me know but rescan with Farbar Service Scanner too.
     
  11. davidchu

    davidchu Private E-2

    both worked, MSE still down
     

    Attached Files:

    • FSS.txt
      File size:
      2.8 KB
      Views:
      2
  12. thisisu

    thisisu Malware Consultant

    Download and install Revo Uninstaller

    Open Revo Uninstaller and find and locate these items (if they appear):

    • Microsoft Security Client
    • Microsoft Security Essentials

    Uninstall both of them (if they appeared) using the Moderate selection.

    __

    • Now run the attached services.bat file (it's inside services.zip). Extract services.bat onto your desktop and then Right-mouse click it and select "Run as Administrator".
    • When it is complete, there will be a file on your desktop entitled "ATTACH.txt".
    • Please attach this to your next post.

    __

    Now redownload and install MSE from here.
     

    Attached Files:

  13. davidchu

    davidchu Private E-2

    MSE didn't appear within Revo Uninstaller, so I uninstalled it using Program and Features.
    I ran the .bat file, and reinstalled MSE.
    MSE updated itself, and it is currently scanning.
    It says that the computer is protected though.

    EDIT: MSE is done scanning, and it is looking good.
     

    Attached Files:

    Last edited: Sep 12, 2012
  14. thisisu

    thisisu Malware Consultant

    That's good :)

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  15. davidchu

    davidchu Private E-2

    Thanks for your help!!!
     
  16. thisisu

    thisisu Malware Consultant

    You're welcome ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds