|
Help remove zeroaccess rootkit
|
|
01-01-2013, 07:42 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Download Windows Repair (all in one) from this site
Install the program then run it. Go to step 2 and allow it to run Disc check by clicking Do It Go to step 3 and allow it to run SFC Go to start repairs tab select advanced mode and click start. Check the box next to "Restart/Shutdown system when finished" and ensure the following is checked along with the default checks
Register System Files Repair WMI Remove Policies Set By Infections then click Start Then run Farbar's Service Scanner again and post the log. See if you are able to connect to the internet after. If you can, goto http://www.virustotal.com and upload: C:\WINDOWS\system32\wbem\wbemess.dll C:\WINDOWS\system32\wbem\fastprox.dll After each analysis, you will be taken to a results page. Please copy and paste the URL/link of that page in your next reply. Then, download a new copy of TDSSkiller from here
Post the log after (usually C:\ folder in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt |
|||
|
|
01-02-2013, 07:05 AM
(This post was last modified: 01-02-2013 07:46 AM by Papirus.)
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
OK, these were the steps that I did (all in Windows Normal Mode):
1. Run Windows Repair (all 3 steps)....but I forget to close the antivirus, norton ghost and hitman pro services. 2. Run FSS and network still not working. Here is the log. FSS 2013-01-01.txt (Size: 2.89 KB / Downloads: 24)
3. Run Windows Repair again for step 3 (repair) and this time I close the above services to avoid conflicts. 4. Run FSS and network still not working. Here is the log. FSS 2013-01-01b.txt (Size: 2.89 KB / Downloads: 29)
5. Run TDSSKiller and here is the log. TDSSKiller.Set Load Module.log.txt (Size: 9.38 KB / Downloads: 27)
(load module checked) TDSSKiller.Scan_log.txt (Size: 208.83 KB / Downloads: 20)
(scan log)Then I run the OTL mode again to scan the wbemess.dll and fastprox.dll in http://www.virustotal.com. None of them show any sign of virus. Then I run McAfee Root Kit Remover in OTL mode. Interestingly, it says that it found zeroaccess rootkit in the CD. Here is the log. RootkitRemover20130101223836.txt (Size: 700 bytes / Downloads: 37)
.I upload the shell32.dll from the CD to virustotal.com and it does not find any virus. Is this a false positive error from McAfee Rootkit Remover? Is there a way for someone or McAfee to check the Rootkit Remover tool? Also, I can restore my computer in 20 minutes using the backup data that I have and therefore fix the network problems. However, all other steps that we did will be gone and zeroaccess issue will pop up again (even though I am not sure if this is really an issue or not). Do you have any thought on this? Thanks. |
|||
|
01-02-2013, 08:26 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
well that's odd... There's no way the CD has an infection... Is the X drive your CD drive? How many operating systems do you have on the PC? The logs show that you have many partitions. Also, when did you lose internet? Was it after running comodo or one of my instructions? Please download MiniToolBox save it to your desktop and run it. Place a check in the following boxes:
Report IE Proxy Settings Reset IE Proxy Settings Report FF Proxy Settings Reset FF Proxy Settings List content of Hosts List IP configuration List Winsock Entries List last 10 Event Viewer log List Installed Programs List Devices List Users, Partitions and Memory size. List Minidump Files Close your browsers and click Go. Post the Result.txt located in the same directory as the tool. Your C-drive looks clean from the logs.. Does McAfee Root Kit Remover still say C:\WINDOWS\system32\wbem\wbemess.dll & C:\WINDOWS\system32\wbem\fastprox.dll are infected? |
|||
|
01-03-2013, 06:49 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
Well, I create the CD from the infected/corrupted desktop so I am not sure if in the process it infected those files before it got written to the CD. I am not familiar with how the Reatogo CD is created and I am just guessing for the possibilities. I have 3 Hard Drives and all are partitioned. The X is for the CD. I am confused myself why only McAfee recognize the virus but not the other antivirus. In regards to the network issues, the internet connection was lost even when I was still running the Comodo scan. However, I am not sure what had caused it. The Comodo found many issues during the scan but mostly on files reside in other drive (not C) except for sysbar.exe in C:\windows folder. Today, I run the Minitoolbox from Windows Normal mode and attached the log file here. Result 2013-01-02.txt (Size: 14.21 KB / Downloads: 28)
Then I run the McAfee rootkit remover one more time and to my surprise there is NO more virus found. BTW. I did not run McAfee rootkit remover in Windows Normal mode yesterday but I run it in OTL windows mode. It looks like the Windows repair (Tweaking) fixed the problems by replacing those infected files (or rewriting the registries). Do you have any explanation to this solution? Also, I tried to create another boot CD but this time I did it from a clean computer. After rebooting the system, I run the McAfee rootkit remover in OTL mode and it found zeroaccess malware on Shell32.dll and shdocvw.dll files on i386\system32 folders. So at this time, the only problem I have is the internet connection or network driver problem (including firewall, socket, etc.) If I run the backup restore and run the windows repair tool again, will it solve the virus and internet connection problem? Could you please advise? MANY thanks for your help.....but still need help on the internet part though
|
|||
|
01-03-2013, 07:31 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
The Shell32.dll and shdocvw.dll detection are false positives since OTLPE is a clean program. If it is coming from the X drive then you have nothing to worry about. Don't run the rootkit remover in OTLPE as it may not scan the PC properly. If you ran it in normal mode and no infection was found, then that is good. I'm not too sure what caused you to lose internet. I went back to check the fixes I gave you and none of them should have affected your internet, unless the malware made a modification to your system files. However, ServiceRepair and windows repair should have fixed it. Nonetheless, let's try something else. Goto Start > Run > type cmd. In the command prompt, type tracert google.com >trace.txt then press Enter. Wait for a minute or two. Then goto the directory that is shown on the command prompt. It should be something like: C:\... and find trace.txt and post it here. Next, Run the Complete Internet Repair utility.
|
|||
|
01-04-2013, 04:11 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
OK, I run the tracert using full url http://www.google.com but it cannot resolve the hostname as shown in the output here. tracert.txt (Size: 55 bytes / Downloads: 20)
I download the Complete Internet Repair from this site: http://datumza.com/downloads/ and select the CIR v1.3.1.115 (32Bit). I run it with the options you mentioned checked and reboot the system but it still does not have the Network connectivity....really puzzling.... Thanks. |
|||
|
01-04-2013, 05:06 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
Are you using any firewalls? Disable all of them and see if you are able to access the internet. Please do a fresh FRST scan in OTLPE so I can see the state of your PC If the FRST log doesn't show anything, as a last resort.. we can restore the backup you made to get internet back and will remove the malware again. |
|||
|
01-05-2013, 03:20 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Hi,
I am not using any firewall and in fact the firewall is messed up too (I cannot enable or disable it). OK, let me try to restore the backup and I will run the service repair and windows repair after that.....I will reply back after that. I am hoping that the restore system does not overwrite the wbemes.dll and fastprox.dll if it found existing one. But let's see what will happen. Thanks. |
|||
|
01-06-2013, 02:13 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
Fiery, it looks like I have cleaned up the rootkit by running the service repair and windows repair (tweaking).
After the restore, the rootkit shows up again and the internet still did not work. However, the network got fixed after I run the service repair tool. Then I run the windows repair to replace the infected files. To be on the safe site, I run Comodo (some malwares found and cleaned), Hitman Pro (in progress), MalwareBytes (in progress), Ad-Aware (in progress), TDSSKiller (no rootkit found), McAfee Rootkit Remover (no zero access rootkit found), Norton FixZeroAccess (no rootkit found). Do you have any recommendation on what tool I should use to accurately verify/check the MBR? Many thanks again for your persistence and I really appreciate your help. |
|||
|
01-06-2013, 02:23 AM
|
|||
|
|||
|
RE: Help remove zeroaccess rootkit
That's good to hear! Let me know how things go. If you want me to verify your MBR:
Should you wish to run an extra anti-rookit tool for assurance: Download Malwarebytes Anti-Rootkit from here to your Desktop
|
|||
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads... | |||||
| Thread: | Author | Replies: | Views: | Last Post | |
| Rootkit.Zeroaccess | schoj05 | 29 | 375 |
Today 12:04 AM Last Post: kuttus |
|
| zeroaccess.hi removal help/walkthrough | MetroidSnacks | 3 | 231 |
04-27-2013 12:17 AM Last Post: MetroidSnacks |
|
| ZeroAccess.hi preventing EZSirefix download | Dominic_Cyning | 1 | 171 |
04-16-2013 03:43 PM Last Post: Fiery |
|
| remove ZeroAccess Sirefef rootkit WITHOUT INTERNET | LKS105 | 26 | 683 |
04-03-2013 05:58 PM Last Post: kuttus |
|
| Rootkit Removal. | MrExplorer | 12 | 424 |
03-21-2013 04:20 AM Last Post: Fiery |
|
User(s) browsing this thread: 1 Guest(s)
Contact Us |
Privacy policy |
Return to Top |
Return to Content |
Lite (Archive) Mode |
RSS Syndication |
Members List |
Forum Team
MalwareTips.com is an independent website.All trademarks mentioned on this page are the property of their respective owners.


![[Image: clip.jpg]](http://img.photobucket.com/albums/v257/MrChalee/clip.jpg)


![[Image: avast-mbr-1.png]](http://malwaretips.com/blogs/wp-content/uploads/2012/07/avast-mbr-1.png)
![[Image: avast-mbr-2.png]](http://malwaretips.com/blogs/wp-content/uploads/2012/07/avast-mbr-2.png)