Avast WEBforum

Other => Viruses and worms => Topic started by: Uthmer on June 30, 2013, 08:34:31 PM

Title: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on June 30, 2013, 08:34:31 PM
Hello all,

You helped me last year with Sirefef virus, this time Avast keeps showing alert Win32:ZAccess-PB[Trj]
every 5 minutes or so. I´ve tried to remove it, but according to reports, my laptop is still infected.
I can´t download none of the tools that you provide, I don´t know why but they´re detected as a virus.
I´ve managed to get OTL report (I kept the aplication from last year), and the mbam-log as well, hope it´s enough.

I need your help again, please
 
Thanks in advance,
Ruth
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Pondus on June 30, 2013, 08:39:34 PM
you seems to have a ZeroAccess rootkit...again.    :'(     how do you do it.   :-[

removers are notified

Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on June 30, 2013, 08:39:59 PM
Monitoring ...
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on June 30, 2013, 08:50:51 PM
I think installing a codepack  ::)
In Spain we say "Man is the only animal to stumble over the same stone twice" :-\
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on June 30, 2013, 08:54:41 PM
Infection has load its loading files today. This is something that you have been downloading and ran from torrents ...

probably this:
C:\Users\Txomin\Desktop\L.A. - Dualize 2013.rar

If you do not know how to use torrents then don't use them. Why would I separated my free time to help you if you first do not want to help yourself?
+ torrents are illegal stuff, even if I would tell you to not use torrents you probably won't obey.


Fixing ...

Re-run OTL.exe.

Code: [Select]

:Commands
[CREATERESTOREPOINT]

:Otl
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
O4 - HKU\S-1-5-21-2039352587-2439263487-3237410795-1000..\Run: [AdobeBridge]  File not found
[2013/06/30 17:38:59 | 000,000,804 | ---- | C] () -- C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\L\00000004.@
[2013/06/30 17:38:58 | 000,015,360 | ---- | C] () -- C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\U\80000000.@
[2013/06/30 17:38:58 | 000,002,048 | ---- | C] () -- C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\U\00000004.@
[2013/06/30 15:02:04 | 000,001,024 | ---- | C] () -- C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\U\00000008.@
[2012/01/11 15:43:54 | 000,002,048 | -HS- | C] () -- C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\@

:Files
C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}
ipconfig /flushdns /c

:Commands
[emptytemp]

THEN ...




> Download ComboFix from here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.
If you are unsure how ComboFix works please read this guide (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html) or this (http://www.bleepingcomputer.com/forums/topic114351.html) Instruction.

How to disable avast:

Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on June 30, 2013, 09:54:00 PM

I know is absolutly my fault, but it has nothing to do with that archive, I think it has been installing a codepack.
The OTL is not responding with the code you gave me. I guess I´ve done something bad
I´m really sorry to take your time.
Thank you so much anyway Magna86,
Ruth
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on June 30, 2013, 09:55:54 PM

I know is absolutly my fault, but it has nothing to do with that archive, I think it has been installing a codepack.
The OTL is not responding with the code you gave me. I guess I´ve done something bad
I´m really sorry to take your time.
Thank you so much anyway Magna86,
Ruth

Don't quit on me yet ... try to run Combofix. We will clean this mashine.  ;)
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on June 30, 2013, 10:02:19 PM
I can´t download any program, Avast detects them as a virus...
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on June 30, 2013, 10:06:27 PM
I can´t download any program, Avast detects them as a virus...

Avast detect Combofix? Are you shure? Disable avast and try again to download and run Combofix as instructed. If you fail, just let me know, we will use another tool that I have in my heands.
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on June 30, 2013, 10:25:11 PM
I have tried it three more times, even with Avast disabled, but is detected as a virus. Attached screenshot
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on June 30, 2013, 10:32:39 PM
Hm ... that doesn't look as avast.  :)


Follow this guide from here for running RogueKiller;
http://forum.avast.com/index.php?topic=53253.0

Attach here all RK_reports


THEN ...



Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 07:42:53 PM
Hi again,
I´ve managed to download the aplications from a friend´s laptop, you were right,
it had nothing to do with Avast, was related to Windows. Yesterday I didn´t think clearly.
I´ve followed the instructions and have attached requested reports. In case you need something else, let me know, please
I appreciate your help
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 01, 2013, 08:24:51 PM


1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system


Code: [Select]
Start
File: %SystemRoot%\system32\shell32.dll
HKLM-x32\...\Run: []  [x]
HKCU\...\Run: [AdobeBridge]  [x]
Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5 03 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}\U
C:\Windows\Installer\{0a7579f0-3fba-27f3-3dab-5d5370e62ba6}
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini
End


2. Save notepad as fixlist.txt
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.

Note: If the tool warned you about the outdated version please download and run the updated version.
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 08:36:19 PM
Here is the fix log
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 01, 2013, 08:39:06 PM
Looks good. Now try to download fresh copy of Combofix.exe and re-run it as instructed above.
Attach here Combofix.txt log.
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 09:30:07 PM
Done. Combofix file attached
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 01, 2013, 10:40:50 PM
Job done.  8)



It is necessary to uninstall ComboFix :
Code: [Select]
ComboFix /Uninstall Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Wait for the uninstall process is complete.



Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.


I recommended you to keep Malwarebytes and to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://www.mcshield.net)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 10:45:08 PM
Good job,
Thanks a lot!  :)
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 10:49:45 PM
It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
One quick question according to this, do you think the infection could have been via pendrive? or was the codec pack?
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 01, 2013, 11:02:47 PM
One quick question according to this, do you think the infection could have been via pendrive? or was the codec pack?

As I can see from logs, ZeroAccess has been load his own malicious loading files into system on 2013/06/30 at 17:38: 58 - 59 according to your computer time.
What did you do at that moment or a few minutes before that, only you know for shure.


Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 11:15:36 PM
Ok, thanks for your quick response and for your time,
Ruth
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 01, 2013, 11:19:41 PM
Ok, thanks for your quick response and for your time,
Ruth

You owe me a beer.    ;D


Cheers
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 01, 2013, 11:25:27 PM
I owe you a barrel!! but it will have to be when I move to London  ;D
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 02, 2013, 08:15:26 PM
Hi Magna86, sorry to bother you again, but when I try to uninstall Combofix, Windows shows an alert "Windows can not find this file",
is that fine? should I run Delfix anyway?
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: magna86 on July 02, 2013, 09:42:36 PM
Hi Magna86, sorry to bother you again, but when I try to uninstall Combofix, Windows shows an alert "Windows can not find this file",
is that fine? should I run Delfix anyway?

You have been deleted Combofix.exe, that's why it's show you this: "Windows can not find this file"

Run DelFix anyway, it will remove CF and all it's related files.  ;)
Title: Re: Malware Win32ZAccess-PB [Trj]
Post by: Uthmer on July 02, 2013, 10:10:12 PM
Done. These tools are delicate and wanted to make sure...
Thank you!!  :D