Reply
Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

The location really is not the real important piece here as the copies would have been backed up from system files originally and that is what we have to track down, where have they gone.

 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  •  Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!

 

Please read carefully

 

a) Uninstall Spybot S&D, also if Malwarebytes has it's realtime componant running, Uninstall Malwarebytes also.

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Just noticed auto protect added another instance at 21:09

 

Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02ce86a42}\rp906\a0115956.dll

Threat: Trojan.Zeroaccess!inf

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

That's OK, Just do my first instruction above.

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Both have been unistalled.  S&D required a reboot, so took awhile.

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

I may ask for both scans first to try and figure out what is going on for those files to be created.

 

Here is the first

 

Please read carefully

 

1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Well, it said scan finished successfully so I guess it was done.  Log attached.

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

Found at least some more of it,  hmmm have to be careful as a driver with this variantion can go missing, I am thinking.

 

In the meantime, and the scan can take some time

 

Please read carefully and Slowly

 

 Please scan with ESET next   Using Internet Explorer


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

That sure was a long scan. It said ZoneAlarm and Norton Anti-virus may interfer with the scan so I turned those off during the scan.

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

Please read carefully and follow these steps.


Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684  click on the TDSSkiller.exe green link.


Double click on TDSSKiller.exe to run the application,

Open the Change Parameters options and select the Detect TDLFS File System

Then on Start Scan.


If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Didn't seem to find anything.  Log attached.