08-01-2012 06:43 AM
i have hacktool.rootkit and a couple trojan one is zeroaccess and the other is a gen2 iirc and no matter how many times norton scans it will not fully remove any help is much appreciated im running on vista sp2 64
thank you for your time
Solved! Go to Solution.
08-01-2012 07:57 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Do you have a Flash Drive??
Quads
08-02-2012 05:54 AM
Thank you for the quick reply ive seen youve really had your hands full this past month...
Yes i do have a flash drive
08-02-2012 09:21 PM
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
08-03-2012 06:28 AM
08-03-2012 07:59 PM
I will have FRST get me more information
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
08-03-2012 08:59 PM
08-04-2012 07:31 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
08-04-2012 09:50 PM
ComboFix 12-08-05.02 - User 08/04/2012 23:42:55.2.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4093.2915 [GMT -4:00]
Running from: c:\users\User\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\programdata\Roaming
c:\programdata\Roaming\Intel\Wireless\Settings\Set
c:\users\User\GoToAssistDownloadHelper.exe
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\SysWow64\ReadMe.txt
c:\windows\SysWow64\URTTemp
c:\windows\SysWow64\URTTemp\regtlib.exe
.
c:\windows\system32\Services.exe . . . is infected!!
.
.
((((((((((((((((((((((((( Files Created from 2012-07-05 to 2012-08-05 )))))))))))))))))))))))))))))))
.
.
2012-08-05 04:26 . 2012-08-05 04:26 -------- d-----w- c:\windows\system32\config
2012-08-05 04:26 . 2012-08-05 04:26 -------- d-----w- c:\users\Default\AppData\L
2012-08-03 17:17 . 2012-08-03 17:17 -------- d-----w- C:\FRST
2012-07-12 06:19 . 2012-06-13 13:58 2769408 ----a-w- c:\windows\system32\win32k.
2012-07-10 18:13 . 2012-07-10 18:13 -------- d-----w- c:\windows\SysWow64\A444~1
2012-07-10 05:23 . 2012-07-10 05:23 -------- d-----w- c:\windows\SysWow64\DE1B~1
2012-07-08 14:35 . 2012-07-08 19:10 -------- d-----w- c:\users\User\AppData\Loca
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-04 04:01 . 2012-03-30 04:53 426184 ----a-w- c:\windows\SysWow64\FlashPla
2012-08-04 04:01 . 2011-06-07 07:20 70344 ----a-w- c:\windows\SysWow64\FlashPlay
2012-07-12 06:21 . 2006-11-02 12:35 59701280 ----a-w- c:\windows\system32\mrt.ex
2012-06-02 22:19 . 2012-06-21 07:04 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 07:05 2428952 ----a-w- c:\windows\system32\wuaueng
2012-06-02 22:19 . 2012-06-21 07:05 57880 ----a-w- c:\windows\system32\wuauclt.e
2012-06-02 22:19 . 2012-06-21 07:05 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 07:04 35864 ----a-w- c:\windows\SysWow64\wups.dll
2012-06-02 22:19 . 2012-06-21 07:04 701976 ----a-w- c:\windows\system32\wuapi.dl
2012-06-02 22:19 . 2012-06-21 07:04 577048 ----a-w- c:\windows\SysWow64\wuapi.dl
2012-06-02 22:15 . 2012-06-21 07:05 2622464 ----a-w- c:\windows\system32\wucltux
2012-06-02 22:15 . 2012-06-21 07:04 99840 ----a-w- c:\windows\system32\wudriver.
2012-06-02 22:12 . 2012-06-21 07:04 88576 ----a-w- c:\windows\SysWow64\wudriver.
2012-06-02 19:19 . 2012-06-21 07:04 186752 ----a-w- c:\windows\system32\wuwebv.d
2012-06-02 19:19 . 2012-06-21 07:04 171904 ----a-w- c:\windows\SysWow64\wuwebv.d
2012-06-02 19:15 . 2012-06-21 07:04 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 19:12 . 2012-06-21 07:04 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
2012-05-15 06:37 . 2012-06-14 03:01 916992 ----a-w- c:\windows\SysWow64\wininet.
2012-05-15 06:32 . 2012-06-14 03:01 43520 ----a-w- c:\windows\SysWow64\licmgr10.
2012-05-15 06:32 . 2012-06-14 03:01 1469440 ----a-w- c:\windows\SysWow64\inetcpl
2012-05-15 06:31 . 2012-06-14 03:01 109056 ----a-w- c:\windows\SysWow64\iesyspre
2012-05-15 06:31 . 2012-06-14 03:01 71680 ----a-w- c:\windows\SysWow64\iesetup.d
2012-05-15 05:01 . 2012-06-14 03:01 385024 ----a-w- c:\windows\SysWow64\html.iec
2012-05-15 03:26 . 2012-06-14 03:01 133632 ----a-w- c:\windows\SysWow64\ieUnatt.
2012-05-15 03:23 . 2012-06-14 03:01 1638912 ----a-w- c:\windows\SysWow64\mshtml.
2012-05-15 02:19 . 2012-06-14 03:01 1147392 ----a-w- c:\windows\system32\wininet
2012-05-15 02:19 . 2012-06-14 03:01 1488384 ----a-w- c:\windows\system32\urlmon.
2012-05-15 02:19 . 2012-06-14 03:01 108032 ----a-w- c:\windows\system32\url.dll
2012-05-15 02:18 . 2012-06-14 03:01 243712 ----a-w- c:\windows\system32\occache.
2012-05-15 02:16 . 2012-06-14 03:01 1062912 ----a-w- c:\windows\system32\mstime.
2012-05-15 02:15 . 2012-06-14 03:01 9328640 ----a-w- c:\windows\system32\mshtml.
2012-05-15 02:15 . 2012-06-14 03:01 98304 ----a-w- c:\windows\system32\mshtmled.
2012-05-15 02:15 . 2012-06-14 03:01 742912 ----a-w- c:\windows\system32\msfeeds.
2012-05-15 02:15 . 2012-06-14 03:01 71680 ----a-w- c:\windows\system32\msfeedsbs
2012-05-15 02:15 . 2012-06-14 03:01 56832 ----a-w- c:\windows\system32\licmgr10.
2012-05-15 02:15 . 2012-06-14 03:01 31744 ----a-w- c:\windows\system32\jsproxy.d
2012-05-15 02:14 . 2012-06-14 03:01 1538560 ----a-w- c:\windows\system32\inetcpl
2012-05-15 02:14 . 2012-06-14 03:01 77312 ----a-w- c:\windows\system32\iesetup.d
2012-05-15 02:14 . 2012-06-14 03:01 2350592 ----a-w- c:\windows\system32\iertuti
2012-05-15 02:14 . 2012-06-14 03:01 219136 ----a-w- c:\windows\system32\ieui.dll
2012-05-15 02:14 . 2012-06-14 03:01 132096 ----a-w- c:\windows\system32\iesyspre
2012-05-15 02:14 . 2012-06-14 03:01 72192 ----a-w- c:\windows\system32\iernonce.
2012-05-15 02:14 . 2012-06-14 03:01 12508672 ----a-w- c:\windows\system32\iefram
2012-05-15 02:14 . 2012-06-14 03:01 252416 ----a-w- c:\windows\system32\iepeers.
2012-05-15 02:14 . 2012-06-14 03:01 459776 ----a-w- c:\windows\system32\iedkcs32
2012-05-15 01:21 . 2012-06-14 03:01 479232 ----a-w- c:\windows\system32\html.iec
2012-05-15 00:40 . 2012-06-14 03:01 162816 ----a-w- c:\windows\system32\ieUnatt.
2012-05-15 00:40 . 2012-06-14 03:01 70656 ----a-w- c:\windows\system32\ie4uinit.
2012-05-15 00:39 . 2012-06-14 03:01 12288 ----a-w- c:\windows\system32\msfeedssy
2012-05-15 00:39 . 2012-06-14 03:01 1638912 ----a-w- c:\windows\system32\mshtml.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[7] 2009-04-11 . 934E0B7D77FF78C18D9F8891221B6DE3 . 384512 . . [6.0.6002.18005] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-ser
[7] 2008-01-21 . DFAC660F0F139276CC9299812DE42719 . 384512 . . [6.0.6001.18000] .. c:\windows\winsxs\amd64_microsoft-windows-s..s-ser
[-] 2009-04-11 . B8844F93D2C5F1DCDB179AAA9AF134B7 . 381952 . . [6.0.6000.16386] .. c:\windows\system32\services.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curr
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft
"NDSTray.exe"="NDSTray.exe" [BU]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"VirtualCloneDrive"="c:\program files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 89456]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-05-31 59280]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-06-07 421776]
.
c:\users\User\AppData\Roaming\Microsoft\Windows\St
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
Stardock ObjectDock.lnk - c:\program files (x86)\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-6 3768176]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2012-1-8 107720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\cur
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"DisableCAD"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft
"aux"=wdmaud.drv
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPl
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft
Akamai REG_MULTI_SZ Akamai
.
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\
Themes
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-05 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-06 09:41]
.
2012-08-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-06 09:41]
.
2012-08-05 c:\windows\Tasks\User_Feed_Synchronization-{89CB71
- c:\windows\system32\msfeedssync.exe [2012-06-14 03:24]
.
2012-08-05 c:\windows\Tasks\User_Feed_Synchronization-{F5C35A
- c:\windows\system32\msfeedssync.exe [2012-06-14 03:24]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur
"RtHDVCpl"="RAVCpl64.exe" [2008-04-08 6156288]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2009-09-17 190472]
"Rainmeter"="c:\program files\Rainmeter\Rainmeter.exe" [2012-01-08 107720]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.yahoo.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183
LSP: mswsock.dll
TCP: DhcpNameServer = 192.168.2.1
CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D59
Wow6432Node-HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Wow6432Node-HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macrome
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUt
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\C
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\I
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\I
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\I
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\T
@Denied: (A 2) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\T
@="Shockwave Flash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\T
@Denied: (A 2) (Everyone)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\T
@="FlashBroker"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\C
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\C
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\C
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe
c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
c:\program files (x86)\Motorola\MotoConnectService\MotoConnectServi
c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe
c:\program files (x86)\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
c:\program files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\program files (x86)\Toshiba\ConfigFree\NDSTray.exe
c:\program files (x86)\Toshiba\ConfigFree\CFSwMgr.exe
c:\program files (x86)\Motorola\MotoConnectService\MotoConnect.exe
.
**************************************************
.
Completion time: 2012-08-05 00:38:14 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-05 04:38
.
Pre-Run: 176,104,226,816 bytes free
Post-Run: 175,815,790,592 bytes free
.
- - End Of File - - D88BA4E8C2F10D4A0544DBE5D4B4F72F
08-05-2012 05:43 PM
You didn't attach the post.
Quads
