Reply
Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Malware Removal Forum

Tackled a zeroacces variant on a laptop (x86) took a bit of time and 3 restarts and still not all files can be shifted. People love to bag Norton (Symantec) with stating to use even like Avast or AVG etc. but I had a laugh as Zeroaccess on this system selected to infect AVG (Haha, no anti-tamper protection).

 

list

 

c:\users\Marewa\AppData\Local\31868fd4\U
c:\users\Marewa\AppData\Local\31868fd4\U\00000001.@
c:\users\Marewa\AppData\Local\31868fd4\U\000000c0.@
c:\users\Marewa\AppData\Local\31868fd4\U\000000cb.@
c:\users\Marewa\AppData\Local\31868fd4\U\000000cf.@
c:\users\Marewa\AppData\Local\31868fd4\U\80000000.@
c:\users\Marewa\AppData\Local\31868fd4\U\800000c0.@
c:\users\Marewa\AppData\Local\31868fd4\U\800000cb.@
c:\users\Marewa\AppData\Local\31868fd4\U\800000cf.@
c:\windows\$NtUninstallKB16813$\206546423
c:\windows\$NtUninstallKB16813$\830902228\@
c:\windows\$NtUninstallKB16813$\830902228\L\xadqgnnk
c:\windows\$NtUninstallKB16813$\830902228\loader.tlb
c:\windows\$NtUninstallKB16813$\830902228\U\@00000001
c:\windows\$NtUninstallKB16813$\830902228\U\@000000c0
c:\windows\$NtUninstallKB16813$\830902228\U\@000000cb
c:\windows\$NtUninstallKB16813$\830902228\U\@000000cf
c:\windows\$NtUninstallKB16813$\830902228\U\@80000000
c:\windows\$NtUninstallKB16813$\830902228\U\@800000c0
c:\windows\$NtUninstallKB16813$\830902228\U\@800000cb
c:\windows\$NtUninstallKB16813$\830902228\U\@800000cf
c:\windows\system32\service
c:\windows\system32\service\05022011_TIS17_SfFniAU.log
c:\windows\system32\service\18072011_TIS17_SfFniAU.log
c:\windows\$NtUninstallKB16813$       Could not delete folder, had to manually powertool force delete

 

C:\Windows\system32\DRIVERS\avgtdix.sys  infected!!

 

Still to force delete below, but have copied.

 

C:\Windows\system32\FreeTdi.dll

C:\Windows\system32\tsp.dll

C:\Windows\system32\GTPTSER.dll

C:\Windows\system32\motmodem.dll

 

Quads

 


Bot Obliterator
elsewhere
Posts: 1,137
Registered: ‎05-30-2009

Re: Malware Removal Forum

[ Edited ]

Quads wrote:

[...]

 

It was the fact in this open forum, people would tell the user to install or run everything but the kitchen sink, which could make things worse, harder to remove, or start telling the user to run tools I was using, but yet they didn't know how how to properly use the tools, know what they were looking at or how to script / fix a problem if it occurs.

Other times I would be half way through removal and waiting for the user reply, I would be offline. another user would jump in saying do this do that. GEEZ, made things harder.

 

So I decided it's not a good idea to do advanced removal on a open forum and I can see why removal forums have protection in place.

 

[...]


Given that one-on-one remediation has become necessary again, the forum Admins need to look at options here that will allow you to assist these particular thread authors without interference from third-parties. My initial thoughts on this; is thread access controlled by a Forum Security Group? If so, then could a 'Quads' Forum Security Group be created that had the following attributes:

 

  • Forum members (including Gurus): Read only;
  • Quads + Moderator-selected thread authors: Read / Write

If so, then Forum Moderators could add users targeted for one-on-on remediation to the 'Quads' Forum Security Group, based solely on an appropriately worded 'Report Inappropriate Content' notification to the Moderators from yourself. Forum Moderators would then add the forum member and apply the 'Quads' Forum Security Group to the thread in question, effectively locking it from third-party interference.

 

Another reason for this post is that threads like this one hardly reflect a positive forum experience for the user who posted advice with best intentions. Expecting forum members to know the status quo around here by virtue of the fact that you are participating in a thread is hardly an effective way of maintaining thread integrity, as you, yourself, have acknowledged above...

 

I trust that the forum Moderators/Admins will review this and advise what options are available here.

Bot Obliterator
Andmike
Posts: 2,258
Registered: ‎03-23-2011

Re: Malware Removal Forum

My primary thought on reading this post is are you/we expecting too much of Quads?  He does an amazing job but despite his name there is but one.  [As far as I am aware!]

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: Malware Removal Forum

There is only one Quads (I hear people saying thank gawd for that).

 

Quads

dickevans
Posts: 9,217
Registered: ‎04-08-2008

Re: Malware Removal Forum


Quads wrote:

There is only one Quads (I hear people saying thank gawd for that).

 

Quads


And there are those who say 'Thank God that there is one!'


 

Dick
Win7x64 SP1 current NIS V20
Contributor
Jeevith
Posts: 24
Registered: ‎05-13-2012

How to Remove Trojan.Zeroaccess.B

How to Remove Trojan.Zeroaccess.B
 

1. Temporarily Disable System Restore

2. To be able to identify even the most recent variant of Trojan.Zeroaccess.B, open your antivirus application and update the virus definition file.

3. Start Windows in Safe Mode with Networking.
- From a power-off state, turn on the computer and press F8 on your keyboard repeatedly.
- Your computer will display Windows Advanced Boot Options menu. Please select Safe Mode with Networking.
- The system will now boot Windows and loads only necessary drivers and files.

4.Delete the following file:
C:\Windows\System32\ consrv.dll

5.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems .Export from regedit, manually edit to replace consrv.dll with the correct data, then re-import.

6.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems\”Windows” = “consrv:ConServerDllInitialization”

Press CTRL + ALT +DEL to access Task Manager and stop the following process:
consrv.dll

Go To Regedit  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems .Replace the consrv with good substring ServerDll=winsrv:ConServerDllInitialization with the infected substring ServerDll=consrv:ConServerDllInitialization.

7.Delete Associated Files and Folders:

%Windir%\assembly\tmp\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6} %System%\consrv.dll %Windir%\assembly\tmp\U\80000000.@ %Windir%\assembly\tmp\U\800000cb.@ %Windir%\assembly\tmp\U\800000cf.@
8.Restart The computer computer.Issue is Fixed
Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: How to Remove Trojan.Zeroaccess.B

I have found where these instructions don't work for 64 bit systems either hahaha it just changes it back after you change the registry.  a bit more clever.

 

Quads