This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.zeroaccess.b [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Norton is telling that I have a Trojan.zeroaccess.b that requires manual removal. I already tried some of Norton's suggestions, I ran the NPE but couldn't find anything. I also ran Roguekiller which found the trojan and other two viruses. I have been trying different suggestions but nothing has work so far. I would really appreciate the help to get rid of this. The following is the report from Roguekiller:

RogueKiller V7.6.3 [07/08/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Started in : Normal mode
User: Kraft [Admin rights]
Mode: Scan – Date: 07/12/2012 15:52:09

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 3 ¤¤¤
[ZeroAccess] HKCR\[…]\InprocServer32 : (C:\Users\Kraft\AppData\Local\{27c4a710-7ee3-6661-7aef-265de1ef4275}\n.) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] n : c:\windows\installer\{27c4a710-7ee3-6661-7aef-265de1ef4275}\n –> FOUND
[ZeroAccess][FILE] @ : c:\windows\installer\{27c4a710-7ee3-6661-7aef-265de1ef4275}\@ –> FOUND
[ZeroAccess][FOLDER] U : c:\windows\installer\{27c4a710-7ee3-6661-7aef-265de1ef4275}\U –> FOUND
[ZeroAccess][FOLDER] L : c:\windows\installer\{27c4a710-7ee3-6661-7aef-265de1ef4275}\L –> FOUND
[ZeroAccess][FILE] n : c:\users\kraft\appdata\local\{27c4a710-7ee3-6661-7aef-265de1ef4275}\n –> FOUND
[ZeroAccess][FILE] @ : c:\users\kraft\appdata\local\{27c4a710-7ee3-6661-7aef-265de1ef4275}\@ –> FOUND
[ZeroAccess][FOLDER] U : c:\users\kraft\appdata\local\{27c4a710-7ee3-6661-7aef-265de1ef4275}\U –> FOUND
[ZeroAccess][FOLDER] L : c:\users\kraft\appdata\local\{27c4a710-7ee3-6661-7aef-265de1ef4275}\L –> FOUND
[ZeroAccess][FILE] Desktop.ini : c:\windows\assembly\gac\desktop.ini –> FOUND
[Susp.ASLR][ASLR WIPED-OFF] services.exe : c:\windows\system32\services.exe –> CANNOT FIX
[ZeroAccess][Sig found] services.exe : c:\windows\system32\services.exe –> CANNOT FIX

¤¤¤ Driver: [LOADED] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x822945C3 -> HOOKED (Unknown @ 0x86C5FA20)
SSDT[14] : NtAlertThread @ 0x8220D255 -> HOOKED (Unknown @ 0x86ECD498)
SSDT[18] : NtAllocateVirtualMemory @ 0x822494FB -> HOOKED (Unknown @ 0x86E75A48)
SSDT[21] : NtAlpcConnectPort @ 0x821EB887 -> HOOKED (Unknown @ 0x86C30220)
SSDT[42] : NtAssignProcessToJobObject @ 0x821BEB43 -> HOOKED (Unknown @ 0x8733E110)
SSDT[67] : NtCreateMutant @ 0x82221812 -> HOOKED (Unknown @ 0x86EA3F00)
SSDT[77] : NtCreateSymbolicLinkObject @ 0x821C135A -> HOOKED (Unknown @ 0x86EB1A20)
SSDT[78] : NtCreateThread @ 0x82292BE0 -> HOOKED (Unknown @ 0x86E73898)
SSDT[116] : NtDebugActiveProcess @ 0x82265D22 -> HOOKED (Unknown @ 0x86D8B110)
SSDT[129] : NtDuplicateObject @ 0x821F9551 -> HOOKED (Unknown @ 0x86E75C60)
SSDT[147] : NtFreeVirtualMemory @ 0x82085F1D -> HOOKED (Unknown @ 0x86E754A8)
SSDT[156] : NtImpersonateAnonymousToken @ 0x821BBF12 -> HOOKED (Unknown @ 0x86BDE1D8)
SSDT[158] : NtImpersonateThread @ 0x821D154F -> HOOKED (Unknown @ 0x8721F150)
SSDT[165] : NtLoadDriver @ 0x8216CDEE -> HOOKED (Unknown @ 0x86BE8120)
SSDT[177] : NtMapViewOfSection @ 0x8221189A -> HOOKED (Unknown @ 0x86E74E60)
SSDT[184] : NtOpenEvent @ 0x821FADCF -> HOOKED (Unknown @ 0x86B83150)
SSDT[194] : NtOpenProcess @ 0x82221FAE -> HOOKED (Unknown @ 0x86E75E78)
SSDT[195] : NtOpenProcessToken @ 0x82202A2E -> HOOKED (Unknown @ 0x869CAD58)
SSDT[197] : NtOpenSection @ 0x8221266D -> HOOKED (Unknown @ 0x858CB690)
SSDT[201] : NtOpenThread @ 0x8221D4FF -> HOOKED (Unknown @ 0x86E75D28)
SSDT[210] : NtProtectVirtualMemory @ 0x8221B2E2 -> HOOKED (Unknown @ 0x86EAC670)
SSDT[282] : NtResumeThread @ 0x8221CB4A -> HOOKED (Unknown @ 0x87044168)
SSDT[289] : NtSetContextThread @ 0x8229406F -> HOOKED (Unknown @ 0x872C9168)
SSDT[305] : NtSetInformationProcess @ 0x822158C8 -> HOOKED (Unknown @ 0x86E74C48)
SSDT[317] : NtSetSystemInformation @ 0x821E7EEB -> HOOKED (Unknown @ 0x86B5DC78)
SSDT[330] : NtSuspendProcess @ 0x822944FF -> HOOKED (Unknown @ 0x86F7CD80)
SSDT[331] : NtSuspendThread @ 0x8219B92B -> HOOKED (Unknown @ 0x87310168)
SSDT[334] : NtTerminateProcess @ 0x821F2143 -> HOOKED (Unknown @ 0x869A2418)
SSDT[335] : NtTerminateThread @ 0x8221D534 -> HOOKED (Unknown @ 0x87329168)
SSDT[348] : NtUnmapViewOfSection @ 0x82211B5D -> HOOKED (Unknown @ 0x869C3168)
SSDT[358] : NtWriteVirtualMemory @ 0x8220E92D -> HOOKED (Unknown @ 0x86E75778)
SSDT[382] : NtCreateThreadEx @ 0x8221CFE9 -> HOOKED (Unknown @ 0x86EB1EB0)
S_SSDT[317] : Unknown -> HOOKED (Unknown @ 0x86E45280)
S_SSDT[397] : Unknown -> HOOKED (Unknown @ 0x86FBC248)
S_SSDT[428] : Unknown -> HOOKED (Unknown @ 0x84577768)
S_SSDT[430] : Unknown -> HOOKED (Unknown @ 0x86E451F8)
S_SSDT[442] : Unknown -> HOOKED (Unknown @ 0x86834480)
S_SSDT[479] : Unknown -> HOOKED (Unknown @ 0x86897370)
S_SSDT[497] : Unknown -> HOOKED (Unknown @ 0x868834C0)
S_SSDT[498] : Unknown -> HOOKED (Unknown @ 0x86897440)
S_SSDT[573] : Unknown -> HOOKED (Unknown @ 0x86BCC8B8)
S_SSDT[576] : Unknown -> HOOKED (Unknown @ 0x86CAF1F8)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost
::1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD3200BEVT-26ZCT0 ATA Device +++++
— User —
[MBR] 333f06488c00b1b5c911c5c199899bac
[BSP] a3710cdfc8cf6a4f69c582cbd39cd5ab : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 294788 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 606799872 | Size: 8956 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs made by OTL and aswMBR. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI