BleepingComputer.com: ZeroAccess rootkit?

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 8 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

ZeroAccess rootkit? IP address 169, NT Authority/System Shutdown

#31 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 06 December 2011 - 10:27 PM

I did the reset.bat as you said.

Then I clicked to see if I could access the internet.

It looks like I don't have a 169 IP anymore. But I get the message "Internet Explorer cannot display the webpage."

Then I tried again and got the following message in a gray box:
To help protect your computer, windows has closed this program. Services and Conroller App.
Data Execution Prevention

I tried again and got this message in a gray box:
Services and Controller app encountered a problem and needed to close.
Please tell Microsoft about this problem. Send error report. Don't Send.
To see what data this report contains, click here.


Thanks for being so patient with all this.

#32 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 08:37 AM

Hello


I want you to go here and download SP3 and install it http://www.microsoft.com/download/en/details.aspx?id=24



gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#33 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 07 December 2011 - 10:10 AM

OK, thanks.

#34 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 10:21 AM

:thumbup2:
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#35 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 07 December 2011 - 10:25 AM

I just went to the page and it says:
"This installation package is intended for IT professionals and developers downloading and installing on multiple computers on a network. If you're updating just one computer, please visit Windows Update at http://update.microsoft.com."

Is it still ok to use?

Also, I will be downloading from a computer with Vista and putting it on the sick computer which is XP. I know someimes that matters but wasn't sure if this was one of those times. (I hope not.)

Thanks again.

#36 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 10:31 AM

yes it is ok I use it all the time


gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#37 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 07 December 2011 - 10:34 AM

You are the professional! Me? Well, not in the least...

Thanks. I'll do it now.

#38 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 10:34 AM

:thumbup2:
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#39 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 07 December 2011 - 10:51 AM

I have three USBs and the file is too big for each of them. The file is 316MB. Is there a way I can download a specfic file insead? I'll keep looking around to see if I can find another USB.

#40 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 11:00 AM

hello


you need to do it all at once - if need be check with a friend


gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#41 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 07 December 2011 - 11:02 AM

Good idea. I'll check back in with you later after I ask around.

Thanks.

#42 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 07 December 2011 - 11:07 AM

see you then


gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#43 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 08 December 2011 - 12:31 PM

Still searching...

Thanks again for your patience.

#44 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,549
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 08 December 2011 - 12:41 PM

Ok don't worry I will be around


gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#45 User is offline   sally23 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 76
  • Joined: 25-November 11

Posted 08 December 2011 - 02:59 PM

Good news, I found a USB from a friend that will hold the files! (I think he uses Windows 7)

I had a question though. I put the USB on my Vista computer and the USB was fine. I transferred the files onto the USB.

Then I put the USB in my XP computer. Before I could download the files, I got the following message:

USB Mass Storage Device has no passed the Windows Logo tesing to verfiy its compaibility with Windows XP. Continuing your insallation of this sofware may impair or destable the correct operation of your system either immediaely or in he future. Microsoft strongly recommends that you stop this installation now and contact the hardware vendor for software that has passed windows logo testing.

There was a problem installing this hardware: transmemory
An error occured during the insallaion of this device. The driver cannot be installed because it either is not digitally signed or not signed in he appropriate manner.

What do you think?

Share this topic:


  • 8 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users