Solved Many backdoors/various Trojans/rootkit. Shutdowner present

For those lurking, or anyone who is interested in the details about Sirefef/ZeroAccess: http://www.kindsight.net/sites/default/files/Kindsight_Malware_Analysis-ZeroAcess-Botnet-final.pdf
http://www.2-viruses.com/remove-zeroaccess-rootkit

I believe that I had the older variant of Sirefef-- .Y, .W, .B
There are new variants out by now-- .AG, .I, .P (which I believe is also called the CLSID variant) Major shift in strategy for ZeroAccess rootkit malware, as it shifts to user-mode | Naked Security

Since I'm really interested in hacking and viruses, I'm actually having some fun trying to fight it. I'm not ready to reinstall Windows just yet. It's important that I learn what this is and what it does. I want to do everything I can before I wipe the whole thing. It's a learning process. Some of my most important files are already backed up here on my laptop, such as novels I'm writing.

I also hope the information will aid others in learning about the virus. I'll keep reporting back here with updates on how far I've gotten. Right now, I have to focus on fixing Services.exe. ESET has a ServicesRepair tool that I'm going to see if I can quickly use in safe mode before the system shuts down. If not that, then I'm going to try to get my AHCI drivers onto a flash drive so that I can access my OS when repairing my computer so I can do an SFC scannow.

I'm not giving up just yet.

This is a guide I was going to follow: http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
Here's a video about it as well, and from what I can see, the virus can impact a system far worse than how it hit mine. I can at least boot into Windows. http://www.youtube.com/watch?v=xVtGvtlDPwo&feature=related

(This reminds me a lot of the Conficker scare back in, I think 2010?)
 
Last edited:

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
I'm reading the .pdf and actually I'm scared of its contents...
 

My Computer My Computer

At a glance

Microsoft Windows 10 Professional / Windows 7...Intel i5-357016GB DDR3AMD Radeon HD 7850 2GB
Computer type
PC/Desktop
OS
Microsoft Windows 10 Professional / Windows 7 Professional
CPU
Intel i5-3570
Motherboard
Lenovo Mahobay
Memory
16GB DDR3
Graphics Card(s)
AMD Radeon HD 7850 2GB
Sound Card
(1) Realtek HD Audio (2) AMD HD Audio
Monitor(s) Displays
LG LS192WS
Screen Resolution
1440 x 900 @ 32bit color
Hard Drives
(1) SUV300S37A/120G (2) ST3500413AS SATA Disk Device AHCI mode enabled.
PSU
Corsair HX620
Case
Thermaltake V4 Black Edition
Cooling
Cooler Master Hyper 212 + Artic Silver 5 on CPU/GPU
Keyboard
Dell SK-8115
Mouse
Razer Copperhead with MAPED mat (awesome!)
Internet Speed
100 Mbps up/down
Browser
Chrome

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Since I'm really interested in hacking and viruses, I'm actually having some fun trying to fight it. I'm not ready to reinstall Windows just yet. It's important that I learn what this is and what it does.

Why? It's like killing roaches. They won't go away. Whatever you learn about virii and Win internals will be useless soon enough, as that all changes quickly.
This is assuming you're not planning on doing this as a "profession."
I suggest you keep a clean house with a recommended anti-virus. A free one.
Paying for an anti-virus just supports the "virus "industry."
Maybe even more important, take image copies. Then the roaches are inconsequential. If I even suspect roaches, I just replace the house with a clean one. 5 minutes.
I get where you're coming from, and used to have "fun" squashing roaches.
After a while it became distasteful - like, do roaches deserve much of my attention?
Nope.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64QuadCore Intel Core i7 920, 2666 MHz (20 x 133)6134 MB (DDR3-1333 DDR3 SDRAM)(2 - SLI) NVIDIA GeForce GTS 250 (1024 MB)
Computer Manufacturer/Model Number
Home Built
OS
Windows 7 Ultimate x64
CPU
QuadCore Intel Core i7 920, 2666 MHz (20 x 133)
Motherboard
Asus P6T
Memory
6134 MB (DDR3-1333 DDR3 SDRAM)
Graphics Card(s)
(2 - SLI) NVIDIA GeForce GTS 250 (1024 MB)
Sound Card
Onboard Realtek ALC888/1200 @ Intel 82801JB IC
Monitor(s) Displays
HDMII
Screen Resolution
1280 x 800
Hard Drives
Crucial M4 (64 GB SSD)
WD Caviar Blacks
WD5001AALS-00J7B1 ATA Device (465 GB)
WD5001AALS-00J7B1 ATA Device (465 GB)
WD5001AALS-00L3B2 ATA Device (465 GB)
WD Elements USB External (250 GB)
PSU
Corsair 550
Case
iStarUSA S-10000BL Black
Thank you for the links. The first step in fighting something, is knowing it's behavioral patterns.
 

My Computer My Computer

At a glance

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1,...Intel Core 2 Duo 2.93GHzNot much with my ADHDATI Radeon HD 4350
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Here's a current update:
I made a Hiren's BootCD and I'm using it to back up a lot of data just in case I can't get all of the malware off, but so far I've found a lot of it and removed it.

I've located the trojan lurking in my Windows/Installer folder as well as in the AppData/Local folder and removed it.

I've deleted various adware/spyware and tracking cookies.

I've run a checkdisk using the BootCD, and I'm still going to do a scannow when I'm done copying everything.

If you're in a similar situation and either can't boot into Windows, or Windows keeps kicking you out, I would highly recommend the Hiren's BootCD. It's got most tools you need to recover data and remove stuff without having to get into Windows first. You can also use it to edit the registry.

Download Hiren

Why? It's like killing roaches. They won't go away. Whatever you learn about virii and Win internals will be useless soon enough, as that all changes quickly.
This is assuming you're not planning on doing this as a "profession."
I suggest you keep a clean house with a recommended anti-virus. A free one.
Paying for an anti-virus just supports the "virus "industry."
Maybe even more important, take image copies. Then the roaches are inconsequential. If I even suspect roaches, I just replace the house with a clean one. 5 minutes.
I get where you're coming from, and used to have "fun" squashing roaches.
After a while it became distasteful - like, do roaches deserve much of my attention?
Nope.

I like to learn, I like to work on the computer, and I like to develop new skills. I don't consider that at all a bad thing.

This is also the first time in maybe eight years that I've had a virus.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Another new update:
I've successfully repaired the Windows files that were causing my machine to randomly restart by doing an SFC /SCANNOW at boot from the Windows 7 installation CD. It found corrupted files and fixed them. My machine no longer shuts down.

I'm now able to get into Safe Mode and run Malwarebytes, TDSS killer, and others.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Final update: I installed Comodo Internet Security (Free Internet Security, Download Internet Security Software Suite - Comodo) and ran a scan, and I also uninstalled and reinstalled Malwarebytes and scanned with that.

Comodo: Found 0 Malicious objects.
Malwarebytes: Found 0 malicious objects.
Used Comodo System Utilities (Comodo System Utilities Tools - Disk Registry Cleaner Software | Comodo) to clean up some remnants in the registry.

Computer is running smoother and cleaner, and I now have a fully working antivirus program, and it's free!

I'm also blocking a lot of bad IP addresses.

I didn't have to reinstall Windows 7, and everything is back to normal. I'm glad I decided to try to remove it instead of reinstall. Reinstalling would have been an even bigger hassle. I have a LOT of data on this drive.

I hope this forum is helpful to people in the future.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
there is one final thing, which i don't like myself, but that would be to use another computer to make a bootable ubuntu USB drive
and then put that into your pc change the BIOS to boot USB first, and then run ubuntu, NOT INSTALL, and download CLAMAV ANTIVIRUS and scan your other OS, that could fix it, saved me once before.

whichever way you choose, it sounds like a bad virus so i hope it goes well for you!
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64, Windows 8.1 Pro x64 (...AMD - A6-3670 Accelerated Processing unit W/R...8.00GBAMD Radeon HD 6530D (APU)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Desktop - Zoostorm, Laptop - HP
OS
Windows 7 Ultimate x64, Windows 8.1 Pro x64 (on laptop)
CPU
AMD - A6-3670 Accelerated Processing unit W/Radeon HD6530D
Motherboard
MSI
Memory
8.00GB
Graphics Card(s)
AMD Radeon HD 6530D (APU)
Sound Card
Realtek HD
Monitor(s) Displays
single/one
Screen Resolution
1440x900
Hard Drives
1x2tb internal
1x1tb external
PSU
300W
Case
Zoostorm
Cooling
1 rear fan (12cm) 1 GPU cooler fan(8CM) 2 side fans (12cm)
Keyboard
Saitek C.Y.B.O.R.G V5
Mouse
Saitek R.A.T V3
Internet Speed
Download - 17-20 mbps. Upload - 07-1.3 mbps
Antivirus
Eset Smart Security 7.0.302.26
Browser
Google chrome, IE11, Firefox
Other Info
The laptop is a HP Pavillion G6 (AMD A10 APU @ 2.3 (turbo to 3.2) ghz)
never mind! glad you fixed :D but i would make sure that you use a high quality anti virus..ESET is what im comfortable with.
 

My Computer My Computer

At a glance

Windows 7 Ultimate x64, Windows 8.1 Pro x64 (...AMD - A6-3670 Accelerated Processing unit W/R...8.00GBAMD Radeon HD 6530D (APU)
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Desktop - Zoostorm, Laptop - HP
OS
Windows 7 Ultimate x64, Windows 8.1 Pro x64 (on laptop)
CPU
AMD - A6-3670 Accelerated Processing unit W/Radeon HD6530D
Motherboard
MSI
Memory
8.00GB
Graphics Card(s)
AMD Radeon HD 6530D (APU)
Sound Card
Realtek HD
Monitor(s) Displays
single/one
Screen Resolution
1440x900
Hard Drives
1x2tb internal
1x1tb external
PSU
300W
Case
Zoostorm
Cooling
1 rear fan (12cm) 1 GPU cooler fan(8CM) 2 side fans (12cm)
Keyboard
Saitek C.Y.B.O.R.G V5
Mouse
Saitek R.A.T V3
Internet Speed
Download - 17-20 mbps. Upload - 07-1.3 mbps
Antivirus
Eset Smart Security 7.0.302.26
Browser
Google chrome, IE11, Firefox
Other Info
The laptop is a HP Pavillion G6 (AMD A10 APU @ 2.3 (turbo to 3.2) ghz)
So far Comodo seems really awesome. It has a sandbox which makes a "fake" Windows and copies the malicious things there to find out what they are. It also has a firewall with it.

It tells you what's coming in, what it's doing, where it's going, and what it might be capable of. It's really impressive for freeware!

Also from what I've heard, they update their definitions every day.
 

My Computer My Computer

At a glance

Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
OS
Windows 7 64-Bit Home Premium Service Pack 1
CPU
AMD Phenom II Black x4
Motherboard
Asus M4A89TD Pro USB3
Memory
G. Skill Ripjaws Gaming series DDR3 2 x2GB
Graphics Card(s)
Sapphire ATI Radeon HD 5770 PCIe
Hard Drives
Western Digital Caviar Blue 500gb SATA 6.0
PSU
Corsair HX 650w
Case
Cooler Master CM690 II Advanced
Back
Top