![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
||||
|
||||
|
I have the Rootkit Zeroaccess, Combofix found it. Ive tried several removers (Avast Rootkit remover, TDSSKiller, Unhackme) that worked in the past but its not detecting it this time...ive also ran Ccleaner, Superantispyware, Malwarebytes, Spybot, AVG, ComboFix, Avenger, Regseeker and a few others....any help would be great, thx in advance..
|
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
|
|
#3
|
||||
|
||||
|
All is done, altho the RootRepeal freezes my computer everytime i run it. Thx again for your time.
|
|
#4
|
||||
|
||||
Fixing items using ComboFixMake sure that ComboFix.exe that you downloaded while doing the READ & RUN ME is on your desktop -- but do not run it. If it is not on your desktop, the below will not work. Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts. Open Notepad and copy/paste the text in the below code box into Notepad: Code:
KillAll::
ClearJavaCache::
DirLook::
C:\Documents and Settings\Administrator\Application Data\Awig
C:\Documents and Settings\Administrator\Application Data\Diawu
C:\Documents and Settings\Administrator\My Documents\Aspy
c:\documents and settings\Administrator\Local Settings\Application Data\Aspyr
C:\Program Files\Aspyr
Driver::
sptd
McciCMService
File::
C:\WINDOWS\DUMP1770.tmp
C:\WINDOWS\DUMP5c39.tmp
c:\windows\system32\drivers\sptd.sys
Folder::
C:\WINDOWS\$NtUninstallKB23923$
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\0MROXZB1
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\CHYDCNHN
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\L6F6EV3M
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\STZZA5TS
C:\$AVG8.VAULT$
Registry::
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
SecCenter::
AV: AVG Anti-Virus *Disabled/Outdated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
Now use your mouse to drag CFScript.txt on top of ComboFix.exe and then release. ![]() This will launch ComboFix. Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. Allow ComboFix to update itself if prompted. When ComboFix finishes, a log will be produced at C:\ComboFix.txt Attach this log to your next message. (How to attach) I want you to read and follow these instructions: TDSSKiller - How to runThis updates all of the logs inside MGlogs.zip. When it is finished, attach C:\MGlogs.zip to your next message. (How to attach) Let me know what problems remain, if any, after you have completed these steps. |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
Clinetyme (04-18-12) | ||
|
#5
|
||||
|
||||
|
After doing what u ask, Combofix no longer detects the Rootkit....here are the logs...
|
| Sponsored links |
|
|
|
#6
|
||||
|
||||
|
That's good
Your latest logs are clean.You can delete these two empty folders:
__ If you are not having any other malware problems, it is time to do our final steps:
![]() |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
Clinetyme (04-18-12) | ||
|
#7
|
||||
|
||||
|
Everything is back to normal, thx again for your time.
![]() |
|
#8
|
||||
|
||||
|
No problem
![]() |
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ZeroAccess Rootkit | ComputerHack | Malware Removal | 8 | 03-13-12 22:52 |
| rootkit zeroaccess | kevinpetursson | Malware Removal | 2 | 02-18-12 20:12 |
| Rootkit.zeroaccess | mpetro1 | Malware Removal | 12 | 12-29-11 16:04 |
| ZeroAccess Rootkit | zq1 | Malware Removal | 6 | 12-06-11 22:39 |
| HELP please - Rootkit.Zeroaccess | argentia | Malware Removal | 15 | 10-02-11 00:19 |