![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
I have had a zeroaccess trojan on my computer since yesterday. I first tried nortons own removal tool but that did not work and since then the virus has disabled access to norton 360 completely. As of this morning I haven't had any access to my windows in normal mode, all I see is the wallpaper and the virus has had my task manager disabled from the get go.
I have however been able to run norton npe in safe mode, which found one iteration of the virus but didn't remove it completely. I've also followed your instructions apart from two, that I can think of, exceptions. #1: I couldn't disable my norton 360 because I've no access to it in normal mode and in safemode seems to prevent the running of the program #2: Also I can't uninstall java, I've 6.0 update 26, when I try to uninstall it it says windows installer coulnd't be accessed. I can uninstall other programs The required logs should be all attached RRlogs.txt MGlogs.zip ComboFix.txt SUPERAntiSpyware Scan Log - 03-10-2012 - 09-57-07.log |
| Sponsored links |
|
|
|
#2
|
|||
|
|||
|
|
|
#3
|
||||
|
||||
|
Hi and welcome to Major Geeks, MiuGu!
I want you to read and follow these instructions: TDSSKiller - How to run Please download aswMBR to your desktop.
Please update MBAM.Run another Quick Scan. Attach the latest log. (How to attach) Please download RogueKiller to your desktop.Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator) When it opens, press the Scan button When it is finished, there will be a log on your desktop called: RKreport[1].txt Attach RKreport[1].txt to your next message. (How to attach) |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
MiuGu (03-11-12) | ||
|
#4
|
|||
|
|||
|
Thanks for the quick reply.
Ran all the checks, but the problem still persists. Didn't do anything with the roguekiller check results since you only specified a scan. |
|
#5
|
||||
|
||||
Re-scan with TDSSKiller with the parameters you used before.This time if sptd appears, delete it! Then attach the latest TDSSKiller log. (How to attach) Please download OTL by OldTimer.
|
| The Following User Says Thank You to thisisu For This Useful Post: | ||
MiuGu (03-11-12) | ||
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
Thanks for an other quick reply. Ran both scans, deleted the file and windows booted in normal mode. Taskmanager opens normally. Malwarebytes detected and blocked outbound traffic almost as soon as I started IP-BLOCK 222.64.16.59 (Type: outgoing)
Also removed java |
|
#7
|
||||
|
||||
|
Hi,
Are you having trouble with PS/2 keyboard and mouse? Your logs are clean for the most part as I am not seeing any actual malware to remove. |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
MiuGu (03-11-12) | ||
|
#8
|
|||
|
|||
|
Both my keyboard and mouse are usb and there's no trouble at my end either.
Thanks for all the help ![]() |
|
#9
|
||||
|
||||
|
Quote:
Here are a few things I recommend doing before we cleanup. Please download Disable/Remove Windows Messenger to your desktop.
Now install the current version of Sun Java from: jre-7u3-windows-i586.exeAs far as the PS/2 keyboard and mouse goes, the service and files required for it are missing. This is most likely due to the rootkit. We could restore them if you wanted to (just incase you ever needed to use PS/2 kb/mouse), I leave this decision up to you. __ If you are not having any other malware problems, it is time to do our final steps:
![]() |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
MiuGu (03-11-12) | ||
|
#10
|
|||
|
|||
|
I doubt I'll ever use a PS/2 mouse/kb so installing the drives would be pretty pointless.
I presume using combofix means when you drag&drop a text file on it? Even though I didn't do that do I still have to uninstall combofix? I think that's about it thanks a lot for your help. |
| The Following User Says Thank You to MiuGu For This Useful Post: | ||
iivanita (04-03-12) | ||
| Sponsored links |
|
|
|
#11
|
||||
|
||||
|
Quote:
You're welcome ![]() |
| The Following User Says Thank You to thisisu For This Useful Post: | ||
MiuGu (03-12-12) | ||
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| ZeroAccess Rootkit Infection and Possible Trojans | Mitchle | Malware Removal | 24 | 03-05-12 16:45 |
| Another Rootkit.zeroaccess infection | raritan01 | Malware Removal | 10 | 02-19-12 15:58 |
| Please help, Zeroaccess Rootkit Infection | suntzu83 | Malware Removal | 4 | 12-05-11 01:51 |
| Need help finishing removal of ZeroAccess rootkit infection | NukeMan | Malware Removal | 26 | 11-09-11 12:47 |
| trojan.zeroaccess!inf infection | ThrAsh4u | Malware Removal | 1 | 09-18-11 14:29 |