Could be Zero Access Rootkit... Please Help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bom123, Jan 2, 2012.

  1. bom123

    bom123 Private E-2

    Hi There!

    ComboFix log shows that my computer is infected with Rootkit.Zeroaccess. I tried diffrent things but not lucky. I have access to internet but its very slow and sometime even page does not load and have to refresh it again.

    Any help would be appreciated. I have attached log files for references. Let me know if you need anything else.

    TIA
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Whose instructions have you been following???

    Apparently you are not following our cleaning procedures because
    1. You did not attach a log from SUPERAntiSpyware
    2. You did not attach a log from Malwarebytes
    3. And you delete registry entries and files with TDSSkiller that are required for your PC. The below should not have been touched. You will have to reinstall your SAMSUNG USB Driver for Mobile Phones software
    When did your problems begin?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what I'm seeing in your logs Zero Access is the least of your problems. It appears that you have a Virut infection, or Ramnit infection or another similar PE file infector. I have to post the below notice which is a generic post for Ramnit but the same statements apply for Virut


    Even your installed McAfee program is no longer trust worthy since there is a very high probability it is infected too and scanning with it will just spread the infection more.
     
  4. bom123

    bom123 Private E-2

    So what you sugget? Also, I deleted those files before visiting your site. Now I have reinstalled Samsung mobile driver and also can provide Malwarebytes log. Let me know and thanks for your help.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually due to the stability issues that the effects of this kind of infection typically cause, I would actually recommend that you reinstall and be extremely careful what files you backup from this infected PC. Any executable file may be infected and if you put just one of them back on to a clean system and run it, you will start the whole cycle all over again. In addition, if you have plugged flashdrives into this PC and those flashdrives have any kind of executable on them, they may also be infected. And even worse, any PC you plugged those flash drives into may also be infected. Hence you see the potential problems this type of infection may cause.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds