Need help removing ZeroAcess

Discussion in 'Malware Help (A Specialist Will Reply)' started by Intsav, Jun 29, 2012.

  1. Intsav

    Intsav Private E-2

    Hello you wonderful people,

    The past few days my Antivirus, VISS (Verizon internet security suite) has been acting up, refusing to allow real time scanning to be turned on, and also telling me that it could not enable my firewall. I decided to uninstall it, and try a new antivirus after running Malwarebytes and SuperAntiSpyware. MB had detected something called Rootkit.ZeroAccess. I let MBdo it's thing and attempt to remove and quarantine, it seemed successful at first, but after a reboot and another thorough scan, it still turned up. My Windows Firewall was still refusing to turn on, so I tried to do a System Restore back to the safest and farthest date possible I had, sadly the farthest back I had was only to about the 24th of June. While this has fixed Windows Firewall, and has allowed it to turn back on, the Rootkit.ZeroAccess is stil showing up in scans, and a mysterious .exe called im4igtyxv3.exe is showing up in "C:\Users\Savy". This .exe is practically untouchable, I've tried to delete it but I have no permissions to access it at all. It also has a process with the same name running in the background. I fear that as I type this its doing some nasty things to my files, folders, and OS. I just tried to open the Task Manager and it gave me a System Error claiming that it couldn't be opened due to "pcwum.dll" missing.

    I was at my wits end until I found your site, and decided to give your troubleshooting a go. I have gone through the checklist, but to no avail have I been able to find any real solutions besides a link that RougeKiller opened up after it was done scanning. ( http://tigzyrk.blogspot.com/2011/09/rootkit-zeroaccess-max.html being said link).

    If you all could help me rid my computer of this I would be most appreciative. I will try and follow every instruction that you give just as you give it.

    I have attached the files that the "READ & RUN ME FIRST Malware Removal Guide" instructed me to. If I have left anything out, please let me know.

    Thank you in advanced,

    Intsav
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. Intsav

    Intsav Private E-2

    A friend of mine took a look and some action on my computer today, so I' going to run the "READ & RUN ME FIRST Malware Removal Guide" instructions again and attach the subsequent files that it asks once more, as I'm not sure if he managed to remove the virus/malware or not. (Task Manager is once again working, as is Windows Firewall. The .exe that was located under "C:\Users\Savy" he was also able to reclaim and remove, along with killing its process in the task manager after getting that to work again.) So I'm going to run the items again and let them recreate logs to be safe before taking any action of my own. (I don't want to mess anything up).

    I'll post the new logs as soon as I finish the removal guide items again.

    Sorry for this, but my friend had insisted that he could help and possibly remove the virus/malware for me. And I didn't exactly want to turn down the help as I was in a frenzy over this entire situation. (My computer didn't come packaged with a windows 7 installation disk, so I have no way of just doing a clean install. All we had to do was enter the Windows 7 activation code that came with the computer as Windows 7 came pre-installed.)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As long as there is only one of us working on your computer at a time. ;) Let me know whether you need my assistance now still or not. No offence taken if you wish for your friend to help you instead.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds