rootkit.ZeroAccess! removal, FRST log attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Gorbiani, Aug 13, 2012.

  1. Gorbiani

    Gorbiani Private E-2

    Recently I started getting a popup from McAffee stating that it has detected and quarantined the trojan rootkit.ZeroAccess!

    I restart the computer and the same thing occurs, same message and all. The strange thing is that my audio will not function (claiming it is missing a driver), will not connect to wifi, and will not recognize USB devices (all new issues as of today). I ran a FRST scan and attached the scan results.

    Thank you for your time and hopefully we can get this resolved.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks Gorbiani :)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  3. Gorbiani

    Gorbiani Private E-2

    Ran the FRST and will post the fixlog
     
    Last edited: Aug 14, 2012
  4. Gorbiani

    Gorbiani Private E-2

    Ok, here's the fixlog.txt
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    Hello

    This log looks good.
    If you are still experiencing problems, it is recommended that you go through this thread: READ & RUN ME FIRST Malware Removal Guide
    You can attach your logs here when finished.
     
  6. Gorbiani

    Gorbiani Private E-2

    Ok, things have gone absolutely crazy since I last tried to boot normally. Not only are all the problems I have encountered before running FRST still present, but there are more problems. Upon booting normally, I was greeted by a "this copy of windows is not genuine" message. I took a look under device manager and the list was not populated at all. This is probably linked to the fact that my USB, audio, and wireless connection are not working at all.

    Could this be the damage left behind by the rootkit? I'm almost ready to just insert a new harddrive, install windows, use the one in my computer as an external storage device, take everything off of it that is important, and then wipe it and start over. I'd like to avoid it, but things are so messed up that I'm tempted to.
     
  7. thisisu

    thisisu Malware Consultant

    Yes it could be damaged by the rootkit. I will leave the decision up to you. If you want further assistance you will need to go through the Read and Run Me First thread I previously recommended to you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds