ZeroAccess Removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by ewin, Aug 20, 2012.

  1. ewin

    ewin Private E-2

    I have this virus on my HP PC. I have Norton Antivirus 2012 and it says it is preventing it from running anything but it cannot remove the virus.

    After doing a search I stumbled upon a thread here that had someone download and run the Farbar Recovery Scan Tool (frst64). I booted to the recovery console then ran the frst64 program and got a frst.txt log file. I need to know what to do next. So a little help would be very much appreciated.
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Re: ZeroAccess Removal (desktop.ini and services.exe)

    Welcome to MajorGeeks, ewin

    http://img827.imageshack.us/img827/1263/frst.gif Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. ewin

    ewin Private E-2

    Re: ZeroAccess Removal (desktop.ini and services.exe)

    Thanks, for the help. Here is the search.txt file.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    Re: ZeroAccess Removal (desktop.ini and services.exe)

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  5. ewin

    ewin Private E-2

    Re: ZeroAccess Removal (desktop.ini and services.exe)

    Here is the fixlog.txt file.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    The log looks good. How is the computer running at this point? Do you have any other malware related problems?
     
  7. ewin

    ewin Private E-2

    I'm not in front of it ATM but I'll check it when I get home later. I'll know if Norton notifies me of the files when I login again.
     
  8. ewin

    ewin Private E-2

    I had a chance to test my PC last night and wanted to let you know that everything seems to be working fine. I did have to repair Norton but once that was done there were no more issues. Thanks, very much, for your help. You guys are awesome!
     
  9. thisisu

    thisisu Malware Consultant

    You are very welcome :)

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds