ZeroAccess Trojan FRST file attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by ryanb4614, Jul 24, 2012.

  1. ryanb4614

    ryanb4614 Private E-2

    Hello. I have Macfee Virus protection but it will not remove this trojan that keeps coming up during the scans.

    C:\Windows\assembly\GAC_64\Desktop.ini
    ZeroAccess

    C:\Windows\assembly\GAC_32\Desktop.ini
    ZeroAccess

    As instructed I have the FRST.txt file attached.

    I work with online store upload multiple php, xml, css files via ftp would this type of trojan infect these files?
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Welcome to MajorGeeks, ryanb4614 :)

    No

    __

    http://img827.imageshack.us/img827/1263/frst.gif Boot to System Recovery Options and run FRST again.
    Type the below bolded text in the edit box after "Search:".

    services.exe

    Then click the Search button.

    It will make a log (Search.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. ryanb4614

    ryanb4614 Private E-2

    Thank you for the reply please see attachment. I hope get this resolved asap.
     

    Attached Files:

  4. thisisu

    thisisu Malware Consultant

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally.
     

    Attached Files:

  5. ryanb4614

    ryanb4614 Private E-2

    Hello. Please see attachment as requested.
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    Looks fine.
    Delete the C:\FRST folder and let me know what issues remain.
     
  7. ryanb4614

    ryanb4614 Private E-2

    When I try to delete C:/FRST I get

    You need permission to perform this action
    You require permission from SYSTEM to make changes to this folder
     
  8. ryanb4614

    ryanb4614 Private E-2

    Got it with running CMD as administrator and then rmdir c:\FRST /s
     
  9. thisisu

    thisisu Malware Consultant


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds