Author Topic: Help deleting Rootkit.ZeroAccess  (Read 43627 times)

0 Members and 1 Guest are viewing this topic.

Offline CraigB

  • Avast Überevangelist
  • Serious Graphoman
  • *****
  • Posts: 11237
  • No support PM's thanks
Re: Help deleting Rootkit.ZeroAccess
« Reply #30 on: December 23, 2012, 06:47:14 PM »
Quote from:  link=topic=111512.msg877489#msg877489 date=1356284289
Craigb tell your friend Martin that the rules are the same- you don't want this.
Martin " essexboy " is a qualified malware expert and teacher of such, you are not ::)
« Last Edit: December 14, 2021, 11:22:46 AM by Eva137 »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76038
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help deleting Rootkit.ZeroAccess
« Reply #31 on: December 23, 2012, 06:49:47 PM »
Quote from:  link=topic=111512.msg877489#msg877489 date=1356284289
Look below my nickname - im WATCHED

You certainly are.
« Last Edit: December 13, 2021, 03:45:22 PM by Eva137 »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76038
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Help deleting Rootkit.ZeroAccess
« Reply #32 on: December 23, 2012, 07:49:36 PM »
@LaLuz: Sorry for all this useless OT-stuff.

Please see: Reply #16 from essexboy and continue from there.
-> http://forum.avast.com/index.php?msg=877357
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #33 on: December 23, 2012, 09:11:34 PM »
Thank you for all your help Martin, I will only follow your instructions.

I run that program but I could not find the txt file, so I clicked on the report tab and saved one from there on my desktop.  I'm not sure if it is the same, but here it goes.  The system said that 2 threads were detected.

For some reason it's not letting me send the attachment.
« Last Edit: December 23, 2012, 09:13:51 PM by LaLuz »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #34 on: December 23, 2012, 09:17:04 PM »
What threats did it detect..  There should be a zip folder at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip

Could you upload it to mediafire http://www.mediafire.com/ and post the sharing link
Or if you have dropbox then drop it into your public folder and post the sharing link

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #35 on: December 23, 2012, 09:24:47 PM »
I don't have a folder named "Users" on my C drive.  I've just tried sending you a zipped version of that file, but I got a message saying that it was too large.  Do I need to run that program again to get the logs?

I don't know the names of the threats, I didn't write them down because I thought they would be listed on the report :-(
« Last Edit: December 23, 2012, 09:30:20 PM by LaLuz »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #36 on: December 23, 2012, 09:35:28 PM »
The AVP (Virus Removal Tool) folder should be on your desktop, if you go into that and dig down you will find a log folder that contains a zip file..  that is the one I need

Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip

Could you upload it to mediafire http://www.mediafire.com/ and post the sharing link

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #37 on: December 23, 2012, 09:49:04 PM »
do I need to register with Mediafire first?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #38 on: December 23, 2012, 09:50:18 PM »
Unfortunately yes ..  It costs nothing though

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #39 on: December 23, 2012, 09:58:19 PM »
ok, let me do that now.  Are you gonna be around for a while?  I don't know where are you at, but you're 7 hours ahead of me and I'm gonna be out of town for about 5 days.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #40 on: December 23, 2012, 10:00:06 PM »
Time is not a problem, although I have just seen the wine coming out  ;D

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #41 on: December 23, 2012, 10:12:54 PM »
it's telling me that I need to upgrade my browser, should I do it?  I have IE 8

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #42 on: December 23, 2012, 10:15:29 PM »
No it should accept that

LaLuz

  • Guest
Re: Help deleting Rootkit.ZeroAccess
« Reply #43 on: December 23, 2012, 10:29:12 PM »
I'm not sure what to do now, is this the link?
http://www.mediafire.com/view/?onngwrexgccj1ik

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Help deleting Rootkit.ZeroAccess
« Reply #44 on: December 23, 2012, 10:42:29 PM »
Is there any change to the computer ?  If not what are the main problems