Author Topic: Malware Win32ZAccess-PB [Trj]  (Read 10109 times)

0 Members and 1 Guest are viewing this topic.

Uthmer

  • Guest
Re: Malware Win32ZAccess-PB [Trj]
« Reply #15 on: July 01, 2013, 09:30:07 PM »
Done. Combofix file attached

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Malware Win32ZAccess-PB [Trj]
« Reply #16 on: July 01, 2013, 10:40:50 PM »
Job done.  8)



It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.



    Please download DelFix by "Xplode" to your Desktop.

    Run the tool and check the following boxes below;
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore

    Now click on "Run" button. Wait for the programme completes his work.
    All the tools we used should be gone.
    Tool will create and open an log report (DelFix.txt)
    Note: The report will also be stored on C:\DelFix.txt


    > I don't need DelFix log report.


    I recommended you to keep Malwarebytes and to use MCShield if you will.
    You may download MCShield from one of the following links:

    MyCity -  Official download link
    Softpedija - Mirror download link

    It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
    And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.

    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #17 on: July 01, 2013, 10:45:08 PM »
    Good job,
    Thanks a lot!  :)

    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #18 on: July 01, 2013, 10:49:45 PM »
    It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
    One quick question according to this, do you think the infection could have been via pendrive? or was the codec pack?
    « Last Edit: July 01, 2013, 10:55:32 PM by Uthmer »

    Offline magna86

    • Anti Malware Fighter
    • Avast Evangelist
    • Massive Poster
    • ***
    • Posts: 4235
      • Ambulanta MyCity Forum - ASAP Member
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #19 on: July 01, 2013, 11:02:47 PM »
    One quick question according to this, do you think the infection could have been via pendrive? or was the codec pack?

    As I can see from logs, ZeroAccess has been load his own malicious loading files into system on 2013/06/30 at 17:38: 58 - 59 according to your computer time.
    What did you do at that moment or a few minutes before that, only you know for shure.



    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #20 on: July 01, 2013, 11:15:36 PM »
    Ok, thanks for your quick response and for your time,
    Ruth

    Offline magna86

    • Anti Malware Fighter
    • Avast Evangelist
    • Massive Poster
    • ***
    • Posts: 4235
      • Ambulanta MyCity Forum - ASAP Member
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #21 on: July 01, 2013, 11:19:41 PM »
    Ok, thanks for your quick response and for your time,
    Ruth

    You owe me a beer.    ;D


    Cheers

    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #22 on: July 01, 2013, 11:25:27 PM »
    I owe you a barrel!! but it will have to be when I move to London  ;D

    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #23 on: July 02, 2013, 08:15:26 PM »
    Hi Magna86, sorry to bother you again, but when I try to uninstall Combofix, Windows shows an alert "Windows can not find this file",
    is that fine? should I run Delfix anyway?

    Offline magna86

    • Anti Malware Fighter
    • Avast Evangelist
    • Massive Poster
    • ***
    • Posts: 4235
      • Ambulanta MyCity Forum - ASAP Member
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #24 on: July 02, 2013, 09:42:36 PM »
    Hi Magna86, sorry to bother you again, but when I try to uninstall Combofix, Windows shows an alert "Windows can not find this file",
    is that fine? should I run Delfix anyway?

    You have been deleted Combofix.exe, that's why it's show you this: "Windows can not find this file"

    Run DelFix anyway, it will remove CF and all it's related files.  ;)

    Uthmer

    • Guest
    Re: Malware Win32ZAccess-PB [Trj]
    « Reply #25 on: July 02, 2013, 10:10:12 PM »
    Done. These tools are delicate and wanted to make sure...
    Thank you!!  :D