Jump to content


Photo

win32.rootkit.Zaccess


  • This topic is locked This topic is locked
2 replies to this topic

#1 jmikesheehan

jmikesheehan

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 11 August 2011 - 11:25 PM

I've been battling this infestation for several days. The last virus scan indicated win32.rootkit.Zaccess.

I deleted dlactrlw.exe , isuspm.exe, issch.exe, stsystra.exe as directed on several antivirus web sites. I also deleted those entries in the registry manually. The next reboot I was unable to connect to the internet The error I'm getting is RPC server is unavailable.

from command prompt ipcofig/release then ipconfig/renew RPC server is unavailable
then I tried ipconfig/flushdns succesfull flushe DNS resolver cache. ipconf/renew RPC server is unavailable.

At the end of the day I ran a virus scan and 4 new trojans were discovered. Today I have disabled the network cards.

I am unable to get the machine clean, I've run antivirus apps from bleepingcomputer.com, PC Tools, PC Fixer and Ad Aware the machine gets a little better and then degrades over the day.

Issues;
RCP Server unavailable
USB devices stop working, reboot, scan, delete malware and they work again for several hours.
USB external drive will no longer spin up on any computers - yes that is my only backup

I need some serious intervention here I have attached a GMER log file for smart folks to review so I can get back to work.

Attached Files



#2 Blade81

Blade81

    Advanced Member

  • Volunteer Security Advisor
  • PipPipPip
  • 6557 posts

Posted 12 August 2011 - 05:22 AM

Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds file to run the tool.
  • When done, DDS will open two (2) logs:
    • DDS.txt
    • Attach.txt
  • Save both reports to your desktop. Post them back to your topic.

Microsoft MVP Consumer Security 2008 2009 2010 2011 2012

ASAP & UNITE member since 2006

I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.

Provided removal instructions are meant to be used in the correspondent user's case only.

Please use "Reply to this topic" -button while replying.

#3 Blade81

Blade81

    Advanced Member

  • Volunteer Security Advisor
  • PipPipPip
  • 6557 posts

Posted 14 September 2011 - 02:16 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Thank You !
Microsoft MVP Consumer Security 2008 2009 2010 2011 2012

ASAP & UNITE member since 2006

I don't help with logs thru PM so don't bother to post me one. If you have problems create a thread in the forum, please.
Don't post your log into other user's topic, create a new one.

Provided removal instructions are meant to be used in the correspondent user's case only.

Please use "Reply to this topic" -button while replying.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users