|
#1
|
|||
|
|||
|
Have any of you had luck in removing the 0Access virus from PCs without reformatting? This has got to be one of the most difficult viruses I have come accross.
Just thought I'd ask what you guys have come accross when dealing with this rootkit. Thanks |
|
#2
|
|||
|
|||
|
My last experience was to reinstall Vista x86 and run getdataback on the clone of the original drive. Managed to rebuild most of the file system (mainly photos, & docs) but many files and folders were trashed. The MBR and system files was the worst affected. It was a challenge to get the good stuff off as windows could not access the drive. Repair was out of the question and no restore points were available. Wasted a lot of time chasing ghosts. Tons of fun.
|
|
#3
|
|||
|
|||
|
go to foolishit.com and on the d7 page click on pics and vids then at the bottom go to malware vids. He gives you the tools and a video on removing it
|
|
#4
|
|||
|
|||
|
The download link for Foolish IT's ZeroAccess removal tool didn't work for me. Here's a video from Britec that shows how to manually remove ZeroAccess.
http://www.youtube.com/watch?v=F7KlPBv0yp8 |
|
#5
|
||||
|
||||
|
|
|
#6
|
||||
|
||||
|
Quote:
There's a variant not long ago out there that hooks system drivers that's very difficult to remove, but it doesn't work on 64bit OSes... The latest variant that does infect 64bit OSes however is a "user mode" variant and no longer technically a 'rootkit', so it is surprisingly easy to remove IF you know where to look; I wrote a tool to do just that in a few minutes. Attached... of course this automatic detection/removal is also part of D7 v6.4 and again, it ONLY works for the latest and greatest user mode variant of ZeroAccess.
__________________
Author of d7, and TONS of other FREE PC technician's tools. www.FoolishIT.com Checkout my videos on d7: An introduction to v6.6.x and Configuration Overview Also check out My Network Boot Setup details, and the comment thread. Boot diag CDs over the network / deploy Windows installs with updates, drivers, and pre-installed apps in minutes! Last edited by FoolishTech; 06-09-2012 at 03:33 PM. |
|
#7
|
||||
|
||||
|
Quote:
__________________
put that in your pipe and grep it |
|
#8
|
|||
|
|||
|
That is exactly what it did, trashed the recovery partition. Sorry I didn't mention that the first time. I did slave the drive but never could get my bench machine's windows to recognize/load the drive. It would assign a letter to the drive, but show no content and gave no access. This was a seriously "mucked up" drive.
|
![]() |
| Tags |
| format tutorial coming? |
| Thread Tools | |
| Display Modes | |
|
|