Zeroaccess virus infection at T4R.ORG

rob-be-me

New member
I was navigating this site yesterday and have been infected with the Zeroaccess virus. I retraced my steps and it lead me to these links below. Once I revisted this site I once again got infected. The virus resides at C:Windows\assembly\GAC\Desktop.ini which can only be visable at the command promt via C:Windows\assembly\GAC>dir a/

Our System Administrator is having trouble removing it and a re-image of my hard drive may be our only hope.

Just thought you site Administrators should now.

BTW: DO NOT FOLLOW THESE LINKS YOU WILL GET INFECTED!!!

This link is accessable from the T4R.ORG link below which may hold the virus in question.
http://home.centurytel.net/stevenjackie/transmission flush/tranny .html

http://www.toyota-4runner.org/3rd-gen-t4rs/69744-tutorial-documentation-reference .html
 
Last edited:
Register to hide this ad
If you know where it reside, can you delete it in safe mode? or rename the file while in safe mode, then delete it? If it locks, maybe an updated malwarebytes can get rid of it safely(also while in safe mode)

Or, run a portable bootable windows 7 cd/USB and go to the location of the virus and delete it, should have no problem.
 
If you know where it reside, can you delete it in safe mode? or rename the file while in safe mode, then delete it? If it locks, maybe an updated malwarebytes can get rid of it safely(also while in safe mode)

Or, run a portable bootable windows 7 cd/USB and go to the location of the virus and delete it, should have no problem.

It is possible to delete the virus manually, but it is not at all something someone can do easily. The way these trojans work is they work very much like a real biological virus. They infect your computer, nestle themselves inside your core systems and then start duplicating itself in multiple directories and root locations. Essentially making removal highly improbable. you may delete a majority of the files, but it often needs only a small portion of its original self to replicate and reinfect.

I've had to deal with this particular torjan and a couple others a lot recently, and they are very stubborn to deal with. The only sure way to completely get rid of the virus is to do a full reimage/reformat/install of the HDD. Something that seems to work well if you do have the setting turned on is to roll back the computer to an earlier saved image (system recovery) as this often writes over the current HDD contents, but if you're recovery image is infected then it won't do you any good.
 
If OP knows how to trace browsing history, know atleast how to explore his HDD in windows flatform, which lead him to a suspected infected file location which is C: yada da, I assume he has above average computer knowledge atleast in windows environment. So I suggested running OS in safemode when deleting an infected file so while in that environment, some windows drivers , configsys, and .bat files will not load making the virus somewhat cripple. Also in “safe mode” we have the option to disable network support. Disabling it will favor troubleshooters since malwares are very stubborn when connected online. if it happens that windows will not load because some important system files were deleted like the file he posted above , then recovery CD is always the way to go. Formatting/reinstalling OS is the last option for some people like me because I only have 100GB in my virtual HD, I can not transfer or backup a 150GB of movies music and pictures while im formatting the OS partition and run setup just to get rid of the virus. I can not imagine downloading the service pack again and all updates . But I always believe in clean install though, its like driving a brand new car.
 
The issue isn't tracking down and deleting one file in Safe Mode. Its that you have to find the remaining spots it has nestled in. It can easily become many files, and if you neglect to delete just one, the virus will just sprout back up. They will make subfolders in unassuming files and directories and then lock themselves down to make removal even more difficult. They are nasty little bas****s, particularly the Zeroaccess and one other similar trojan I have had to deal with myself.
 
Mods, please inactivate the links? Not that I even care, MAC=FTW! You know some idiot out there will go "Hmmm, what happens if I poke the pile of poop or touch my finger to the fire?".

If the OP can do all that then why even point that it's on a workspace computer, or did I misread or misinterpret the post.

Throw this topic in the dustbin once we've all had time to say "IBTL"? :boxer:
 
Mods, please inactivate the links? Not that I even care, MAC=FTW! You know some idiot out there will go "Hmmm, what happens if I poke the pile of poop or touch my finger to the fire?".

If the OP can do all that then why even point that it's on a workspace computer, or did I misread or misinterpret the post.

Throw this topic in the dustbin once we've all had time to say "IBTL"? :boxer:

Since Mac is a more popular operating system these days, coders have written a lot of viruses for them.

I used to think Mac's were mostly virus free until I found a key-tracker and some other nasties in my old macbook. :hiding:
 
Last time

i got a virus,i ended up loading anti virus on a USB stick and installing it on the HD b/c the virus wouldn't allow me to install it directly to the HD. Just make sure that whatever anti virus software you choose recognizes the virus youre trying to remove
 
Since Mac is a more popular operating system these days, coders have written a lot of viruses for them.

I used to think Mac's were mostly virus free until I found a key-tracker and some other nasties in my old macbook. :hiding:

OK, you're definitely coming over to our place or I am heading to yours, I wanna see this trick on my old macbook pro. Clean up the old one and you can see the new one as soon as I get it back from having the logic board fixed?
 
Last edited:

Members online

Forum statistics

Threads
278,312
Messages
3,554,089
Members
248,016
Latest member
Advally Service

Trending content

Back
Top