Jump to content


  • Content Count

  • Joined

  • Last visited

Everything posted by Zeroaccesstrojan

  1. SystemLook 30.07.11 by jpshortstuff Log created at 10:45 on 02/12/2019 by SYSTEM Administrator - Elevation successful WARNING: SystemLook running under WOW64. Use SystemLook_x64 for accurate results. ========== filefind ========== Searching for "Atapi.sys" C:\Windows\erdnt\cache64\atapi.sys --a---- 24128 bytes [01:41 28/11/2019] [01:52 14/07/2009] 02062C0B390B7729EDC9E69C680A6F3C C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys --a---- 24128 bytes [23:19 13/07/2009] [01:52 14/07/2009] 02062C0B390B7729EDC9E69
  2. i just need a fixlist similar to this. https://forums.malwarebytes.com/topic/128689-windows-7-zero-access-rootkit/page/2/ please see the original OTL log, i have remnants of zero access. ========== ZeroAccess Check ========== [2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsi
  3. here are the two requested logs FRST.TXT and Addition.txt logs FRST.txt Addition.txt
  4. i will post the OTL scan firstly since it clearly states zero access in the log OTL.Txt
  5. Hello malwarebytes members this is my very first post on this board, what an amazing grace so far been reading this forum for a few years now and finally pulled the trigger, i have a zero access trojan which persists on every workstation it seems im able to remove a portion of it manually... about 95 % of virus scanners fail to even detect it... this seems to be a mix of zero access alueron and zeus combined is the best way i can explain it. so far only otl and farbar have been fairly accurate in detecting the trojan. i will post 2 logs, farbar and otl, if someone c
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.