News: Cexx forums, with volunteers dedicated to helping you remove malware and stay protected
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
May 18, 2013, 04:11:06
Pages: 1 [2]   Go Down
  Print  
Topic: Security shield  (Read 2399 times)
0 Members and 1 Guest are viewing this topic.
« Reply #15 on: July 08, 2012, 14:59:55 »
Cgolf1 Offline
Jr. Member

**

Karma: 0
Posts: 89



Away on business for a week, sorry I couldn't respond.  I logged on this morning and tried the combofix after being prompted to download the new version.  Seconds after starting it said that access was denied and an administrator (command or password) was needed.  It then tried to find a retore point and hung as usual.  To make matters worse I continued "surfing" afterwards and the "Security Shield" malware popped up again.  I'm writing this under safe mode with networking.  By the way, on your last instruction I didn't understand what you meant about closing the dos window.
Logged
« Reply #16 on: July 08, 2012, 23:15:43 »
dvk01 Offline
Administrator WWW

Karma: 6
Posts: 308



I don't think we can fix this
your best bet is to format & reinstall windows
Logged

« Reply #17 on: July 09, 2012, 19:29:24 »
Cgolf1 Offline
Jr. Member

**

Karma: 0
Posts: 89



I might have further information before you give up.  I scanned with Trend Micro and it found the trojan RKTK_ZACCESS.FP   You said earlier that it was probably this.  Trend can't fix it but says the infected file is Desktop.ini   The folder path is  C:\Windows\assembly\GAC_32\  Does this help at all?
Logged
« Reply #18 on: July 09, 2012, 23:50:50 »
dvk01 Offline
Administrator WWW

Karma: 6
Posts: 308



there will be a lot more than that wrong with this one
when combofix is blocked form running with zero access rootkit, it generally means that so many vital system files have been altered or changed or infected that reinstall is the only viable & safe option
Logged

 
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  

Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Page created in 0.126 seconds with 19 queries.