Reply
Contributor
Mattger
Posts: 13
Registered: ‎08-12-2012

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Hi Quads,

 

Looks like the combofix didn't stall. It produced a log and a text file, both which i have attached below.

 

The above comments were posted since i thought it was taking too long. The program said it would take 10 minutes or maybe double that if it ws badly infected. Didn't expect it to take 20hrs to complete.

 

Thanks,

Matthew

 

 

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

step 4. (a)

 

Please read carefully and Slowly

 

You might have to export the results

 

 Please scan with ESET next 


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
Mattger
Posts: 13
Registered: ‎08-12-2012

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Hi Quads,

 

I ran the online scanner and attached the log.

 

Somethings i noticed during the scan:

About 2 minutes into the scan, Norton came up with a pop-up on the bottom right hand corner

Trojan.zeroaccess.C was detected by autoprotect and quarrantined.

 

Thanks,

Matthew

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Norto should have probably detected dead files that are inside the quarantine folders for the programs I have used.

 

Step 4. (b)

 

Disable Norton for say 30 minutes

 

 

Download OTL http://www.bleepingcomputer.com/download/otl/

 

Start OTL,  

Click the Scan All Users checkbox.

Change file age to 60 days

 

Press the 

 

 

An OTL.txt  and extras.txt will be created.

 

Quads

Contributor
Mattger
Posts: 13
Registered: ‎08-12-2012

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Hi Quads,

 

I ran the scan and attached the two files below

 

During the scan, no warnings from norton popped up.

 

Thanks,

Matthew

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Uninstall

 

Ask Toolbar
"AVG Secure Search" = AVG Security Toolbar
"ESET Online Scanner" = ESET Online Scanner v3

 

I have to script for the rest

 

Interesting how the uninstall list shows both NIS and N360 installs.

 

Quads

Contributor
Mattger
Posts: 13
Registered: ‎08-12-2012

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Hi Quads,

 

I have uninstalled those 3 programs.

 

I'll wait for you to script.

 

Thanks,

Matthew

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Disable Norton for say 30 minutes

 

Start OTL,   under   Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom)  and run the script. (Red Run Fix Button)

 

The output log, should be placed in the C:\ _OTL folder after.

 

Quads

Contributor
Mattger
Posts: 13
Registered: ‎08-12-2012

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

Hi Quads,

 

I ran the script as specified

 

The log is produced below.

 

Thanks,

Matthew

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Norton is dectecting and blocking Trojan.Gen.2 Trojan.zeroaccess.b ALSO wmsan.dll

How is your system running now??

 

Quads