07-09-2012 06:47 PM
Hello! I started a thread because it was specifically written not to follow the steps to other threads with the same problem.
Please help me with the following:
Norton Security Suite ( the one provided by Comcast) keeps blocking Trojan.ZeroAccess.B, Trojan.Gen and Trojan.Gen.2 every 2-3 minutes. Also, 2-3 windows stating "Host Process for Windows Services has stopped working" keep popping up every minute.
The infected computer is a HP Pavilion a6120n with 32-bit Windows 7 Ultimate (Service Pack 1).
I followed the steps given by Norton (NPE) and I deleted any suspicious files that were modified at the time of infection (only the Prefetch and Temp folders were touched).
Thank you in advance for your help,
NiNi
Solved! Go to Solution.
07-09-2012 11:53 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
07-10-2012 06:39 AM
Thank you for your reply!
I have attached the log.
Here is more information about the current state of the computer:
For about 6 hours, Norton kept blocking unauthorized access by services.exe. After I restarted the computer, it blocked Trojan.ZeroAccess again. Windows Security Center is also off. At some point during the night, Norton could not update itself until I used Live Update 5 times.
Thank you again,
NiNi
07-10-2012 04:35 PM
Zeroaccess plays with Windows and AV software
Step 2
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
07-12-2012 05:28 AM
Hello!
The log is attached.
Sorry for my late reply. I though I had a subscription then checked and saw otherwise. :)
NiNi
07-12-2012 03:48 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
07-13-2012 08:02 AM
Hello!
The log is attached.
NiNi
07-13-2012 10:16 AM
Hello.
I don't mean to double post but, I just want to say that I won't have access to the computer until Monday morning (time of board).
Thanks,
NiNi
07-13-2012 01:48 PM
No Problem,
Leave the system as is with no changes.
Quads
07-15-2012 02:52 PM
