08-08-2012 04:22 PM
Good Day,
Seeking help to remove Trojan.Gen.2 and Trojan.Zeroaccess.B. Norton 360 raises alerts that these have been blocked repeatedly.
Running Windows Vista Home Premium 64 bit on a Dell Studio laptop.
And yes - have a flash drive.
Thanks in advance for the assistance.
Cheers!
Joe
08-08-2012 09:28 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
08-09-2012 08:59 AM
Hi Quads,
Thank you for the quick response!!!!
Attached is the requested file.
Thanks!
Joe
08-10-2012 07:43 PM
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
08-11-2012 05:12 AM
Hi Quads,
Ran the fix and attached the log.
Thanks!
Joe
08-11-2012 09:24 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
08-12-2012 09:55 AM
Happy Sunday!
Ran combofix, appeared to hang while fixing the problem with services.exe - not sure I was able to properly "turn off" norton 360, so I uninstalled norton 360 for the time being.
Re-ran combofix and attached the log.
Thanks!
Joe
08-12-2012 05:27 PM
You are on your own, you have gone against instruction and done your own thing.
Good Luck
Quads
08-12-2012 08:16 PM
Hi Quads,
FWIW - I disabled Norton 360 every way that I knew how (unchecked everything and disabled every feature that I could find for the 5 hours option). ComboFix noted that Norton 360 was still running, when I attempted to 'x' out of the second ComboFix warning window that Norton was still running and would most likely interfer with ComboFix, the program started the scan. I let it run and ComboFix got to the point where it was attempting to fix services.exe the first time and paused for 5+ hours. Don't know if the screen saver or some part of Norton interfered with ComboFix or if ComboFix would have completed given additional time. I do know that once Norton was no longer installed and the screen saver disabled, ComboFix completed in under 1 hour.
Appreciated the help up until now!
Good Luck to you as well!
Cheers!
Joe
08-12-2012 08:22 PM
Please do not run any tools unless instructed to do so.
User "Re-ran combofix and attached the log."
I do not need luck with Mlaware, although I do when trying to understand users who do not follow instructions
You are still infected
Quads
