03-30-2012 04:18 AM
2 New zeroaccess droppers and the detection rates,
https://www.virustotal.com/file/5497b00598bcc266b5
https://www.virustotal.com/file/9cc7f4931d88ddfe47
Quads
03-30-2012 04:36 PM
Bad news, i kept internet disconected and the antivirus disabled but after an hour i turn on the combofix and it said that the anti virus was turned on, it asked if it could disable it, i click YES, but it said that it couldn't do that, so it would run the combofix anyways. I closed the combofix window before it started scanning.
What should i do? there is another way to disable the antivirus? I disable it by clickng right botton, disable.
What should i do>? i have to wait another hour?
03-30-2012 04:51 PM
Oh well will just have to run it., Don't know what's up with Symantec
Quads
03-30-2012 04:55 PM
3 qjuestion:
1 )i run it no matter symantec cannot be totatlly disabled you said?
2) can it have damage on the anti virus?
3) i have to wait one more hour disconected and so?
03-30-2012 05:00 PM
What you do is enable Syamantec again so the 1 hour gets removed, then you disable for 1 hour again.
I have a feeling SEP (Symantec Antivirus) does not have the protection compared to Norton Internet Security, let alone what is going on with Symantec.
Quads
03-30-2012 05:42 PM
Alright so i disable symantec for and hour without having internet, then without changing this i run the combofix no matter what symantec antivirus related stuff it may say.
It's that ok?
I'll do it later and post the logs.
03-31-2012 04:59 AM - edited 03-31-2012 05:06 AM
Yes, with the CFscript.txt
I have updated the script attached to this message
Quads
03-31-2012 12:06 PM
Terrible news...
I waited an hour and when running the combofix with the script it started only partially, the kind of ms-dos window of combofix never opened. Then i restarted my computer, and the same happened. I connected internet again, but i couldn´t do it. The combofix is still not working and now my computer can´t connect to internet. It says when i click on repair that the ip adress cannot be renew or update (renovar in spanish). What can i do ?
03-31-2012 06:02 PM
Do not restart the PC while Combofix is running, I had this problem with another user the other day.
Quads
03-31-2012 06:06 PM
The problem was that combofix didn't ran at 100%after waiting a lobg time. What can i do/download/whatever to get back the internet conection at that computer, so then i can continue with the zeroaccess issue?
