04-01-2012 05:18 PM
Symantec should not be running realtime protection in safe Mode so that is OK.
Don't forget to do the dropping of the script.txt on top of Combofix this time.
Quads
04-01-2012 06:54 PM
THE LOG.
04-01-2012 07:00 PM
Run the ESET online scanner like last time.
Quads
04-02-2012 12:28 AM
The eset log.
04-02-2012 12:40 AM
Turn off System Restore and leave it turned off
As you can see zeroaccess is in the System Restore
Find this folder and delete it C\Documents and Settings\admin\Configuración local\Datos de programa\69c3a23e
Then delete this folder C:\Qoobox
I am not sure what to do with Symantec and whether it's up to standard with stopping this or not I have never used it to compare to Norton Internet Security.
One other thing is has been found that that malware can come in via emails, so if you or others have strange looking emails delete them completely,
Quads
04-02-2012 12:15 PM
Questions
1) I have to leave off system restore until when? forever or what you suggest?
2) I can't remove Qoobox folder because one folder in it that's called Backenv, i 'm doing this in normal mode, what would you suggest to eliminate it?
3) When you say emails you are reffering to hotmail inbox mails? I never open that emails, but you say that by having it closed without opening them the virus can attack anyways?
04-02-2012 04:12 PM
1) Say for 2 - 3weeks
2) That's OK I will get it at a later date, once we know you haven't got it back for a 4th time.
3) These groups like zeroaccess are infecting PC's in many ways, including ads in websites and Java, and the evil creators are still active and update the malware all the time.
Manually Live update Symantec and Malwarebytes making sure the updates are installed and run scans every day for now.
Quads
04-15-2012 07:51 PM
Since your last post i desactivated system restore and no virus were found. Should i turn system restore on or before you want some logs from some programs?
04-15-2012 07:55 PM - edited 04-15-2012 07:59 PM
If your PC is still running fine, you can turn System Restore back on. Just keep updating malwarebytes every day to back sure you have definition updates. and please don't get any more variants of Zeroaccess etc., you were getting them faster then I was.
Just need a new OTL log Change the file age to 90 days instead of 60days like the last instructions
Quads
04-15-2012 10:45 PM
I don't have malewarebytes, is it freeware?
Here's the log.
I will wait some mroe days to turn on the system restore, it changes something very important to turn it on?
