07-23-2012 09:31 AM - edited 07-23-2012 10:04 AM
Appear to be having same problems popping up that others are seeing. NAV popping up windows re: Trojan. Zeroaccess.B and Trojan.Gen.2. But, not fixing problem. I was going to download the Farbar Recovery scan tool to get you a log, but, running XP (on HP HDX laptop), I don't know if what a "PE boot CD" is. Any help, direction or advice is creatly appreciated! Thanks.
PS - I have a flash drive available
Also, the details in the scan history show the infected file at:
c:\users\me\appdata\local\{ff24043d-55f8-5ce9-a20a
80000000.@
I don't know if that location helps as I cannot locate that file on the system.
Solved! Go to Solution.
07-23-2012 06:26 PM - edited 07-23-2012 06:29 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Please download SystemLook from one of the links below and save it to your Desktop.
http://jpshortstuff.247fixes.com/SystemLook.html the 32 bit version
Disable Norton for say 30 mins
Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
\n
\@
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
07-23-2012 08:21 PM
Thanks for replying, Quads! I know you do this volunteer....so I GREATLY appreciate the help.
Just to confirm....you want me to download the 32-bit version of SystemLook even though I'm running 64-bit?
07-24-2012 06:17 PM
XP 64 bit is not supported by Norton, and the path you gave has been modified and is not XP.
So it looks like you are on your own to sort out even what system you have.
Quads
07-24-2012 06:40 PM
My bad! Vista 64 (XP is my wife's laptop). Sorry about that. Ran SystemLook. Log attached. Again, my apologies.
07-25-2012 05:26 PM - edited 07-25-2012 05:28 PM
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Vista 64 means
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
07-25-2012 08:59 PM
Thank you. Log file is attached.
07-26-2012 05:48 PM
Step 2
Download the script attached, needs to be the same file name as well (fixlist.txt), Copy across to flash drive
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Now please enter System Recovery Options again. Like previously
Quads
07-26-2012 08:20 PM
Thank you for writing the script. fixlog attached.
07-27-2012 07:05 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
