06-22-2012 02:09 AM
It blocks it every 30 mins I would say. I check my computer for virus none was found. So why does it keep repeating?
06-22-2012 02:21 AM - edited 06-22-2012 02:22 AM
These are the virus the same two
Category: Resolved Security Risks Date & Time,Risk,Activity,Status,Recommended Action 6/22/2012 2:16 AM,High,00000001.@ (Backdoor.Trojan) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks Date & Time,Risk,Activity,Status,Recommended Action 6/22/2012 2:16 AM,High,80000000.@ (Trojan.Zeroaccess) detected by Auto-Protect,Blocked,Resolved - No Action Required
06-22-2012 02:32 AM
It's a Rootkit that is why.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
What are the files and locations that Norton is detecting??
Please download SystemLook from one of the links below and save it to your Desktop.
hxxp://jpshortstuff.247fixes.com/SystemLook.exe change the xx to tt
Disable Norton for say 30 mins
Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
06-22-2012 01:19 PM
I think I did it right.
06-22-2012 01:26 PM
I also notice something just now it says one thing was download Imciqtq.exe after this was download I had a total 24 virus blocks??
06-22-2012 01:33 PM
Interesting how on yours system services.exe does not show in the system32 folder as it should.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Doiwnload the attached CFscript.txt, , For some browsers Right Click the attachment on the forum and select "Save AS" or similar to Download it. See screenshot below.
Now drag the CFScript.txt into the ComboFix.exe

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
06-22-2012 03:54 PM
I had to uninstall norton because my computer would not let me disable it I hope thats okay
06-22-2012 04:23 PM
06-22-2012 04:48 PM
It still does not show a services.exe in the system32 folder.
Download OTL http://www.bleepingcomputer.com/download/otl/
Start OTL,
Click the Scan All Users checkbox.
Change file age to 60 days
under
Copy and paste what is below between the lines
msconfig
activex
drivers32
netsvcs
"%WinDir%\$NtUninstallKB*$." /30
C:\Program Files\Common Files\ComObjects\*.* /s
%systemroot%\*. /mp /s
%systemroot%\*. /rp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.sys
atapi.sys
explorer.exe
winlogon.exe
mswsock.dll
wininit.exe
services.exe
svchost.exe
tdx.sys
afd.sys
cdrom.sys
i8042prt.sys
netbt.sys
redbook.sys
mrxsmb.sys
/md5stop
Press the 
An OTL.txt and extras.txt will be created.
Quads
06-22-2012 05:17 PM
