07-11-2012 07:27 PM
One thing, don't have more than one realtime AV installed they conflict, even if you don't see it
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
07-11-2012 07:43 PM
07-11-2012 07:52 PM
Hows your system running now??
Quads
07-11-2012 07:58 PM
seems good, no popup detections or anything, is there any changes I need to do to keep this from happening again?
07-11-2012 08:07 PM
Zeroaccess is actively evolving and even AV compinies are having to keep up with the changes.
Just think about smart browsing and where you are downloading anything from.
Disable Norton
Start OTL again but this time click the Black CleanUp button, then make sure the C:\_OTL folder is deleted.
After that you are free to go on your merry way. You are now fixed / Solved.
If you want Malwarebytes download the Free version to install and don't click the Trial button
If you want to, you can turn off System Restore wait for it to clear the Restore Points and then Turn it back on once you find all is happy. today, tomorrow whenever.
Quads
07-11-2012 09:11 PM
Thanks Quads I sincerely appreciate everything to do for all of us newbies!
07-23-2012 10:26 AM
Moved to own thread for better exposure.
07-26-2012 08:11 AM
Hello,
I have had the same issues as expressed on these messages; trojan.gen, trojan.gen2, zeroacces.b. I have been working on this issue for a couple of days now, and I have noticed that the Base Filtering Engine and Windows Firewall services have been removed (there may be more). I have replaced them, but they will not start, access is denied. Can you guide me to a thread that helps to fix the computer from the damages that these trojans have done --- after I get these viruses removed?
Thanks,
Mike
07-26-2012 06:08 PM
And any damage you have done.
Quads
