07-08-2012 03:11 PM
This program is being constantly blocked. And it is also reading as a trojan.patchep!sys. I also have a Trojan.zeroaccessB in another file. Neither of which I can seem to remove. Any help would be appreciated.
07-08-2012 05:18 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
What is your Operating system including if it's 32 bit or 64 bit??
Quads
07-08-2012 06:03 PM
Windows 7 64bit
07-08-2012 07:47 PM
Do you have a Flash Drive??
Quads
07-08-2012 08:34 PM
No
07-08-2012 08:51 PM
Please download SystemLook from one of the links below and save it to your Desktop.
http://jpshortstuff.247fixes.com/SystemLook.html the 64 bit version
Disable Norton for say 30 mins
Double-click SystemLook_v64.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
\n
\@
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply (attach to message).
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
07-14-2012 01:20 PM
SystemLook 30.07.11 by jpshortstuff
Log created at 15:16 on 14/07/2012 by Josh
Administrator - Elevation successful
========== filefind ==========
Searching for "\n"
No files found.
Searching for "\@"
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
Searching for "*.@"
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
Searching for "services.exe"
C:\Windows\System32\services.exe --a---- 328704 bytes [23:19 13/07/2009] [01:39 14/07/2009] 24ACB7E5BE595468E3B9AA488B9B4FCB
C:\Windows\winsxs\amd64_microsoft-windows-s..s-ser
-= EOF =-
07-14-2012 05:15 PM
Download OTL http://www.bleepingcomputer.com/download/otl/
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
07-14-2012 06:39 PM
All processes killed
========== OTL ==========
========== FILES ==========
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d
C:\Users\Josh\AppData\Local\{ff56e231-8c20-23a1-2d
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
C:\Windows\Installer\{ff56e231-8c20-23a1-2d0d-003f
========== REGISTRY ==========
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56466 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Josh
->Temp folder emptied: 273133493 bytes
->Temporary Internet Files folder emptied: 35023368 bytes
->Java cache emptied: 374592 bytes
->FireFox cache emptied: 436868205 bytes
->Google Chrome cache emptied: 6553751 bytes
->Flash cache emptied: 66983 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 449296630 bytes
%systemroot%\sysnative\config\systemprofile\AppDat
RecycleBin emptied: 202279148 bytes
Total Files Cleaned = 1,404.00 mb
[EMPTYFLASH]
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: Josh
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: Josh
->Java cache emptied: 0 bytes
User: Public
Total Java Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.54.0 log created on 07142012_203059
Files\Folders moved on Reboot...
C:\Users\Josh\AppData\Local\Temp\FXSAPIDebugLogFil
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
PendingFileRenameOperations files...
File C:\Users\Josh\AppData\Local\Temp\FXSAPIDebugLogFil
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
File C:\Users\Josh\AppData\Local\Mozilla\Firefox\Profil
Registry entries deleted on Reboot...
07-14-2012 09:14 PM
start attaching logs NOT copy and pasting them.
Quads
