Reply
Contributor
ms_kimmie
Posts: 29
Registered: ‎09-28-2012
Accepted Solution

Trogen.zeroaccess.c and Trogen.gen.2

norton antivirus 2012 installed on my computer saying that these two viruses have been detected and quarintined. Cannot update windows vista or windows defender. Have also installed and run power eraser which found no problems. What do I need to do? Windows Vista Home Premium, service pk 2 - 32 bit

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trogen.zeroaccess.c and Trogen.gen.2

Where are the files detected located?

 

Quads

Contributor
ms_kimmie
Posts: 29
Registered: ‎09-28-2012

Re: Trogen.zeroaccess.c and Trogen.gen.2

Norton antivirus says that all files were located in infected file c:\$recycle.bin  and that they have been resolved/removed, but still getting messages saying Trojan has been detected/blocked by autoprotect. And I still cannot get any windows updates (it says service not running) or windows defender updates (cannot download any updates). 

 

Thank you for the help

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trogen.zeroaccess.c and Trogen.gen.2

[ Edited ]

ANY other user other than the thread starter is not to use any instructions, scripts or proceedures,  The work though in cleaning a system is individual and only for that system due to a number of factors.

 

Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient.   I am  trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update.  I use the boards in reverse to what is seen

 

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability. Do as the instructions ask nothing extra or run things twice
  • If I ask a Question just answer it, don't run anything unless it states.
  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)

 

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.

 

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post. Please remember, I am a volunteer, and I do have a life outside of these forum, (sometimes :smileylol:)

  • Attention to detail is important! Since I cannot see or directly interact with your computer I am dependent on you to "be my eyes" and provide as much information as you can regarding the current state of your computer.

 

Download these 2 programs to you desktop ready just in case after the break you have no Internet  Don't run them yet

 

http://www.bleepingcomputer.com/download/farbar-service-scanner/

 

http://www.bleepingcomputer.com/download/combofix/

 

Quads

 

Contributor
ms_kimmie
Posts: 29
Registered: ‎09-28-2012

Re: Trogen.zeroaccess.c and Trogen.gen.2

I downloaded both to my desktop (even though Norton warned that Faber service scanner is not usually a safe download).  I have not run either one and will be waiting to see what the next step will be. Thank you again for you assistance.

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trogen.zeroaccess.c and Trogen.gen.2

Download the 2 attached .txt files, and remove the .txt extension so that you have the files end in .reg (ZAFix1.reg) etc.

 

Then click to run the files and then the system should ask if you want the data added to the registry, answer = yes.  A cofirmation message should them appear saying that the data has been added..

 

The other way is to right click the files and choose "Open With" from the menu, and you should see Registry Editor as an option to choose.

 

For me this repaired the 2 Windows registry keys in question.  So then I could after deal with the rest and also repair broken services.

 

As for connecting your other system, as far as I can see, it is OK to do so.

 

Quads

Contributor
ms_kimmie
Posts: 29
Registered: ‎09-28-2012

Re: Trogen.zeroaccess.c and Trogen.gen.2

[ Edited ]

I have done both. What is my next step. Thank you for the help.

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trogen.zeroaccess.c and Trogen.gen.2

After adding to the registry the fixes, restart Windows then.

 

Run FSS.exe, Tick all the boxes before running the scan and post back a log.

 

Quads

Contributor
ms_kimmie
Posts: 29
Registered: ‎09-28-2012

Re: Trogen.zeroaccess.c and Trogen.gen.2

Done...log attached. Thank you

Bot Obliterator
Quads
Posts: 13,238
Registered: ‎07-21-2008

Re: Trogen.zeroaccess.c and Trogen.gen.2

Download the 2 attached .txt files, and remove the .txt extension so that you have the files end in .reg 

 

Then click to run the files and then the system should ask if you want the data added to the registry, answer = yes.  A cofirmation message should them appear saying that the data has been added..

 

The other way is to right click the files and choose "Open With" from the menu, and you should see Registry Editor as an option to choose.

 

After adding to the registry all those, restart the system and Run FSS like the first time, ticking all the boxes.

 

Quads