Reply
Contributor
lesliep21
Posts: 14
Registered: ‎06-28-2012

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Yeah, should I look out for something?

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Step 3.

 

 

Please read carefully Read all of this message first

 

Download Combofix http://www.bleepingcomputer.com/download/anti-virus/combofix


  • Ensure that Combofix is saved directly to the Desktop <--- Very important  (not in the download or temp folders)

  • Disable all security programs as they will have a negative effect on Combofix, Disabled for say 1 hour or more.
  • Close any open browsers and any other programs you might have running

 

Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"  If required.

 

  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

*EXTRA NOTES*

  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Quads

Contributor
lesliep21
Posts: 14
Registered: ‎06-28-2012

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Disable all security programs? Isn't Norton keeping the trojans at bay? By the way, the Trojan.Gens haven't popped up, but the Trojan.Zeroaccess was auto-blocked.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

[ Edited ]

Follow the instructions it states why to do so.  or you can just keep the rest of the infection(on your system).

 

Notice I said way back 


  • Major steps used:

1. Find

2. Break

3. Destroy

4. Cleanup  (including system as a whole)


 

I would say you have no idea what is going on with your system, what is left and what I have done so far to just  give a question like your last post.

 

Quads

Contributor
lesliep21
Posts: 14
Registered: ‎06-28-2012

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Well **bleep**, "Adobe Flash Updater" kept annoyingly popping up all the time, asking to run, even when I closed it each time. So I stupidly clicked ok and now I got Trojan.Zeroaccess.B -> 80000000.@, 00000004.@ (Trojan.Gen.2), 000000cb.@ (Trojan.Gen.2). We'll probably have to start all over again, and I'm really sorry for causing you this much trouble. I've been too lax about this and I'll try to get over with quickly this time.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

[ Edited ]

There is no point complaining you have not carried on with my instructions,   Now  you are back at step one and needing a new FRST log as we previously had done.

 

All logs and scripts are null amd void.  This is what happens when all the steps are not done for this

 

Quads

Contributor
lesliep21
Posts: 14
Registered: ‎06-28-2012

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

 
Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Delete the copy of fixlist you have on your desktop and download and use the fixlist attached to this message.

 

As before transfer it to the flash drive and then restart the PC loading FRST and click fix etc.

 

Quads

Contributor
lesliep21
Posts: 14
Registered: ‎06-28-2012

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

 
Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Trojan.Gen.2 and Trojan.Gen (Trojan.Zeroaccess)

Step 3.  I have underlined why to disable all running security products.

 

 

Please read carefully Read all of this message first

 

Download Combofix http://www.bleepingcomputer.com/download/anti-virus/combofix


  • Ensure that Combofix is saved directly to the Desktop <--- Very important  (Not in the Download(s) or Temp folders)

  • Disable all security programs as they will have a negative effect on Combofix, Disabled for say 1 hour or more.
  • Close any open browsers and any other programs you might have running

 

Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"

 

  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

*EXTRA NOTES*

  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Quads