07-11-2012 11:04 PM
I see that several people have posted issues with Zeroaccess.B and Gen.2 and I seem to be in the same boat as most of the other people. The problems started tonight (7/11/2012) at 9:22 and seem to repeat over and over. Here are the last few notices I've gotten:
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:26:45,High,00000008.@ (Trojan.Gen) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:26:46,High,80000032.@ (Trojan.Gen.2) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:26:51,High,80000000.@ (Trojan.Zeroaccess.B) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:35:13,High,00000004.@ (Trojan.Gen.2) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:35:13,High,000000cb.@ (Trojan.Gen.2) detected by Auto-Protect,Blocked,Resolved - No Action Required
Category: Resolved Security Risks
Date & Time,Risk,Activity,Status,Recommended Action
2012-07-11 22:35:19,High,80000000.@ (Trojan.Zeroaccess.B) detected by Auto-Protect,Blocked,Resolved - No Action Required
I could use whatever heelp you can provide to clear this off of my computer.
Thanks,
Ron
07-11-2012 11:37 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
What is your Operating System, including if it's 32 bit or 64 bit??
Quads
07-11-2012 11:45 PM
Windows XP Service Pack 3
32 bit
07-11-2012 11:51 PM
Please download SystemLook from one of the links below and save it to your Desktop.
http://jpshortstuff.247fixes.com/SystemLook.html the 32 bit version
Disable Norton for say 30 mins
Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
\n
\@
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply (attach to message).
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
07-12-2012 11:59 PM
The network connection on the computer is not working anymore (I'm getting a limited or no connection on the adapter.) So I was finally able to get the program to the computer and run the program. I am attaching the log here.
Thanks,
Ron
07-13-2012 12:08 AM
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
07-13-2012 01:36 AM
I'm not sure that I understand the last request. Is OTL a program that I am supposed to have? Is it something else?
Thanks,
Ron
07-13-2012 02:01 AM
07-13-2012 06:18 AM
Here is the log from the OTL run
07-13-2012 06:36 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
