09-05-2012 12:54 AM - edited 09-05-2012 12:55 AM
Hi,
As many others I do have a persistent Trojan on my laptop: Trojan.Zeroaccess!Inf in services.exe
It was identified by Norton 360 a few days ago.
Tried the Norton Power Eraser and the suggested Removal Tool without success.
My system:
HP Elitebook 8530w
Windows Vista Buisness 32-bit, Service Pack 2
Any help to remove this is highly appreciated.
Thanks,
Mark
Solved! Go to Solution.
09-05-2012 06:13 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link.
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters option and select the detect TDL File system
Click OK
Then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
Look for the Filesystem detection
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste into Notepad and attach back here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ ) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.
Quads
09-06-2012 12:46 AM
The requested log. Thanks.
09-06-2012 06:31 PM
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
09-07-2012 03:15 AM
The Combofix log:
09-07-2012 07:12 PM
Download FSS
http://www.bleepingcomputer.com/download/farbar-se
Start FSS.exe, tick all the boxes in the list and then run a scan, and attach the log back.
Quads
09-08-2012 01:52 AM
FSS Log:
09-08-2012 02:04 AM
Download the attached .txt file, and remove the .txt extension so that you have the files end in .reg
Then click to run the files and then the system should ask if you want the data added to the registry, answer = yes. A cofirmation message should them appear saying that the data has been added..
The other way is to right click the files and choose "Open With" from the menu, and you should see Registry Editor as an option to choose.
Once added restart the system and run FSS with all options again.
Quads
09-08-2012 03:09 AM
The second FSS log after adding registries. Thanks!
09-08-2012 04:30 PM
2 services still don't want to start, lets make sure they are correct
Download the attached .txt file, and remove the .txt extension so that you have the files end in .reg
Then click to run the files and then the system should ask if you want the data added to the registry, answer = yes. A cofirmation message should them appear saying that the data has been added..
The other way is to right click the files and choose "Open With" from the menu, and you should see Registry Editor as an option to choose.
Once added restart the system and run FSS with all options again.
Quads
