08-01-2012 03:54 PM
Yesterday my PC got infected with Trojan.Zeroaccess and Trojan.Gen.2. Symantec Antivirus auotprotect reported a swarm of Trojan.Zeroaccess and Trojan.Gen.2 infections. After multiple scans SAV no longer reports that the viruses are on my computer. However real time protection is disabled and I cannot restart it. Similarly Windows Firewall is disabled and cannot be enabled.
Malwarebytes reports that Trojan.Agent is infecting my computer as well. I don't know if this is related to my Zeroaccess and Gen.2 infection. Any help would be appreciated.
My PC is running Windows XP SP3 and I have a flash drive.
Solved! Go to Solution.
08-02-2012 06:34 PM - edited 08-02-2012 06:36 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
Please download SystemLook from one of the links below and save it to your Desktop.
http://jpshortstuff.247fixes.com/SystemLook.html the 32 bit version
Disable Norton for say 30 mins
Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
\n
\@
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
08-02-2012 06:52 PM
Quads,
Thank you for offering to help. Here is the SystemLook log file.
-phil
08-03-2012 06:18 PM
Step 2
Download OTL http://www.bleepingcomputer.com/download/otl/ to the Desktop
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Attach log.
Quads
08-03-2012 06:44 PM
Quads,
OTL log file is attached.
-phil
08-03-2012 06:48 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
08-03-2012 07:26 PM
Quads,
ComboFix log is attached.
-phil
08-04-2012 06:44 PM
step 4. (a)
Please read carefully and Slowly
You might have to export the results
Please scan with ESET next
I'd like us to scan your machine with ESET OnlineScan
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it.
Quads
08-05-2012 04:33 AM
Quads.
Here is the ESET log.
-phil
08-05-2012 05:51 PM
Step 4. (b)
Disable Norton for say 30 minutes
Download OTL http://www.bleepingcomputer.com/download/otl/
Start OTL,
Click the Scan All Users checkbox.
Change file age to 60 days
Press the 
An OTL.txt and extras.txt will be created.
Quads
