08-01-2012 05:58 AM
It appears that I have contracted the Trojan.Zeroaccess!inf virus. Can somebody help me out on how to get rid of this thing? I am not able to connect to any of the other computers on the network. I am on Windows XP Professional, 2002 Version Service Pack 3.
Please help!!
Thanks in advance.
MR
Solved! Go to Solution.
08-01-2012 07:48 PM - edited 08-01-2012 07:51 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Unfortunately, with the amount of threads means the waiting time is longer, Norton continually Blocking files won't hurt your system but is is just annoying, Please wait and be patient. I am trying to keep up, spending hours here to script and clean machines on a first come/first served basis. If you or someone adds to your thread It will be pushed back in line due to the new update. I use the boards in reverse to what is seen
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
The infection has to be removed first before seeing after that the network gets fixed
Please download SystemLook from one of the links below and save it to your Desktop.
http://jpshortstuff.247fixes.com/SystemLook.html the 32 bit version
Disable Norton for say 30 mins
Double-click SystemLook.exe to run it.
Copy the content of the following codebox into the main textfield: (don't forget the : in front of :filefind)
:filefind
\n
\@
*.@
services.exe
Click the Look button to start the scan.
When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Quads
08-02-2012 05:43 AM
Quads, you are awesome. Thanks for your help. The requested log is attached.
08-02-2012 09:15 PM
What is the file detected as Trojan.Zeroaccess!inf
Quads
08-03-2012 03:04 PM
These are the two listings that Norton gives me:
Infected file: c:\system volume information\_restore{ffb90830-caa0-478c-ad8b-c120d
Remove Failed
Infected file: c:\WINDOWS\system32\drivers\netbt.sys
No fix attempted
08-04-2012 01:15 AM
One is in the system restore deal with that later.
Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link.
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters option and select the detect TDL File system
Click OK
Then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
Look for the Filesystem detection
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste into Notepad and attach back here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ ) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.
Quads
08-04-2012 03:15 PM
The report is attached. Also, it is now letting me see the other computers on the network.
08-04-2012 05:47 PM - edited 08-04-2012 05:59 PM
Still have to be careful about the services and networks
14:41:50.0281 10340 C:\WINDOWS\system32\DRIVERS\netbt.sys - copied to quarantine
14:41:55.0750 10340 Backup copy found, using it..
14:41:55.0812 10340 C:\WINDOWS\system32\DRIVERS\netbt.sys - will be cured on reboot
14:41:57.0953 10340 C:\WINDOWS\$NtUninstallKB42420$\590043313 - will be deleted on reboot
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
Quads
08-06-2012 06:26 AM - edited 08-06-2012 06:26 AM
Attached is the Combofix log that you requested.
08-06-2012 11:15 PM
step 4. (a)
Please read carefully and Slowly
You might have to export the results
Please scan with ESET next
I'd like us to scan your machine with ESET OnlineScan
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it.
Quads
