Reply
Contributor
caf0814
Posts: 16
Registered: ‎07-16-2012

Re: Trojan Zeroaccess still remains

[ Edited ]

In disabling my security program (Norton Internet Security), do I just go through all of the settings and features and turn every single thing off? Or just major things (i.e. antispyware)?

 

Also, I get the usual notice of disabling said antivirus scanners before proceeding, which is followed by another warning that says I am performing this at my own risk (all after disabling features on NIS)

Bot Obliterator
Quads
Posts: 13,245
Registered: ‎07-21-2008

Re: Trojan Zeroaccess still remains

The Norton warning is OK.

 

Disable Auto-Protect,  AntiVirus / AntiSpyware and Sonar,  You can leave the Firewall turned on.

 

Quads

 

Contributor
caf0814
Posts: 16
Registered: ‎07-16-2012

Re: Trojan Zeroaccess still remains

ComboFix log is attached.

 

 

-C.

Bot Obliterator
Quads
Posts: 13,245
Registered: ‎07-21-2008

Re: Trojan Zeroaccess still remains

step 4. (a)

 

Please read carefully and Slowly

 

 Please scan with ESET next 


I'd like us to scan your machine with ESET OnlineScan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Under scan settings, check Posted Image and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • Attach the resulting log in your next reply


If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it. 

 

Quads

Contributor
caf0814
Posts: 16
Registered: ‎07-16-2012

Re: Trojan Zeroaccess still remains

ESET log is attached.

 

-C.

Bot Obliterator
Quads
Posts: 13,245
Registered: ‎07-21-2008

Re: Trojan Zeroaccess still remains

Step 4. (b)

 

Disable Norton for say 30 minutes

 

 

Download OTL http://www.bleepingcomputer.com/download/otl/

 

Start OTL,  

Click the Scan All Users checkbox.

Change file age to 60 days

 

Press the 

 

 

An OTL.txt  and extras.txt will be created.

 

Quads

Contributor
caf0814
Posts: 16
Registered: ‎07-16-2012

Re: Trojan Zeroaccess still remains

After running OTL four consecutive times, the program will scan and abruptly stop, stating it is "Not Responding."

 

-C.

Bot Obliterator
Quads
Posts: 13,245
Registered: ‎07-21-2008

Re: Trojan Zeroaccess still remains

Try in Safe Mode with Networking.

 

Quads

Contributor
caf0814
Posts: 16
Registered: ‎07-16-2012

Re: Trojan Zeroaccess still remains

OTL log and Extras log are attached.

 

-C.

Bot Obliterator
Quads
Posts: 13,245
Registered: ‎07-21-2008

Re: Trojan Zeroaccess still remains

Uninstall

 

ESET Online scanner

 

I have to script for the rest.

 

Quads