05-12-2012 07:23 PM
While I am slowly creating a script if you want to double check
You can scan with Cureit http://www.freedrweb.com/cureit/?lng=en (free download link) and /or Hitman Pro http://www.surfright.nl/en/downloads/ (the 32 bit on that page)
Just take note of what that find before having them do anything as they can have False Positives, Zeroaccess leftovers or quarantined items are detected as zeroaccess 0access or MaxPlus.
Quads
05-12-2012 07:27 PM
Have them delete those or just report back to you?
05-12-2012 07:31 PM
if unsure on anything at all report back the file name, location and detection name
Quads
05-13-2012 07:52 AM
Ran DrWeb and found nothing, but noticed it defaulted to Express scan. Ran it again with Complete Scan. Found it along with a few false positives. The MuDrop3 had the Panda logo next to it so I assume that's a false return. It did find 8 instances of MaxPlus. I did not take any action. I have pasted the results. I tried to copy and paste into Wordpad and save a .txt, but when I tried to open that .txt, I was asked if I was sure I wanted to add the contents to the registry. I declined.
| restart.exe.vir;C:\Qoobox\Quarantine\C\Documents and Settings\Gary\Desktop\SmitfraudFix;Tool.ShutDown.1 | ||||
| Dc8.exe;C:\RECYCLER\S-1-5-21-776561741-492894223-6 | ||||
| A0112915.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0113427.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0113828.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115879.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115895.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115899.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115924.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115953.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0115956.dll;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0116672.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0116760.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0118727.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0118732.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0118733.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 | ||||
| A0118755.exe;C:\System Volume Information\_restore{77B878BA-823E-498A-9A54-A1D02 |
05-13-2012 01:13 PM
Just Turn off System Restore, and it will take time to wipe the restore points.
Quads
05-13-2012 01:33 PM
Want to be sure here.
I turned off system restore. Now do you want me to use the results of DrWeb to remove those items it found? If so, which? Just teh Maxplus ones?
05-13-2012 01:41 PM
No don't have it fix or remove anything.
The last 2 items left are just,
1 in the Recycle Bin and one that I will be removing via a script anyway.
Quads
05-13-2012 01:44 PM
standing by. Thanks!
05-13-2012 01:50 PM - edited 05-13-2012 01:52 PM
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
05-13-2012 02:38 PM
Log attached.
