Avast WEBforum

Other => Viruses and worms => Topic started by: madalinbj on May 22, 2013, 10:39:20 PM

Title: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 22, 2013, 10:39:20 PM
HI! Can you help me?

Thx!
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: Pondus on May 22, 2013, 10:43:44 PM
removers are notified. it may take hours before they arrive so be patient
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 22, 2013, 10:46:04 PM
aswMBR
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 22, 2013, 10:51:17 PM
Hi,



> Download ComboFix from here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.
If you are unsure how ComboFix works please read this guide (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html) or this (http://www.bleepingcomputer.com/forums/topic114351.html) Instruction.

How to disable avast:

Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.


============ Next ===========



Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 23, 2013, 03:49:28 PM
combo&FRST
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 23, 2013, 07:15:34 PM
any answer? pls
thanks!
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 23, 2013, 09:53:54 PM
any answer? pls
thanks!
Be patient, I will not forget you ...

----------
1.
Paste FRST.exe in some folder on your desktop

2.


Open notepad.

Copy - paste the content below;


Code: [Select]

File: c:\windows\system32\services.exe
Folder: c:\users\mada\AppData\Roaming\postgresql
c:\windows\Installer\{77a80ffe-2062-1aeb-49d1-726875a5aae8}
DeleteJunctionsInDirectory: C:\Program Files\Windows Defender

fixlist.txt must be in the same location where FRST.exe tool is!



> Attach here fixlog.txt logreport.











Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 24, 2013, 03:59:35 PM
fixlog
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 25, 2013, 06:50:34 PM
So far this looks good. We go to additional check.




Please download zoek.exe (http://home.kpn.nl/stefsmeenk/zoek.exe/) and save it to your desktop.

Code: [Select]

process;
srinfo;
systemscpecs;
installedprogs;
DIR /S /A:L "%systemdrive%\*">>"%temp%\log.txt";b
C:\Windows\system32\services.exe;i
C:\Windows\SysNative\services.exe;i
filesrcm;
startupall;
skipfix-iedefaults;
firefoxlook;
chromelook;

Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 25, 2013, 07:16:26 PM
zoek
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 25, 2013, 07:24:00 PM
We will re-run FRST with this script:


Open notepad.

Copy - paste the content below;


Code: [Select]

DeleteJunctionsInDirectory: C:\Windows\winsxs\amd64_security-malware-windows-defender-events_31bf3856ad364e35_6.1.7600.16385_none_118cf1dcd54a3dea
DeleteJunctionsInDirectory: C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7600.16385_none_b3b1a27171e01f6c
DeleteJunctionsInDirectory: C:\Windows\winsxs\amd64_security-malware-windows-defender_31bf3856ad364e35_6.1.7601.17514_none_b5e2b6396ecea306



fixlist.txt must be in the same location where FRST.exe tool is!



> Attach here fixlog.txt logreport.
[/quote]


=========== Next =========


Re-run zoek.exe using this script:

Code: [Select]
DIR /S /A:L "%systemdrive%\*">>"%temp%\log.txt";b
Attach here fresh zoek log.




How's your computer running now?
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 25, 2013, 07:35:16 PM
another logs
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 25, 2013, 07:40:20 PM
Ok, your computer running good now?
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: madalinbj on May 25, 2013, 07:54:50 PM
like 1st day.
Thanks a lot !
 
Title: Re: logs Win32:Malware-gen Win32:Trojan-gen Win32:ZAccess-PB [Trj] on servic
Post by: magna86 on May 25, 2013, 10:40:01 PM
like 1st day.
Thanks a lot !
8)



It is necessary to uninstall ComboFix :
Code: [Select]
ComboFix /Uninstall Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Wait for the uninstall process is complete.


-----------------------------------------


Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.


------------------------------




I recommended you to keep Malwarebytes and to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://amf.mycity.rs/mcshield/)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.