Author Topic: Win32:ZAccess-PB trojan horses  (Read 10289 times)

0 Members and 1 Guest are viewing this topic.


argus

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #16 on: July 29, 2013, 09:34:53 PM »
Remove icon (Combofix) and download  new ComboFix to your desktop
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Run Combofix. When the tool is finished, it will produce a log report for you. Attach log reports ( ComboFix.txt) back to topic.

destineeraej

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #17 on: July 29, 2013, 11:04:45 PM »
I've attahced the new comboFix log.

argus

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #18 on: July 29, 2013, 11:33:11 PM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SmcService]
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

RegLockDel::
[HKEY_LOCAL_MACHINE\SOFTWARE\Symantec\Symantec Endpoint Protection\CurrentVersion]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Symantec\Symantec Endpoint Protection\CurrentVersion]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\

SecCenter::
{5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}

Folder::
c:\program files (x86)\Symantec



Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

destineeraej

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #19 on: August 06, 2013, 01:27:37 AM »
ComboFix log attached

argus

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #20 on: August 06, 2013, 08:08:09 AM »
Norton is not active anymore. Any problems?

destineeraej

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #21 on: August 07, 2013, 08:18:17 PM »
Nope! Thank you for your help!!

argus

  • Guest
Re: Win32:ZAccess-PB trojan horses
« Reply #22 on: August 07, 2013, 08:25:47 PM »



It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.