Pending Trojan.Zeroaccess ...Help please

Discussion in 'Virus, Spyware and Malware Removal' started by Kristy Rohm, Jul 15, 2012.


  1. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    My anti virus protectiction is locating and deleting by cleaning the trojan.zeroaccess virus or worm or whatever it is. I keep receiving popups that show the auto-protect results. My computer also shuts down by itself for some reason. Can you help?

    Attached Files:

  2. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    Hi,

    Welcome to the site :)

    First off I don't see an anti-virus installed and yet you state its picking up something. Can you confirm?
    =====

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    Link 3

    When saving ComboFix rename it to PCHelpForum.exe to prevent it from being blocked by malware.


    Refer to this image:

    To prevent your anti-virus application interfering with ComboFix we need to disable it. See here for a tutorial regarding how to do so if you are unsure.
    • Close any open windows and double click PCHelpForum.exe to run it.

      You will see the following image:
    [IMG]

    Click I Agree to start the program.

    ComboFix will then extract the necessary files and you will see this:

    [IMG]

    As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7

    It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    If you did not have it installed, you will see the prompt below. Choose YES.

    [IMG]

    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [IMG]

    Click on Yes, to continue scanning for malware.

    When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).

    Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so.

    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.
  3. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    I have symantec...thanks for responding :)
  4. Google Advertisement

  5. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    Ok. Follow up with ComboFix please
  6. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    do I attach the combofix log or copy paste into a reply window
  7. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    Attach it please
  8. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    Combo Fix log :)

    Attached Files:

  9. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
  10. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    I'm not sure what you mean be setting up a proxy? Can you tell me if I need to do that? And if so do I just follow the directions on the link? It runs okay...a little slow. I keep getting the popups from symantec with the auto protect reults. It has been shutting itself down and odd times and I can figure out why? Sorry I'm not the most computer savvy person there is :(
  11. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    No, its not needed and sometimes set by malware. If you don't know how to do it, that's likely what's happened. Following the instructions above will remove it
  12. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    Ok I went to Internet Optins and clicked on Lan Settings ...The Proxy Server is not checked. Do I need to check it and leave it saying bypass proxy server for your LAN?
  13. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    No, leave it unchecked.


    Please download TDSSKiller from here and save it to your Desktop.

    • Doubleclick TDSSKiller.exe to run the tool
    • Choose Change Parameters and make sure all the options are checked
    • Click the Start Scan button
    • After the scan has finished, click the Close button
    • Click the Report button and attach the contents of it into your next reply
    Note:It will also create a log in the C:\ directory.
  14. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    Okay...ran the scan and see a screen that says threats detected and a box that says continue...no close button...click continue?
  15. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    40,376
    Likes Received:
    3,758
    My System
    Loading...
    Yes, close
  16. Kristy Rohm Bronze Member

    Bronze
    Message Count:
    31
    Likes Received:
    0
    My System
    Loading...
    tried to copy and pste thelog...to big...trying to attach and send it now

Trojan.Zeroaccess ...Help please