
02-17-2012 07:46 AM
Hi please cacel the avp scan...i will run the big boys.
Download ComboFix from the any of the locations given in this website:


Download aswmbr.exe ( 1.8mb ) to your desktop.
http://public.avast.com/~gmerek/aswMBR.htm
Double click the aswMBR.exe to run it Click the "Scan" button to start scan.

Click the [Scan] button to start scan

On completion of the scan click [Save log], save it to your desktop and post in your next reply.
02-17-2012 08:25 AM
ok AVP canceled.. onto the next set of tasks..
Thanks again for all the help with this!
02-17-2012 08:32 AM
No problem!
I am online now.
02-17-2012 09:50 AM
Combofix found Rootkit.ZeroAccess! in my tcp/ip stack
On to the next task
02-17-2012 01:10 PM - edited 02-17-2012 01:21 PM
aswMBR Scan Results
It did find a trojan - I've deleted the file
02-17-2012 01:30 PM
Please go here:
C:\WINDOWS\System32\nlssrv32.exe
Upload this file here:
Tell me if it gets detected my any scanners.... this file is clean
02-17-2012 05:25 PM
I tried the OTL fix you suggested on page 2 and my computer locked up
lost my entire desktop.
I cold booted and it's fine so I'm not sure the fix took..
But I'm getting slammed by internet web threats... Anyway to stop this?
02-17-2012 09:43 PM - edited 02-17-2012 09:49 PM
Hi..i think combofix failed in curing rootkit zaccess...Re-run aswmbr and if the trojan is detected press fix button once the scan completes and the OTL fix did work...as OTL kills explorer before the fix thats the reason u lost your desktop.
Download the latest version of TDSSKiller from here and save it to your Desktop.
download link:http://support.kaspersky.com/viruses/utility





A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply.
NEXT
Please post:
All RKreport.txt text files located on your desktop
02-18-2012 05:38 AM
Should I rerun that OTL fix? I gave it about 5 min and when the screen didn't come back up I cold booted.
Also is someone keeping a list of stores launching attacks? I know now who stole my credit card info
the first time... I knew it was one of the web stores I went to but now I know who.
02-18-2012 08:02 AM - edited 02-18-2012 08:03 AM
Hi.
No need to re-run OTL fix...Just follow my instructions.
Copyright (c) 1989-2012 Trend Micro Incorporated. All rights reserved.
