Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Infected with ZeroAccess Katusha and more

  • This topic is locked This topic is locked
2 replies to this topic

#1 moreice


  • Members
  • 2 posts
  • Local time:08:11 AM

Posted 18 August 2011 - 12:49 PM

Was infected with TDSS - fixtdss got rid of it.
Ran almost every tool possible...almost all crash and are disabled from running again.
I have resorted to copying each EXE that I use and running the copy, so I can have a backup.
Just got finished running Panda SafeCD from CD and it removed a bunch of stuff, but I still am infected and getting redirected on all websites.
No matter what I do, I keep seeing a fake process called 2088005743:2425326467.exe running as system.
Process exists in SAFE MODE with Networking, but not regular SAFE MODE

Attached Files

BC AdBot (Login to Remove)


#2 moreice

  • Topic Starter

  • Members
  • 2 posts
  • Local time:08:11 AM

Posted 18 August 2011 - 02:04 PM

Somehow seems fixed.
Ran Defogger disabled CD
Uninstalled all versions of JAVA.
Ran D7 and managed to blacklist the "services" that were suspicious.
Downloaded and installed FixNCR.Reg from this forum.
Restarted and everything seems ok
Malwarebytes didnt detect anything in quick scan yet
Neither did antizeroaccesss
going to run everything again just to make sure.

#3 Orange Blossom

Orange Blossom

    OBleepin Investigator

  • Moderator
  • 37,011 posts
  • Gender:Not Telling
  • Location:Bloomington, IN
  • Local time:08:11 AM

Posted 22 August 2011 - 11:33 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.

Orange Blossom

An ounce of prevention is worth a pound of cure

SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users