Endpoint Protection

 View Only
  • 1.  *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!

    Posted Feb 01, 2014 03:01 PM

    So Today I went to signup for a fourm and it said: 

    Your IP 74.85.***.* has been blocked because it is blacklisted. For details please see http://www.spamhaus.org/query/bl?ip=**.**.***.*

    Now when I looked at it I was listed in CBL and It Said: 

    It appears to be infected with a spam sending trojan, proxy or some other form of botnet.

    It was last detected at 2014-01-25 02:00 GMT (+/- 30 minutes), approximately 7 days, 18 hours, 29 minutes ago.

     

    This IP address is infected with, or is NATting for a machine infected with the ZeroAccess botnet, also known as Sirefef.

    =============================

    SEP Didn't Pick It Up and I have all the nessecary software from symantec to remove but first I need to know if I am infected?!?!



  • 2.  RE: *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!
    Best Answer

    Posted Feb 01, 2014 03:05 PM

    Download and run the removal tool to see if anything comes up

    http://www.symantec.com/security_response/writeup.jsp?docid=2011-121607-4952-99

    You can also try this removal tool

    http://www.bleepingcomputer.com/download/tdsskiller/

    What components of SEP do you have installed? Also, what version do you have running?



  • 3.  RE: *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!

    Posted Feb 01, 2014 03:21 PM

    SEP 7.5.1670

    And I have Mangement Agent

    and 6 Other Componets

    Tell Me Is

    i8042prt.sys That The Trojan Virus?



  • 4.  RE: *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!

    Posted Feb 01, 2014 03:38 PM

    Did you run a scan with the removal tool?

    You can submit that file to https://www.virustotal.com to see what comes up.



  • 5.  RE: *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!

    Posted Feb 01, 2014 03:42 PM

    I used both removel tools no possible virus found!

    VirusTotal No Possible Virus Found!

    Why Does It Say I have the ZeroAcsess Trojan?



  • 6.  RE: *URGENT!* I need to know if I have ZeroAccess Infecting my PC?!?!

    Posted Feb 01, 2014 04:05 PM

    I checked your IP against 90 known blacklists and you only appeared on 1...not sure why, perhaps false positive

    Download a second opinion scanner such as malwarebytes and run a full scan