also @ TechSpot: Study suggests majority of Windows 8 users ignore Metro apps

Windows Server 2008, Sirfef.b/y and zeroaccess

Discussion in 'Virus and Malware Removal' started by avenged187, Aug 9, 2012.

Post New Reply
  1. avenged187 Newcomer, in training Posts: 68

    Sorry. Just listing them off as I'm thinking of them. Been working on trying to get this server back in shape since 6pm last night. :confused:
  2. avenged187 Newcomer, in training Posts: 68

    Ok, MSE reinstalled, updates working fine on that end.
  3. avenged187 Newcomer, in training Posts: 68

    I think the java apps just need to be reinstalled, probably corrupted with all the changes. And just have to replace the firewall rules (ugh). but it seems as though most things are running correctly now.
  4. Broni Malware Annihilator Posts: 39,349   +175

    Zero Access rootkit is not a joke so I'm not surprised some programs got messed up.
    Hold on. I have to scroll up to see where we're at.
  5. Broni Malware Annihilator Posts: 39,349   +175

    OK, see if Security Check will run now.

    Also I'll need Eset scan log.
  6. avenged187 Newcomer, in training Posts: 68

    security check is still not running properly. saying that every command is not recognized as an internal or external command.
     
  7. Broni Malware Annihilator Posts: 39,349   +175

    Can you give me one example with full wording?
  8. avenged187 Newcomer, in training Posts: 68

    'find' is not recognized as an internal or external command, operable program or batch file.
  9. Broni Malware Annihilator Posts: 39,349   +175

    Hopefully it's just messed up path not files themselves.

    First check if you can find "find.exe" in d:\Windows\System32 folder.
  10. avenged187 Newcomer, in training Posts: 68

    I see find, as well as many other commands that weren't working in cmd, but its in c:\windows\system32. d: is simply the storage drive. no windows folder
  11. Broni Malware Annihilator Posts: 39,349   +175

  12. avenged187 Newcomer, in training Posts: 68

    I have %systemroot%\system32 in there, which I thought should default to c:\windows\system32. I copied it and pasted it to notepad, and could paste it here.
  13. Broni Malware Annihilator Posts: 39,349   +175

    It should.
    I'm not really sure what's going on there.

    Since we're getting well outside malware removal subject I want you to run Eset scan so we can wrap up malware removal part.

    As for your other issue you'll have to create new topic in Windows forum.
    I'm simply too busy here.
  14. Broni Malware Annihilator Posts: 39,349   +175

    I've noticed that FSS was also looking for drivers in "D" drive so it must be something in your "path".
  15. avenged187 Newcomer, in training Posts: 68

    Understood. Did you want me to run TFC first? or just the Eset?
  16. Broni Malware Annihilator Posts: 39,349   +175

    TFC then Eset but also read my previous reply.
  17. avenged187 Newcomer, in training Posts: 68

    Also, ESet is not running. When I click to have it run a scan, and accept the terms, it defaults to a blank grey window.
  18. Broni Malware Annihilator Posts: 39,349   +175

    Try different browser.
  19. avenged187 Newcomer, in training Posts: 68

    ok. TFC just finished. Server is rebooting.
  20. avenged187 Newcomer, in training Posts: 68

    Also, oddly, changing %systemroot% to c: in path apparently fixed the problem, and security check just finished