Reply
Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

infected with trojan.zeroaccess!inf

I started having problems and I could not open any programs so I started my computer in safe mode and ran a scan. It had 3 errors all the same trojan.zeroaccess!inf which it said I had to remove myself. I did some research and I found the Fix Zeroaccess tool from Norton. When i ran that I recieved the error message "Pre-Boot operation failed, unable to continue. Error=1084"

 

Ideas anyone?

 

I am running windows xp sp2

AMD athlon 64 processor 3200+   2.21GHz

2GB of ram

 

Thanks

K_Ramachandran
Posts: 119
Kudos: 22
Solutions: 12
Registered: ‎06-27-2011

Re: infected with trojan.zeroaccess!inf

Hi Jsold406,

-----------------------------------------------------------------------------------------------------------

When i ran that I recieved the error message "Pre-Boot operation failed, unable to continue. Error=1084"

-----------------------------------------------------------------------------------------------------------

 

As to your problem, You have infected with a critical OS file, but in your case you can manully just delete the Infected file by go through the file path given for the infected file in the Norton Security Risk  (making sure to double check you have the correct file) and delete from the Recycle Bin.  You may have to disable Norton Auto-Protect to allow you to do this.

Then you will have to go into the Norton Security History--> Unresolved Threats list and click the "Clear Entries" button.

 

To findout the path for the infected file, please go through this link - as it will helps you to run a stand alone Norton Power Eraser Tool and will help you to find out.

 

http://community.norton.com/t5/Tech-Outpost/TDSSkiller-TDL4/m-p/467396/message-uid/467396/highlight/...

K Ramachandran
Norton One Support Advisor
Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

I ran the power eraser and deleted the file as you instructed. Now i restarted and i still recieve the same error=1084

 

the file that the power eraser wanted me to delete was 

c;\windows\system32\drivers\redbook.sys

 

also once deleted the file and restarted. the computer had some error that it fixed itself. 

Also i cannot do much when i start the computer normally so all of the things i am doing is through safe mode

Super Spam Squasher
cgoldman
Posts: 2,929
Registered: ‎06-25-2008

Re: infected with trojan.zeroaccess!inf

I am concerned at the instructions already advised to you. Redbook is an essential file. It may be infected. Removing it is only advised if you have an uninfected replacement and know how to obtain and copy same over.

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

ok so what do you suggest i do?

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

Did the removal tool actually remove redbook.sys??

 

Quads

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

no the removal tool only said that it was a problem and should be deleted but it would have to be deleted manually

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

[ Edited ]

Please read carefully and follow these steps.

Download TDSSKiller hxxp://support.kaspersky.com/downloads/utils/tdsskiller.exe and save it to your Desktop. (replace the hxxp with http)
doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back


Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back

 

Quads

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

the TDSSKiller did not find any errors and had not option for a report

Bot Obliterator
Quads
Posts: 13,938
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

We have a problem you are running XP SP2 you should be SP3 for Norton and other programs

 

download Combofix http://www.bleepingcomputer.com/download/anti-virus/combofix


  • Ensure that Combofix is saved directly to the Desktop <--- Very important

    Before saving Combofix to the Desktop re-name to Gotcha.exe as below:



  • Disable all security programs as they will have a negative effect on Combofix,
  • Close any open browsers and any other programs you might have running
  • Double click the  icon to run the tool (Vista or Windows 7 users right click and select "Run as Administrator)
  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.

*EXTRA NOTES*

  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Quads