Reply
Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

here is the output

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

you may have a corrupt netsvcs but you also have a missing driver

 

1.  Download OTL   hxxp://oldtimer.geekstogo.com/OTL.exe   (change the hxxp to http) save it to your Desktop.

Double click on OTL.exe to run it.  Right click OTL.exe and select run as administator for Vista and Win 7.

Click the Scan All Users checkbox.

Change file age to 60 days

under  Copy and paste what is below between the lines


 


drivers32

netsvcs
"%WinDir%\$NtUninstallKB*$." /30
%SYSTEMDRIVE%\*.exe
/md5start
volsnap.sys
atapi.sys
explorer.exe
winlogon.exe
wininit.exe
intelppm.sys

redbook.sys
tdx.sys
afd.sys
/md5stop


 

Press the 

 

 

 

Quads

 

 

 

Post back the  log OTL.txt (attach)

 

2.  Download hxxp://download.bleepingcomputer.com/farbar/FSS.exe  (change the hxxp to http) and run it on the computer with the issue.


Make sure the following options are checked:


Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update


Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

 

With all thouse files I might have to find a free upload site so I can get the zipped quarantine.

 

Quads

 

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

here are the outputs

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

You have 2 drivers missing not one, that I will have to figure is the best way to place them back.

 

Quads

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

alright keep me posted

 

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

Can you get a copy of redbook.sys out of the archive  C:WINDOWS\ServicePackFiles\i386\sp3.cab       redbook.sys

 

And the same for  :intelppm.sys  C:\WINDOWS\ServicePackFiles\i386\sp3.cab   intelppm.sys

 

and place the copies in the C:\Windows\System32\drivers\ folder

 

Quads

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

alright i got both files copied into that folder. now what?

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

Do the same as from these few messages on this thread http://community.norton.com/t5/Norton-Internet-Security-Norton/GOOGLE-REDIRECTS-TO-http-abnow-com/m-...

 

Download Netsvcs reg fix etc. to correct the data.

 

Quads

Contributor
jsold406
Posts: 43
Registered: ‎03-31-2012

Re: infected with trojan.zeroaccess!inf

ok i downloaded the file and ran the registry  fix. do i have to do the combofix thing too?

Bot Obliterator
Quads
Posts: 13,254
Registered: ‎07-21-2008

Re: infected with trojan.zeroaccess!inf

NO

 

OK, Restart your PC, then with the same instructions do this, post, http://community.norton.com/t5/Norton-360/infected-with-trojan-zeroaccess-inf/m-p/692387/highlight/t...

 

If all with the drivers comes back correct then we can start to look at a full system scan and cleanup script.

 

Quads