Reply
Visitor
green15
Posts: 7
Registered: ‎04-26-2012
Accepted Solution

virus detected but unable to remove

          I have scanned the file with norton.  It detects it as a virus

      Trojan.Zeroaccessinf2.  It says manual removal required  I scanned in

      safe mode. It says manual removal required.

 

 I clicked on the link

      to take me to manual removal instructions.  I downloaded the manual

      removal tool.  It says no viruses found yet security suite says its

      still there.

 

 I followed step 2 and used NPE.  I then follwed step 3

      and used Norton Bootable recovery tool.  Both say removal failed and

      to manually remove it.

 

 At this point Im not sure if its even a

      virus since it was part of a windows patch in the following directory:

      C:\WINDOWS\$NtUninstallKB2536276-v2$

 

File name was:  mrxsmb.sys

 

 I am running the comcast

      version of norton which has been updated to version 5.2.1.3 with

      latest definitions

 

I submitted the file to norton falss positives website and they responded contact technical support.

 

Bot Obliterator
Quads
Posts: 13,248
Registered: ‎07-21-2008

Re: virus detected but unable to remove

In x86 systems zeroaccess patches a legit Windows driver so Norton is not allowed to delete the driver,   

 

Quads

Visitor
green15
Posts: 7
Registered: ‎04-26-2012

Re: virus detected but unable to remove

Thank you for the response.

 

But what should I do next?  I have the original xp disk.  Is there a way to fix this?

 

thanks!

Newbie
bsodZeroaccess
Posts: 3
Registered: ‎04-28-2012

Re: virus detected but unable to remove

I would suggest downloading Hitman pro, it's able to detect this rootkit as it has just done it now in my Virtual Machine.

 

http://www.surfright.nl/en/hitmanpro/

 

Also, get: http://www.malwarebytes.org/

Super Spam Squasher
cgoldman
Posts: 2,929
Registered: ‎06-25-2008

Re: virus detected but unable to remove


bsodZeroaccess wrote:

I would suggest downloading Hitman pro, it's able to detect this rootkit as it has just done it now in my Virtual Machine.

 

http://www.surfright.nl/en/hitmanpro/

 

Also, get: http://www.malwarebytes.org/


The problem here is not detection but correction or replacement of the infected file. Since for example malwarebytes specifically does not address rootkits, I do not endorse your suggestion.

Visitor
green15
Posts: 7
Registered: ‎04-26-2012

Re: virus detected but unable to remove

I solved the problem by going into safe mode and uninstalling hot fix patch KB2536276-v2$.  I then rebooted into safemode went to the microsoft site and redownloaded the hot fix and installed it in safe mode and the virus infected file was overwritten.  Windows update did not work in safemode thats why i had to manually download the hotfix.  Now the scans come up clean.

 

Thaks to everyone that tried to help