Reply
Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

And 2nd (Extras) log

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Did you do the other steps??

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Yes. All the steps were completed.

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

It appears that one of the Windows drivers MD5 does not match have to investigate, can't find that MD5 number

 

1) you can install that Hotfix now that was uninstalled  http://www.microsoft.com/en-us/download/details.aspx?id=26352

 

 

2) Please download SystemLook and save it to your Desktop.  hxxp://jpshortstuff.247fixes.com/SystemLook.exe  (change hxxp to http)

 

Double-click SystemLook.exe to run it.
Copy the content below between the lines into the main textfield:

 

 

 


:filefind
mrxsmb.sys


 

A log will be produced.

 

Quads

 

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

I didn't reboot after uninstalling the Windows update in the previous step, perhaps that caused some issue?

 

I rebooted, downloaded the Hotfix, rebooted,  and ran the SystemLook as requested.

 

Attached is the log

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

That's better, The MD5 now matches a legit one instead of an unknown, so I won't have to swap over a backup.

 

Now,

 

1) You can't have installed  ESET / NOD32 and Norton on the system at the same time,  go to http://kb.eset.com/esetkb/index?page=content&id=SOLN2289  Read the XP instruction carefully, like about Safe Mode for one.

 

At the same time I will be creating a final script for OTL to clean things up of leftovers and objects used over the last few days. I will also double check for ESET / NOD32 and making sure it's removed.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Can I simply uninstall ESET? It has expired and I usually shut it down.  My Norton is new and up-to-date.

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

I guess I should have read it before asking...

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

The ESET page has the instruction and screenshots on removing their products.

 

Quads

Bot Obliterator
Quads
Posts: 13,979
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Have you finished that removal tool for ESET step??

 

Quads