Reply
Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Yes. ESET is now removed.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Start OTL,   under   Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom)  and run the script. (Red Run Fix Button)

 

The output log, should be placed in the C:\ _OTL folder after.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Here is the log

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

You had a FakeHDD (FakeAV) over the top at some stage,  

 

Do you have all your Desktop and Program (Start Menu) shortcut items and folders shifted back in place??

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

The Startup is fine. The desktop icons where all placed to the left side of the screen the other day and I moved them back.  They are in place and haven't moved since then.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

I noticed by this

  


C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\2
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Windows PowerShell 1.0
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Windows Digital Media Enhancements
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\System Recovery
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Startup
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Spybot - Search & Destroy
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Sonic\DigitalMedia Projects
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Sonic
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Seagate\Seagate Manager
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Seagate
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Quicken 2006
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Online Services\United States
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Online Services
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\NetWaiting
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Netscape
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\My HP Games
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\muvee Technologies\muvee autoProducer 5.0
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\muvee Technologies
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Works
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office\Microsoft Office Tools
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Microsoft Office
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\MediaImpression 2.0 for PENTAX
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Maptech Terrain Navigator
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\LightScribe Direct Disc Labeling
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\iriver\Music Manager
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\iriver
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP Rhapsody
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP\PSC All-In-One 1500 series
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP\Photosmart C6200 series
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP\HP Smart Web Printing
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP\HP Photosmart Essential 2.01
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\HP
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Google Updater
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Google SketchUp 6
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Google Earth
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Garmin
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Games
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\FREE Hi-Q Recorder
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\ESET\ESET NOD32 Antivirus
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\ESET
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\energyXT2
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Creative\Sound Blaster X-Fi Go! Pro\Documentation
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Creative\Sound Blaster X-Fi Go! Pro
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Creative
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Carbonite
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\ArcSoft Connect
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\AIM
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Administrative Tools
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\System Tools
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Microsoft Interactive Training
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Media Center\Media Center Programs
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Media Center
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Entertainment
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\Communications
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories\
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs\Accessories
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1\Programs.
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\1
C\DOCUME~1\owner\LOCALS~1\Temp\smtmp\4


 

Once the Quarantine folder is deleted they are gone. So to check the,

 

The smtmp\2 should have copied across the items to C:\Documents and Settings\user_name\Application Data\Microsoft\Internet Explorer\Quick Launch  Folder (if exists) 

 

The smtmp\1  should have copied across the items to C:\Documents and Settings\All Users\Start Menu Folder

 

The smtmp\4  should have copied across the items to C:\Documents and Settings\All Users\Desktop Folder

 

Quads

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Are you satisfied that the start menu Programs folder is all in order??

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

The appropriate shortcuts/files appear to be in those locations.

Bot Obliterator
Quads
Posts: 13,255
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

OK

 

Then Start OTL and then this time click the Black "CleanUp" button.   It should delete itself and the C:\_OTL folder.

 

Once the _OTL folder is also deleted you are free to go on your merry way.  You are now fixed / Solved.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Awesome. Thanks very much!!!!