07-04-2012 02:20 AM
Hi there,
I just try to get rid of the ZA. Tried the Norton Removal Tool FixZeroAccess.exe - didn't work.
Norton Auto-Protect warns me and blocks ZA constantly.
I would have some problems to set up my system all over again.
I read some other threads and hope, someone can guide me through Find/Break/Destroy/CleanUp...
Thanks,
Florian
Solved! Go to Solution.
07-04-2012 02:26 AM
Well, sorry, I forgot to tell you my OS:
Windows Vista (Business) 32-bit
07-04-2012 05:18 AM
Do you have a Flash drive?
07-04-2012 08:26 AM
Yes, I have.
And if don't find the stick, well, then it's time to buy a new one ;-)
07-04-2012 09:29 AM
Download http://www.bleepingcomputer.com/download/farbar-re
Save it on a flash drive
Plug the flashdrive into the infected PC.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
Restart the computer.
As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
Use the arrow keys to select the Repair your computer menu item.
Select English as the keyboard language settings, and then click Next.
Select the operating system you want to repair, and then click Next.
Select your user account an click Next.
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Select Command Prompt
In the command window type in notepad and press Enter.
The notepad opens. Under File menu select Open.
Select "Computer" and find your flash drive letter and close the notepad.
In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
The tool will start to run.
When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the flash drive. Please Attach it to your reply
07-04-2012 12:13 PM - edited 07-04-2012 12:19 PM
ANY other user other than the thread starter is not to use any instructions, scripts or proceedures, The work though in cleaning a system is individual and only for that system due to a number of factors.
Please do not run any tools unless instructed to do so.
1. Find
2. Break
3. Destroy
4. Cleanup (including system as a whole)
Please read every post completely before doing anything.
)
The instructions are highlighted for a reason, you can wipe the hard drive doing the wrong one, that is what happens with pretenders
Read Slowly and all of it.
Please download http://www.bleepingcomputer.com/download/farbar-re
Transfer it on to the Flash Drive.
Enter System Recovery Options.
To enter System Recovery Options from the Advanced Boot Options:
On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
Quads
07-04-2012 01:37 PM
Here is the log-file...
07-04-2012 01:41 PM
I notice you have startup links disabled, do you not want them in startup??
Quads
07-04-2012 01:45 PM
I read through the log-file - and there are some lines I'm really not amused about. I try to keep my system as clean as (for me) possible. After removing ZA, I'll have to clean up some old mess...
07-04-2012 01:47 PM
No, I don't want them in startup - at least some of them. The system starts up very slowly. Disabling of some of the entries seemed to be a helpful solution to me. Some programs just write themselves into the startup-list.
