05-09-2012 01:49 PM
Long time user of Norton Anti-Virus Corporate Edition. Recently downloaded a 15 day trial of Norton Ant-virus at the site and installed. It has identified Zeroaccess!inf. Coincidence that the Corporate edition could not find it but as soon as I download the trial version I get infected or is the new Norton Anti-Virus more sophisticated and found it where the Corporate Edition could not? Anyway, Norton Eraser cannot remove so I need help getting rid of it. MalWare Bytes does not find it nor does Sybot S&D. I am also running Zone Alarm Firewall. Computer is Windows XP Home Edition, Dell Dimension 4600. I am an experienced computer user. Any experts available to help?
Solved! Go to Solution.
05-09-2012 02:16 PM
Did you try the standalone fix tool?
http://www.symantec.com/security_response/writeup.
05-09-2012 04:52 PM
Do not use the standalone tool on it until you know the variant or if you have the likes of MaxSS, Pihar or other Malware also.
How many times do the likes of myself and Malware Removal forums have to say???????
Quads
05-09-2012 08:27 PM
Too late.........tried the tool first thing as that is what the Norton Anti-Virus recommends. Where do I go from here?
05-09-2012 08:31 PM
Do you Competely remove SEP (corp version) before installing Norton??
Quads
05-10-2012 07:15 AM
Yes
05-10-2012 11:42 AM
What is the name and location of the file(s) detected??
Quads
05-10-2012 06:58 PM
From Norton Insight. Two instances.
Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02
Threat: Trojan.Zeroaccess!inf
Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02
Threat: Trojan.Zeroaccess!inf
05-10-2012 07:04 PM - edited 05-10-2012 07:06 PM
Hmmmmm, interesting for a reason.
Did you have no other detection from Norton or SEP, or other program for zeroaccess in the system32 folder in the past??
maybe that is still hiding. We may fully check the system like I do for the other threads to make sure everything is cleaned of leftovers etc.
Quads
05-10-2012 07:12 PM
Not that I recall. Believe the first I saw of it was with the downloaded Norton. Looking at the path, I see "restore". Does that mean it got loaded into an XP restore point at some time? Both have a filed modified date of 4/13/2008 (if that means anything)
