Reply
Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012
Accepted Solution

Yet Another Zeroaccess!inf Infection

Long time user of Norton Anti-Virus Corporate Edition.  Recently downloaded a 15 day trial of Norton Ant-virus at the site and installed. It has identified Zeroaccess!inf.  Coincidence that the Corporate edition could not find it but as soon as I download the trial version I get infected or is the new Norton Anti-Virus more sophisticated and found it where the Corporate Edition could not?  Anyway, Norton Eraser cannot remove so I need help getting rid of it.  MalWare Bytes does not find it nor does Sybot S&D.  I am also running Zone Alarm Firewall.  Computer is Windows XP Home Edition, Dell Dimension 4600.  I am an experienced computer user.  Any experts available to help?   

Symantec Employee
dkane
Posts: 18
Registered: ‎08-25-2009

Re: Yet Another Zeroaccess!inf Infection

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

Do not use the standalone tool on it until you know the variant or if you have the likes of MaxSS, Pihar or other Malware also.

 

How many times do the likes of myself and Malware Removal forums have to say???????

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Too late.........tried the tool first thing as that is what the Norton Anti-Virus recommends.  Where do I go from here?

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

Do you Competely  remove SEP (corp version) before installing Norton??

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Yes

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

What is the name and location of the file(s) detected??

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

From Norton Insight.  Two instances.

 

Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02ce86a42}\rp906\a0115953.dll

Threat: Trojan.Zeroaccess!inf

 

 

Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02ce86a42}\rp902\a0113427.dll

Threat: Trojan.Zeroaccess!inf

Bot Obliterator
Quads
Posts: 13,259
Registered: ‎07-21-2008

Re: Yet Another Zeroaccess!inf Infection

[ Edited ]

Hmmmmm, interesting for a reason.

 

Did you have no other detection from Norton or SEP, or other program for zeroaccess in the system32 folder in the past??

 

maybe that is still hiding. We may fully check the system like I do for the other threads to make sure everything is cleaned of leftovers etc.

 

Quads

Contributor
Retired_USAF
Posts: 33
Registered: ‎05-09-2012

Re: Yet Another Zeroaccess!inf Infection

Not that I recall.  Believe the first I saw of it was with the downloaded Norton.  Looking at the path, I see "restore".  Does that mean it got loaded into an XP restore point at some time?  Both have a filed modified date of  4/13/2008 (if that means anything)