Reply
Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012
Accepted Solution

Another Zeroaccess!inf infection

I am using Windows XP professional with Service Pack 3 on an Compaq V6000 (x86). Norton picked up the Zeroaccess infection and recommends manual removal.  It looks like I have 2 infected files:

 

C:\windows\system32\tshwmdtcp.dll

C:\windows\system32\parport.dll

 

 

Any  help would be appreciated.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Please do not run any tools unless instructed to do so. 

  • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.

Please read every post completely before doing anything. 

  • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.



 

Please read carefully

 

1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Attached is the log file.

 

I did not run any Tools, but Norton AutoProtect was on.  The AutoProtect did pop up a message regarding backdoor.tidserv while scanning.  Do I need to disable or Uninstall Norton and rescan? I also have SpyBot and Malwarebytes (and an outdated ESET package) installed.

 

Thanks for the help.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Uninstall Spybot S&D

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

I have uninstalled Spybot and rebooted.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Ok, and I know the Windows driver involved, just in case.

 

Please read carefully and follow these steps.


Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684  click on the TDSSkiller.exe green link.


Double click on TDSSKiller.exe to run the application,

Open the Change Parameters option and select the detect TDLsystem

Then on Start Scan.


If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

I did the scan and it found two "threats" . The default action is delete. Should I delete?

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

What are they as you have not given a log.

 

Quads

Contributor
BudBullets
Posts: 20
Registered: ‎05-04-2012

Re: Another Zeroaccess!inf infection

Sorry, I wasn't sure if "cure" was the same as "delete" as a default option.

 

Backdoor.Multi.ZAccess.gen

Service:lvsrvlauncher

 

Backdoor. Multi.Zaccess.gen

Service: venturi2

 

Both with default action set to Delete.

Bot Obliterator
Quads
Posts: 13,260
Registered: ‎07-21-2008

Re: Another Zeroaccess!inf infection

Yes you can have TDSSkiller delete the 2 services, It's similar to the Oak Technology version.

 

Quads