05-02-2012 05:00 PM
I am running windows XP Media Center Edition Version 2002 with Service Pack 3. It looks like my system has been infected with the Trojan.Zeroaccess!inf. It seems from the Protection Logs that a number of files have logged as infected. I have disconnected my computer from the network.
Can someone help me with this problem?
Thanks.
Solved! Go to Solution.
05-02-2012 05:12 PM
Re Connect to the internet so that the program can be used as I want it to download it's definitions
Please read carefully
1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.
Quads
05-02-2012 07:29 PM
Ok, I ran the program and attache the log file.
05-02-2012 07:49 PM
X86 system, Ok, and I know the Windows driver involved, just in case.
Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link.
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters option and select the detect TDLsystem
Then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back
Due to the KB folder still being left behind we will use a different program later.
Quads
05-02-2012 10:14 PM
Ok attached is the log file from the TDSKiller.
05-02-2012 10:21 PM
Ok,
Change the setting beside these entries
01:02:31.0640 5588 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
01:02:31.0640 5588 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip
to Delete
Quads
05-02-2012 10:50 PM
Sorry, I am confused. Am I suppose to re-run the TDSSkiller again and select delete?
05-02-2012 10:51 PM
Yes
05-02-2012 10:54 PM
ok done.
05-02-2012 10:58 PM
Now we have to go about finding leftovers (if any exists).
Quads
