Reply
Contributor
steve2234
Posts: 19
Registered: ‎03-23-2012
Accepted Solution

How to remove Trojan Horse ZeroAccess

I am running windows XP Media Center Edition Version 2002 with Service Pack 3.  It looks like my system has been infected with the Trojan.Zeroaccess!inf.  It seems from the Protection Logs that a number of files have logged as infected.  I have disconnected my computer from the network.  

 

Can someone help me with this problem?

 

Thanks.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: How to remove Trojan Horse ZeroAccess

Re Connect to the internet so that the program can be used as I want it to download it's definitions 

 

Please read carefully

 

1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.

 

Quads

 

Contributor
steve2234
Posts: 19
Registered: ‎03-23-2012

Re: How to remove Trojan Horse ZeroAccess

Ok, I ran the program and attache the log file.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: How to remove Trojan Horse ZeroAccess

X86 system, Ok, and I know the Windows driver involved, just in case.

 

Please read carefully and follow these steps.


Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684  click on the TDSSkiller.exe green link.


Double click on TDSSKiller.exe to run the application,

Open the Change Parameters option and select the detect TDLsystem

Then on Start Scan.


If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back

 

Due to the KB folder still being left behind we will use a different program later.

 

Quads

Contributor
steve2234
Posts: 19
Registered: ‎03-23-2012

Re: How to remove Trojan Horse ZeroAccess

Ok attached is the log file from the TDSKiller.

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: How to remove Trojan Horse ZeroAccess

Ok,  

 

Change the setting beside these entries 

 

01:02:31.0640 5588 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
01:02:31.0640 5588 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

 

to Delete

 

Quads

Contributor
steve2234
Posts: 19
Registered: ‎03-23-2012

Re: How to remove Trojan Horse ZeroAccess

Sorry, I am confused.  Am I suppose to re-run the TDSSkiller again and select delete?

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: How to remove Trojan Horse ZeroAccess

Yes

Contributor
steve2234
Posts: 19
Registered: ‎03-23-2012

Re: How to remove Trojan Horse ZeroAccess

ok done.  

Bot Obliterator
Quads
Posts: 13,250
Registered: ‎07-21-2008

Re: How to remove Trojan Horse ZeroAccess

Now we have to go about finding leftovers (if any exists).

 

Quads