05-10-2012 07:20 PM
The location really is not the real important piece here as the copies would have been backed up from system files originally and that is what we have to track down, where have they gone.
Please do not run any tools unless instructed to do so.
Please read every post completely before doing anything.
Please read carefully
a) Uninstall Spybot S&D, also if Malwarebytes has it's realtime componant running, Uninstall Malwarebytes also.
Quads
05-10-2012 07:29 PM
Just noticed auto protect added another instance at 21:09
Full Path: c:\system volume information\_restore{77b878ba-823e-498a-9a54-a1d02
Threat: Trojan.Zeroaccess!inf
05-10-2012 07:30 PM
That's OK, Just do my first instruction above.
Quads
05-10-2012 07:47 PM
Both have been unistalled. S&D required a reboot, so took awhile.
05-10-2012 07:52 PM
I may ask for both scans first to try and figure out what is going on for those files to be created.
Here is the first
Please read carefully
1. Please download aswMBR hxxp://public.avast.com/~gmerek/aswMBR.exe to your desktop. (replace the hxxp with http)
Double click the aswMBR.exe icon to run it
it will ask to download extra definitions - ALLOW IT / Yes
Click the Scan button to start the scan
On completion of the scan, click the save log button, save it to your desktop and Please attach the log in the post back, Don't have the program fix anything.
Quads
05-10-2012 08:21 PM
Well, it said scan finished successfully so I guess it was done. Log attached.
05-10-2012 08:34 PM
Found at least some more of it, hmmm have to be careful as a driver with this variantion can go missing, I am thinking.
In the meantime, and the scan can take some time
Please read carefully and Slowly
Please scan with ESET next Using Internet Explorer
I'd like us to scan your machine with ESET OnlineScan
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it.
Quads
05-11-2012 05:18 AM
That sure was a long scan. It said ZoneAlarm and Norton Anti-virus may interfer with the scan so I turned those off during the scan.
05-11-2012 12:55 PM
Please read carefully and follow these steps.
Download TDSSKiller from http://support.kaspersky.com/faq/?qid=208280684 click on the TDSSkiller.exe green link.
Double click on TDSSKiller.exe to run the application,
Open the Change Parameters options and select the Detect TDLFS File System
Then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please attach the log in the post back.
Quads
05-11-2012 04:35 PM
Didn't seem to find anything. Log attached.
