Inactive System infected: ZeroAccess Rootkit Activity 4 and TidServ Activity 2

It does work! Shall I try to recover ComboFix log (in Safe
Mode) by going to C:\… like you said before?
 
Oh no! I hadn't done anything else yet and got a pop up saying Windows recovered from unexpected shutdown and that it can check for solution online. The problem was a blue screen and it lists the details. Please tell me if you need those as the pop up is still there. It also says it can check for solution or cancel (but this is not safe mode with networking). Before, when I chose safe mode, the option that was highlighted by default was "Repair Computer".
 
You can go for repair (I doubt it'll do anything but it won't break anything so give it a shot).

Let me know how it went.
 
I chose Repair and it wants to do a system restore. Before doing that, computer is waiting for me to select a keyboard layout from different options listed.
 
But the computer is infected. Can I back up my work files from this infected computer? Won't it mess up my clean (not-infected) external hard drive?
 
So then I can't do the system recovery... I can't lose those files without updating their backup first. What do you suggest I should do?
 
I restarted the PC in safe mode and I got combofix log report and saved it to desktop, but this safe mode doesn't have internet.
 
Restart in Safe Mode with Networking to post it.
Alternatively use USB flash drive to move it to a computer you're posting from.
 
Sorry our messages crossed paths. I'm a little confused now. Let's see. To recap, I need to restart infected computer in safe mode with networking; that's clear enough. What confuses me is the flash drive part. What should i do with the usb flash drive? What should I move in there? Please know that at this time that my infected computer (let's call it "PC1") has no antivirus (I uninstalled NIS), I'm using my cell phone to post. I have another computer (clean) ("PC2") that I'm not using (it's not even plugged in) because it's in the same network the infected computer (PC1) and I fear the virus will go there too. Last time I used PC2 was last Friday and PC1 got infected 2 days later.
 
If you can restart in Safe Mode with Networking and post Combofix log from there that's all I need.
 
Back