Win32/Zbot.gen!Y

Fiery

Member
MSE keeps saying I have the above in my PC, I have removed it, quarantined it, ran Malwarebytes, Ad-Aware. Run my updates, and yet MSE still keeps giving me the RED balloon :mad:.

I have cleaned my C:\Users\Fiery_WA\AppData\Local\Temp, using CCleaner, yet still this damn balloon keeps popping up.

It particularly likes to pop up after a reboot, which has me stuffed, although at random times it also pops up.

HELP!!
 

Attachments

  • potential threat.jpg
    potential threat.jpg
    288.7 KB · Views: 85
  • MSE.jpg
    MSE.jpg
    88.4 KB · Views: 55
  • Temp.jpg
    Temp.jpg
    71.1 KB · Views: 45

My Computer

System One

  • Manufacturer/Model
    Homebuilt
    CPU
    AMD Phenom II x 4 965
    Motherboard
    Gigabyte GA-MA770T-UD3P
    Memory
    4GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX 750 TI
    Sound Card
    Creative Sound Blaster X-Fi Xtreme Audio
    Monitor(s) Displays
    Phillips 19"
    Screen Resolution
    1280 x 1024
    Hard Drives
    1 x 128GB Samsung 840 Pro SSD
    1 x 1TB Sata
    1 x 160GB IDE
    1 x 2Tb WD External My Book Elite
    1 x 1TB WD External My Book Elite
    1 x 4TB WD External My Book
    PSU
    Thermaltake 850W XT
    Case
    Coolermaster Storm Sniper Black Edition
    Cooling
    AC-ALPINE-64PRO ARTIC COOLING
    Keyboard
    12 year old Compaq, cant see any of the letters anymore :)
    Mouse
    Microflacid Sterile
    Internet Speed
    ADSL2+
    Other Info
    My husband and I divorced over religious differences.. He thought he was God and I didn't.
Welcome
Since members have their own area of expertise, I will notify our security expert. She is away for a day or two, but you will be helped.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
In preparation for her, can you do the following for us please:

OTL

Download OTL to your desktop.
Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
When the window appears, underneath Output at the top change it to Minimal Output.
Under the Standard Registry box change it to All.
Check the boxes beside LOP Check and Purity Check.
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



Once OTL has completed its first scan it will save notepad copies of the scans in the folder that OTL was started from. Unless set to produce an Extras log it will only produce OTL.txt in subsequent scans.

A copy of an OTL fix log is saved in a text file at

:\_OTL\MovedFiles
in most cases this will be C:\_OTL\MovedFiles

CKScanner

CKScanner:

Please download CKScanner from here to your Desktop.

Make sure that CKScanner.exe is on the your Desktop before running the application!

Double-click on CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved
Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.

RSIT

Please download Random's System Information Tool by random/random from here and save it to your desktop.

Make sure that RSIT.exe is on the your Desktop before running the application!

Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open:
log.txt will be opened maximized.
info.txt will be opened minimized.
Please post the contents of both log.txt and info.txt.

Please post back with all of the logs from these programs :)

Tom

Edit: Please attach the text files of the logs with your next post, not copy and paste the contents (there will be a lot of text!)
 

My Computer

System One

  • Manufacturer/Model
    Build #1
    CPU
    Intel Core i7 3770K @4.4GHz
    Motherboard
    ASUS P8Z77-V PRO
    Memory
    Corsair Vengeance 2x4GB DDR3 1600MHz Low Profile (White)
    Graphics Card(s)
    Gigabyte Radeon HD 7850 (2GB GDDR5)
    Sound Card
    Integrated on motherboard
    Monitor(s) Displays
    23" LG LCD/LED IPS
    Screen Resolution
    1920*1080
    Hard Drives
    Samsung EVO 128GB SSD
    Seagate Barracuda 2TB 7200rpm
    2x500GB Seagate FreeAgent 5400rpm
    PSU
    Corsair TX650W V2 (80+ Bronze)
    Case
    NZXT Phantom 410
    Cooling
    Corsair H100 Water Cooler, 1x140mm and 1x120mm stock fans
    Keyboard
    Microsoft Desktop 2000 Wireless Keyboard
    Mouse
    Microsoft Desktop 2000 Wireless Mouse
    Internet Speed
    95 Mb/s Download 70 Mb/s Upload
CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11
----- EOF -----

Done?
 

Attachments

  • Extras.Txt
    50.4 KB · Views: 60
  • OTL.Txt
    108.5 KB · Views: 53
  • ckfiles.txt
    116 bytes · Views: 49
  • info.txt
    29.8 KB · Views: 93
  • log.txt
    31.7 KB · Views: 65

My Computer

System One

  • Manufacturer/Model
    Homebuilt
    CPU
    AMD Phenom II x 4 965
    Motherboard
    Gigabyte GA-MA770T-UD3P
    Memory
    4GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX 750 TI
    Sound Card
    Creative Sound Blaster X-Fi Xtreme Audio
    Monitor(s) Displays
    Phillips 19"
    Screen Resolution
    1280 x 1024
    Hard Drives
    1 x 128GB Samsung 840 Pro SSD
    1 x 1TB Sata
    1 x 160GB IDE
    1 x 2Tb WD External My Book Elite
    1 x 1TB WD External My Book Elite
    1 x 4TB WD External My Book
    PSU
    Thermaltake 850W XT
    Case
    Coolermaster Storm Sniper Black Edition
    Cooling
    AC-ALPINE-64PRO ARTIC COOLING
    Keyboard
    12 year old Compaq, cant see any of the letters anymore :)
    Mouse
    Microflacid Sterile
    Internet Speed
    ADSL2+
    Other Info
    My husband and I divorced over religious differences.. He thought he was God and I didn't.
I restored my OS back to a previous time prior to virus. Got no idea where it came from though :confused:

I cannot remember how to mark the thread as closed :cry:
 

My Computer

System One

  • Manufacturer/Model
    Homebuilt
    CPU
    AMD Phenom II x 4 965
    Motherboard
    Gigabyte GA-MA770T-UD3P
    Memory
    4GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX 750 TI
    Sound Card
    Creative Sound Blaster X-Fi Xtreme Audio
    Monitor(s) Displays
    Phillips 19"
    Screen Resolution
    1280 x 1024
    Hard Drives
    1 x 128GB Samsung 840 Pro SSD
    1 x 1TB Sata
    1 x 160GB IDE
    1 x 2Tb WD External My Book Elite
    1 x 1TB WD External My Book Elite
    1 x 4TB WD External My Book
    PSU
    Thermaltake 850W XT
    Case
    Coolermaster Storm Sniper Black Edition
    Cooling
    AC-ALPINE-64PRO ARTIC COOLING
    Keyboard
    12 year old Compaq, cant see any of the letters anymore :)
    Mouse
    Microflacid Sterile
    Internet Speed
    ADSL2+
    Other Info
    My husband and I divorced over religious differences.. He thought he was God and I didn't.
PWS:Win32/Zbot.gen!Y is a generic detection for a password stealer and remote access trojan.
Change all your passwords using a known, clean computer... not from the infected one!

P2P.... BitTorrent DNA

It's really important, if you value your PC at all, to stay away from P2P file sharing programs, like utorrent, Bittorrent, Azureus, Limewire, Vuze.
Criminals have "planted" thousands upon thousands of infections in the "free" shared files.
Some of the recent infections can turn your machine into a doorstop.
It's also very important to avoid any "cracks" or "Keygens" that allow unauthorized use of programs.
Besides being illegal, these files also are loaded with "planted" malware
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
See Fiery,
Its worth the wait for one of the best. Follow her instructions and you will be ok.

TY Jacee:)
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
PWS:Win32/Zbot.gen!Y is a generic detection for a password stealer and remote access trojan.
Change all your passwords using a known, clean computer... not from the infected one!

P2P.... BitTorrent DNA

It's really important, if you value your PC at all, to stay away from P2P file sharing programs, like utorrent, Bittorrent, Azureus, Limewire, Vuze.
Criminals have "planted" thousands upon thousands of infections in the "free" shared files.
Some of the recent infections can turn your machine into a doorstop.
It's also very important to avoid any "cracks" or "Keygens" that allow unauthorized use of programs.
Besides being illegal, these files also are loaded with "planted" malware

Yes I understand that P2P programmes can let in nasties, however I hadn't used Bittorrent in months, I check all of my emails using webmail first so as not to download anything undesirable, I am just confused as to how I got it in the first place :confused:.

Quick question from the reading I have been doing the zbot is after passwords for online banking, since I have done a system restore to two months prior to getting this zbot. Is it safe for me to now consider my PC clean?

MSE was the first to notify me of the zbot, since my system restore, I have run MSE, and it shows no signs of the zbot.
 

My Computer

System One

  • Manufacturer/Model
    Homebuilt
    CPU
    AMD Phenom II x 4 965
    Motherboard
    Gigabyte GA-MA770T-UD3P
    Memory
    4GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX 750 TI
    Sound Card
    Creative Sound Blaster X-Fi Xtreme Audio
    Monitor(s) Displays
    Phillips 19"
    Screen Resolution
    1280 x 1024
    Hard Drives
    1 x 128GB Samsung 840 Pro SSD
    1 x 1TB Sata
    1 x 160GB IDE
    1 x 2Tb WD External My Book Elite
    1 x 1TB WD External My Book Elite
    1 x 4TB WD External My Book
    PSU
    Thermaltake 850W XT
    Case
    Coolermaster Storm Sniper Black Edition
    Cooling
    AC-ALPINE-64PRO ARTIC COOLING
    Keyboard
    12 year old Compaq, cant see any of the letters anymore :)
    Mouse
    Microflacid Sterile
    Internet Speed
    ADSL2+
    Other Info
    My husband and I divorced over religious differences.. He thought he was God and I didn't.
Quick question from the reading I have been doing the zbot is after passwords for online banking, since I have done a system restore to two months prior to getting this zbot. Is it safe for me to now consider my PC clean?
I wouldn't trust my machine with the same passwords. Definitely change all of them using another 'known' clean computer.... Not the one your using now!


Let's see if ESET finds anything.....

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Here is the ESET scan results, no other anti virus has ever listed these, what is Win32/TrojanDownloader.Small.PAC trojan?:confused:

Since the zbot scare I have since uninstalled MSE and am trialling paid for Internet Security Suites.

I have been on the internet for 14 years, I always use to use PC-Cillin up until the GUI became icky, that's when I switched over to KIS 2010 ,upgraded it to 2011, but that started random BSOD.

I occasionally had a nasty knock on my door, but my AVS always kept them out.

Right up to MSE, when my first ever virus slipped in.

To date I have trialled Bitdefender Internet Security, Comodo, and currently have ESET Smart Security installed. However as it keeps giving me Win32/TrojanDownloader.Small.PAC trojan for things like my GPU Driver's which I downloaded straight from Nvidia, and also Microsoft Genuine Validation tool.

I am going to uninstall it, and try Webroot. The winner to date is Bitdefender.

Will keep you posted :)
 

Attachments

  • ESET.txt
    10 KB · Views: 77

My Computer

System One

  • Manufacturer/Model
    Homebuilt
    CPU
    AMD Phenom II x 4 965
    Motherboard
    Gigabyte GA-MA770T-UD3P
    Memory
    4GB DDR3
    Graphics Card(s)
    Nvidia GeForce GTX 750 TI
    Sound Card
    Creative Sound Blaster X-Fi Xtreme Audio
    Monitor(s) Displays
    Phillips 19"
    Screen Resolution
    1280 x 1024
    Hard Drives
    1 x 128GB Samsung 840 Pro SSD
    1 x 1TB Sata
    1 x 160GB IDE
    1 x 2Tb WD External My Book Elite
    1 x 1TB WD External My Book Elite
    1 x 4TB WD External My Book
    PSU
    Thermaltake 850W XT
    Case
    Coolermaster Storm Sniper Black Edition
    Cooling
    AC-ALPINE-64PRO ARTIC COOLING
    Keyboard
    12 year old Compaq, cant see any of the letters anymore :)
    Mouse
    Microflacid Sterile
    Internet Speed
    ADSL2+
    Other Info
    My husband and I divorced over religious differences.. He thought he was God and I didn't.

My Computer

System One

  • Manufacturer/Model
    HP-Pavilion m9280.uk-a
    CPU
    2.30 gigahertz AMD Phenom 9600 Quad-Core
    Motherboard
    ASUSTek Computer INC. NARRA3 3.02
    Memory
    3582 Megabytes Usable Installed Memory (4 Gig)
    Graphics Card(s)
    ASUS NVIDIA Geforce GTS450
    Sound Card
    Realtek High Definition 7.1 Audio (HP drivers)
    Monitor(s) Displays
    HP w2408 24.0" (Dual monitor)
    Screen Resolution
    1920 * 1200, 1920 * 1200
    Hard Drives
    3*500 Gigabytes Usable Hard Drive Capacity
    Plus 2x USB (160Gig each) external HDD
    BluRay & DVD Weiters
    HL-DT-ST BD-RE GGW-H20L SCSI CdRom (Bluray RW) Device
    AlViDrv BDDVDROM SCSI CdRom (Blueray) Device
    TSSTcorp CDDVDW TS-H653N SCSI CdRom
    Internet Speed
    40 Meg
Download Combofix from any of the links below, and save it to your desktop.<--Important
Link 1
Link 2
Link 3

Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
Next: Disconnect from the internet. If you are on Cable or DSL, unplug your computer from the modem.
Next: Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working.
This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Please be patient while the scan runs, at times it may appear to stall.
When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
Post this log in your next reply.
After rebooting ensure your Security applications have been re-enabled.

In your next reply post:
ComboFix.txt
***A guide and tutorial on "How to use Combofix" can be found here:
A guide and tutorial on using ComboFix

IF CF won't run:
During the download, rename Combofix.exe to sVchost.exe
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Back
Top