Jump to content

Trojan.Agent.ZB


dennisl

Recommended Posts

Yes it's there now

 

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.12.19.07

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.16476
NB01 [administrator]

19/12/2013 20:51:45
MBAM-log-2013-12-20 (08-39-18).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 240535
Time elapsed: 11 minute(s), 29 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\System32\YAeEGhx.exe (Trojan.Agent.ZB) -> No action taken.

(end)

 

URL

https://www.virustotal.com/en/file/1ad78156646ad730b7cd9667dcc955868229919df28a94d6c57557a0a82adafa/analysis/1387536298/

Link to post
Share on other sites

  • Replies 72
  • Created
  • Last Reply

Top Posters In This Topic

OK.....

Download aswMBR to your desktop.

http://public.avast.com/~gmerek/aswMBR.exe

Double click the aswMBR.exe to run it.

If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".

Click the "Scan" button to start scan.

On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

MrC

Link to post
Share on other sites

If you don't use this toolbar, please uninstall it: http://www.systemlookup.com/CLSID/64579-Toolbar_dll.html
AddThis Toolbar (Version: 1.514)
Toolbar: HKLM - AddThis Toolbar - {B43176CC-4D9E-493B-A636-D9CBFE39C6DA} - C:\Program Files\AddThis Toolbar\Toolbar.dll ()

------------------------------

Download the attached fixlist.txt to the same folder as FRST.
Run FRST.exe and click Fix only once and wait
The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a Quick Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Download the attached fixlist.txt to the same folder as FRST.

Run FRST.exe and click Fix only once and wait

The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......

Update and run a FULL Scan with Malwarebytes.

Let me know...MrC

Link to post
Share on other sites

Sorry I'm having difficulty getting replies from the person who has the infected computer, due the the extended holiday period here in the UK.

I'll be online again all day through next week, when I'm back at work, & will be able keep contact with him & run through the procedures ,without all these delays.

Thanks for your patience.

Dennis

Link to post
Share on other sites

Use this fixlist.txt:

https://forums.malwarebytes.org/index.php?showtopic=138160&p=772970

Download the attached fixlist.txt to the same folder as FRST.

Run FRST.exe and click Fix only once and wait

The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a FULL Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

I noticed that you xxx out the user name in these two lines:

C:\Users\xxx\Convert.exe
C:\Users\xxx\AppData\Local\Temp\Quarantine.exe


Download the attached fixlist.txt, open it up and edit it to enter the correct user name (save the changes) or the fix won't work!

---------------------------


Download the attached fixlist.txt to the same folder as FRST.
Run FRST.exe and click Fix only once and wait
The tool will create a log (Fixlog.txt) in the folder, please post it to your reply.

Then......

Update and run MB

Let me know...MrC

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.