Author Topic: aswMBR found Win32:Zbot-QGP  (Read 3220 times)

0 Members and 1 Guest are viewing this topic.

Jahcson

  • Guest
aswMBR found Win32:Zbot-QGP
« on: February 06, 2013, 11:58:00 AM »
I have the following files now:
OTL
Extras
mbam-log-2013-02-06 (04-34-46)
aswMBR
AdwCleaner[S1] says: [OK] Registry is clean. AND [OK] File is clean.

This is the first day I noticed Avast would not operate normally, I tried the FIX NOW button to no avail. As circumstance would have it today seems to be the due date for my renewal, which is odd since I bought this new PC in May 2012 with Avast included in the bundle. Either way I reapplied for a new Avast registration but used my Facebook account to do this just a few hours ago. For what it's worth I did stumble on a link a couple months ago which did try to put a scare in me with a scam. I believe Java was used to infect me. I also uninstalled Java a few hours ago. I did see an Avast page detailing how to prevent Java in browsers and I do intend to reinstall Java with no browser integration eventually if I may. I do dislike Java overall but it seems so prevalent these days it's nearly impossible to not run into it.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: aswMBR found Win32:Zbot-QGP
« Reply #1 on: February 06, 2013, 12:14:34 PM »
malware removers are notified, check back later today

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMBR found Win32:Zbot-QGP
« Reply #2 on: February 06, 2013, 02:53:33 PM »
The MBAM entry was for a rootkit downloader, however nothing else is apparent on the system

Is Avast working now

Did you knowingly install Jdownloader 

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Files
C:\Users\Admin\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\1ede2ede-55762f34
:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
« Last Edit: February 06, 2013, 03:10:44 PM by essexboy »

Jahcson

  • Guest
Re: aswMBR found Win32:Zbot-QGP
« Reply #3 on: February 06, 2013, 04:09:57 PM »
Hi, Mr. essexboy, thanks for helping me with my dilemma.  ;)
Is Avast working now
No, sorry to say, Avast still says its service is stopped.

Did you knowingly install Jdownloader
Matter of fact I tried installing it like 3 or 4 days ago - was having the darnest time with it too, it just wouldn't install properly on my Windows 7, so I uninstalled it and chucked that bad idea out of my head. I guess it's a residue of it maybe, then ?  ???

Side note, I use Firefox, I don't like Internet Explorer, but have been considering more and more using Google Chrome. Your opinion matters since I want the better protection against infections, so, - should I switch to Chrome or is Firefox just as reliable ?  ::)

There appeared a first text file from OTL upon Reboot which I am sending along with the Quick Scan you asked me to do after the Reboot.
Open OTL again and click the Quick Scan button.

I just double checked with my Avast once more, the FIX NOW button still did not start Avast. Tried a right click to enable all shields (7 disabled) unsuccessfully. Task-bar message to solve PC issue - Virus Protection (Important) Turn On Now button could not start them either.  :'(

Not really crying over here, not really worried since you seem to have my back ! Just wanting to make your day a little brighter with a little funny - so take this  ;D

I did uninstall Jdownloader but I just noticed it's still in my C:\Program Files (x86)\JDownloader
I just looked in my control panel and Jdownloader is not there, though.
Not gonna do it unless I am advised, of course, but eventually that JDownloader folder will have to be deleted - but I will wait for confirmation before I do anything else !
« Last Edit: February 06, 2013, 05:10:45 PM by Jahcson »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMBR found Win32:Zbot-QGP
« Reply #4 on: February 06, 2013, 05:17:26 PM »
OK I will remove Jloader for you and tidy up a bit

For Avast there appears to be a glitch on some systems .. This should cure it, reboot after running 
I suggest to download the latest full update package from here and apply it. The "Fix" button should work then.

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
O8:64bit: - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlall.htm ()
O8:64bit: - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlselected.htm ()
O8:64bit: - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlfvideo.htm ()
O8:64bit: - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dllink.htm ()
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free-Download-Manager_v309\dllink.htm ()
O9 - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\VideoGet_v40254_Nuclear-Coffee\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
O9 - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\VideoGet_v40254_Nuclear-Coffee\Plugins\VideoGet_IE.dll (Nuclear Coffee Software)
[2013/01/16 05:21:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\JDownloader
[2013/02/06 02:40:46 | 000,001,604 | ---- | M] () -- C:\Users\Admin\Desktop\Java Control Panel.lnk
[2013/02/02 09:26:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Free Download Manager

:Files
C:\Program Files (x86)\JDownloader

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Jahcson

  • Guest
Re: aswMBR found Win32:Zbot-QGP
« Reply #5 on: February 06, 2013, 05:41:43 PM »
JDownloader is now gone from --> C:\Program Files (x86)\ :)

Avast still unsecured, you probably know this already since you were aiming for Jloader and were apparently successful - you be the judge.

20 minutes later...................

O.K. so I was a little distracted by I don't know what but now I also download the latest full update package and applied it then rebooted the system and now - as you may have guessed - Avast! is all happy and green and says my system is SECURED and fully protected !

Only one question now, if I may, since I have 119 days remaining yet, and since I already reapplied for a new Avast registration using my Facebook account just a few hours ago can the switch-over be finalized in some way or does my Avast! already remember that I reapplied a few hours ago ?

What happens if things stay the way they are and in 3 months when my 119 days run out will I still be able to use my Facebook account to register, if that is what I choose, or will I run into a problem claiming that the Facebook account was already used to register with them ?

THANK-YOU - HAVE A GREAT DAY - WONDERFUL - HAPPY I AM
« Last Edit: February 06, 2013, 06:21:46 PM by Jahcson »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMBR found Win32:Zbot-QGP
« Reply #6 on: February 06, 2013, 07:29:35 PM »
As it is the free version then registration is not a problem

Any further outstanding problems before I tidy up ?

Jahcson

  • Guest
Re: aswMBR found Win32:Zbot-QGP
« Reply #7 on: February 07, 2013, 05:49:35 AM »
Sorry for the delay, but things looked good last I saw before shutting down 10 or 12 hours ago.

When I booted-up for a new day today Avast! was, as we say when all looks really good, golden !

Everything seems Excellent! GREEN signals from Avast! all across the board.

It was an honor to be so well taken care of - I haven't personally taken time to talk with someone at solving a PC issue over the net like this in well past what could be 5 years.

Thank goodness it happens rarely - Must be cause there's such great software out there nowadays to prevent PC disasters - Avast! 5 Stars.

My best to you for helping make this the kind of world it is meant to be, friendly, helpful, and safe.
« Last Edit: February 07, 2013, 05:51:26 AM by Jahcson »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: aswMBR found Win32:Zbot-QGP
« Reply #8 on: February 07, 2013, 02:33:41 PM »
Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:


Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article and this article.
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

If you use on-line banking then as an added layer of protection install Trusteer Rapport

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected Keep safe  :wave: