Submit Your Article Forum Rules FAQ About Us
Search the forums:

Tech Support Team


Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below.



Notices

Reply
  #1 (permalink)   Top
Old 13th March 2008, 01:46 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
[Solved] backdoor trojan win32/zonebac.gen!f

I turned on my computer this morning and windows malware said I had a trojan in the win32/zonebac.gen!f and that it could not remove this I have ran adware spybot ad mcafee and none seem to be able to remove it. Going onto mcafee's website and I couldn't even find this threat listed in their database, unless there is another name for it. I was wondering what should my next step be in trying to remove this from my computer. Thanks in advance for any help.
Reply With Quote
  #2 (permalink)   Top
Old 13th March 2008, 02:50 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Please download FindAWF to your Desktop.
Double-click FindAWF.exe to start the tool.
Select "option #1 - Scan for bak folders" by typing 1 and press Enter
When the tool has completed, a report will open up in notepad. Please post the results of the awf.txt as an attachment.

Also, please post a HJT log.

Regards Howard
Reply With Quote
  #3 (permalink)   Top
Old 13th March 2008, 10:25 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
Attached Files
File Type: txt awf.txt (379 Bytes, 55 views)
File Type: log hijackthis.log (9.8 KB, 52 views)
Reply With Quote
  #4 (permalink)   Top
Old 13th March 2008, 04:15 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Have HJT fix this entry.

O2 - BHO: IE - {D83A7B12-A4D4-4984-8F72-D41C6B4C1E6E} - C:\Program Files\eSoftware\studio.dll

Download combofix.exe to your desktop. Double click combofix.exe & follow the prompts. A window will open with a warning. Type "1" (and Enter) to start the fix. When the scan completes it will open a text window. Please attach that log back here together with a fresh HJT log. Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt

Post the Combofix log as well as a fresh HJT log.

Regards Howard
Reply With Quote
  #5 (permalink)   Top
Old 14th March 2008, 01:50 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
Attached Files
File Type: txt ComboFix.txt (9.5 KB, 482 views)
File Type: log hijackthis.log (10.1 KB, 42 views)
Reply With Quote
  #6 (permalink)   Top
Old 14th March 2008, 02:15 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Unless you know for a fact that this is safe, I suggest you uninstall it and have HJT fix the entry: O2 - BHO: IE - {D83A7B12-A4D4-4984-8F72-D41C6B4C1E6E} - C:\Program Files\eSoftware\studio.dll

Then delete the following directory.

C:\Program Files\eSoftware

Other than that, your logfiles look clean.

Rename HijackThis.exe as follows.

You need to rename HijackThis.exe to Crusty.exe. This is because some malware can hide from HijackThis.exe. Follow these instructions in order to do so.

Go to the C:\Program Files\Trend Micro\HijackThis\HijackThis.exe file and right click on HijackThis.exe. Choose rename. Click in the title box and hit the enter key to clear what`s there.

Now type Crusty.exe into the title box and hit the enter key. Right click on the Crusty.exe file and choose "Send to desktop Create Shortcut".

You can now close the HJT directory.

Post a fresh HJT log and let me know if you`re still having problems.

Regards Howard
Reply With Quote
  #7 (permalink)   Top
Old 14th March 2008, 02:48 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
Attached Files
File Type: log hijackthis.log (9.9 KB, 42 views)
Reply With Quote
  #8 (permalink)   Top
Old 14th March 2008, 02:57 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
That`s clean mate.

I did ask you to let me know if you were still having problems.

Regards Howard
Reply With Quote
  #9 (permalink)   Top
Old 14th March 2008, 10:13 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
I just ran another scan on the windows malicious removal tool and it is still detecting the zonebac backdoor trojan.:frown:
Reply With Quote
  #10 (permalink)   Top
Old 14th March 2008, 12:30 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Ok, can you give me the exact file path to where the WMRT is finding the infection?

I also suggest you run the AVG Antispyware programme as per steps $, 11, 12. Then, post the AVG Antispyware log.

Regards Howard
Reply With Quote
  #11 (permalink)   Top
Old 15th March 2008, 12:44 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
I just found the file path C:\Program Files\Synaptics\SynTP\SynTPLpr.exe I will run AVG antispyware in the mean time
Reply With Quote
  #12 (permalink)   Top
Old 15th March 2008, 12:49 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
The SynTPLpr.exe should be a legit file, though it`s possible it has been infected.

Uninstall and reinstall the Synaptics software and see if the WMRT still finds it. If it does, I would suggest this is a false positive.

Edit: You can also have the file scanned over at Jotti`s.

Please visit this link http://virusscan.jotti.org/
* Click the Browse... button
* Navigate to the following file C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
* Click Open
* Please let me know the results.

Regards Howard

Last edited by Howard; 15th March 2008 at 12:51 AM.
Reply With Quote
  #13 (permalink)   Top
Old 15th March 2008, 01:37 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
jotti.org said that it was infected malware. So the best bet now is to unistall and reinstall the software then?


avg report attached although really nothing there i guess just tracking cookies
Attached Files
File Type: txt Report-Scan-20080314-213620.txt (12.9 KB, 45 views)

Last edited by phreakmi; 15th March 2008 at 01:41 AM.
Reply With Quote
  #14 (permalink)   Top
Old 15th March 2008, 01:46 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Yes, please do the following.

Go to add remove programmes in your control panel and uninstall anything to do with(if there).

Synaptics

Close control panel.

You might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how HERE.

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE.

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

SynTPLpr.exe

Close task manager.

Locate and delete the following bold files and/or folders(if there).

C:\Program Files\Synaptics

Reboot into normal mode and rehide your protected OS files.

Reinstall the software if you need it, but make sure you get it from a legit source.

Let me know how it goes.

Regards Howard
Reply With Quote
  #15 (permalink)   Top
Old 15th March 2008, 02:48 AM
phreakmi's Avatar
Newcomer
 
Join Date: Feb 2008, 20 posts.
Location: Pittsburgh
Reputation: phreakmi is on a distinguished road
everything went well and the wmrt did not find anything with the new scan, Thank you soo much for all your help again howard. It is much appreciated!
Reply With Quote
  #16 (permalink)   Top
Old 15th March 2008, 03:12 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
No problem mate.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.

You may want to have a read of this thread HERE.



If you have any further virus/spyware problems, please post in this thread.

Regards Howard
Reply With Quote
Reply

Only registered members can participate in forum threads. You must register or log in to contribute.


Thread Tools

Forum Jump


All times are GMT. The time now is 09:20 PM.






Post A Question!
Useful Links
Main Menu
Home
Forum Rules
FAQ
About Us
Welcome Pack
Search the forums
TST Mobile
Contact Us
Send Message

These are the 8 most used thread tags
Tag Cloud
geforce modem monitor no ring response no signal nvidia soft modem win7