Resolved: Troj/Zbot-LA >I think I'm still infected

Status
Not open for further replies.
Making progress

I think I've exterminated the email problems. If you agree, I'll proceed with your cleanup instructions in message #24.

Thanks,
Nostrada
 

Attachments

  • log.txt
    1.4 KB · Views: 2
Outstanding! Whew! That was a job! I do note the following is still present. Did you include it in the move I set up?

C:\Program Files\PestPatrol\Quarantine\20070407233801.zip

It's been quarantined so is no threat to you. You might want to look into deleting the PP quarantined items.

To finish the cleanup of the cleaning tools, add this:
Remove all of the tools we used and the files and folders they created
  • DownloadOTCleanIt by OldTimer
  • Save it to your Desktop.
  • Double click OTCleanIt.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes.

If you are prompted to Reboot during the cleanup, select Yes.

You've will have already uninstalled Combofix and dropped the old restore points. You should be in pretty good shape now.

A reminder: be careful opening email from someone you don't know. Be very careful if opening attachments and forwards. Friends don't count here- most don't realize they're sending an infected file. IF you do get an attachment that you want to open, do a right click> Save to desktop first. Once there, do a right click> scan with AV before opening. That's not a guarantee but it's better than just opening from within the email!

You worked hard an did a good job! Let me know if you need more help in the future.
 
Yes- do 1,2,and 3. Skip 4. Look for the one Pest Patrol file in their quarantine folder and just delete it there.

Then finish with OTCleanIt in post 27.

Then site back and feel good about a job well done! Stay safe!
 
Maybe the end?

I did the first three steps of message #24.
> S-1-5-21-2246190073-3047704572-2931419171-1006
was an 85 byte file that appeared to be empty. I couldn't remove it.
>I didn't do the Outlook Express step since I had already cleaned out OE.
> I didn't do OTMoveIt.

I did OTCleanIt (message #27)

I think I'm all done. A new ESET log is attached.

I could send a donation to the ComboFix guy if you think I should.

Many thanks, you've been great!
Nostrada
 

Attachments

  • log.txt
    784 bytes · Views: 1
Got to love those clean logs!

I left one thing out of the Recycler delete> the Recycle Bin has to be empty or the Recycler Folder cannot be deleted. Try doing that, then double click on the number string in the Recycler. You can do a right click> delete on each of the files.

Are you asking if you should send a donation to Combofix? I don't know what you mean by 'the guy'. But no donations are needed.
 
I think I'm done ?!?

Here is my -- I hope -- final ESET log. Note that there are 2 logs in the LOG.TXT file. Am I done?

Thanks.

You and Techspot are the greatest!
 

Attachments

  • log.txt
    1.6 KB · Views: 1
Another clean log! Congratulations! You are done and I will make the problem Resolved.

Let us know if we can be of help in the future.
 
Status
Not open for further replies.
Back