Oops, ran ShowNew early

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mycologic, May 2, 2007.

  1. Mycologic

    Mycologic Private E-2

    My computer is infected with something nasty so I've been going through the READ & RUN ME FIRST Malware Removal Guide, but I screwed up. I was on step 4, which says to Download GetRunKey.Zip and ShowNew.Zip, but I missed the part that says not to run them yet(even though they are clearly highlighted).:eek: So I ran Shownew early, do I need to do anything with the text file so that it works when I'm supposed to run it?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You just need to re-run the tools at the point where you are suppose to run them which is after all the other scan have been run. The logs will be over written with the new information.
     
  3. Mycologic

    Mycologic Private E-2

    Another question about the Malware Removal Guide

    I am still working through the steps on the Malware Removal Guide, and I just want to make sure I understand it correctly. I'm at the end of step 5, I have run Counterspy. So am I supposed to run HijackThis! now, but wait to post the log after I complete step 6?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Another question about the Malware Removal Guide

    No! Step 5 makes no mention of HijackThis. HijackThis is not run until step 7 where you install it and run it. You were only supposed to download it previously. You must Complete steps 6A, 6B and 6C before getting to step 7.
     
  5. Mycologic

    Mycologic Private E-2

    Re: Another question about the Malware Removal Guide

    Oops, I'm confused. I meant to say step 4. After the instructions to run Counterspy or AVG Anti-Spyware it says: "Hijack This! – Please do not post HijackThis logs until steps 1 thru 6 are followed and then make sure you follow step 7 to post logs properly as attachments. See: HOW TO: Attach Items To Your Post". It's bold and has a link, so I took that to mean to run it. I know that the instructions for running HijackThis are in step 7, but with Step 7 being titled "HijackThis log posting" I thought that the reference to it in step 4 was when you are supposed to run it, and then wait until step 7 to actually post the log. Argh, my brain is fried, I've been trying to clean my system for a week now, with no success. :cry
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Another question about the Malware Removal Guide

    In your own quote from the READ ME is the key and I'll even emphasize again with bold RED
    Also at the beginning of step 4 it also says
    Step 4 is titled Downloading Tools for this reason! You are only supposed to download, install, and update them here. They are not run until later. The reason for doing this is the later you will be in safe mode and offline while running the scans. Thus they need to be downloaded and installed and updated first before rebooting into safe mode. You don't go back online until step 6 where the online scanners are run.
     
  7. Mycologic

    Mycologic Private E-2

    Ok, well I'm on Step 6B now, and I just ran getrunkey.bat, but I didn't get a file named runkeys.txt, I got 3 files named xrkey00.txt, xrkey01.txt, and xrkey02.txt. What happened, and how should I proceed?
     
  8. Mycologic

    Mycologic Private E-2

    Well I tried running getrunkey again, and this time it worked and gave me the right txt file. Once I complete all the steps should I post the logs in this thread or start a new one?
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member


    This thread please as its an active one.
     
  10. Mycologic

    Mycologic Private E-2

    Ok, here's my story of woe. I was dumb and downloaded a program from a shady sight that turned out to be malware. I ran it, and it dissapeared and my computer went crazy. My computer was running painfully slow, and Internet Explorer kept popping up with ads and stuff; and I don't even use IE, I use Firefox as my browser. So I ran spybot, AVG, and Ad Aware. They kept finding a bunch of cookies and a few trojans like Smitfraud-C and Virtumonde. They would say they cleaned them off, but then they would show up again. Sometimes my computer would run extra slow, and when I opened the task manager it listed IE as a process, though there were no IE windows open. When I shut down my computer it would ask me if I wanted to close SuperMwindows.exe, but I checked and that never showed up in the task manager, and I searched my computer and couldn't find that file. Then when I started windows it gave me an error message saying that the specified module cooykxrk.dll could not be found. So I found Majorgeeks and started working through the Malware Removal Guide, which took me over a week. Somewhere in the process I stopped getting those messages while opening and closing windows, but the pop-ups continued. The same things would show up in many of the scans, but I couldn't eliminate the problem. I got to the end of the guide, and looked at the Special Removal Procedures. I wish I had done that first. Anyways, I used the Virtumonde/Vundo Removal tool, and that seemed to do it. I followed the guide for Smitfraud-C removal, but it didn't turn up so maybe one of the scans finally got it. So my computer seems to be clean since I ran the Vundo tool. When these problems started I Googled SuperMwindows, and found a thread here about it where someone said that it kept downloading Virtumonde onto their computer, so I thought Virtumonde was just a symptom of the greater disease. So all of that to say, should I post my logs, or if I don't get any more IE pop-ups should I just call it good? BTW, thanks for all of the info, working through this techy stuff has fried my brain, but I would have been sunk without it.:clap
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Yes, post your logs. That is the only way we can tell if there is something still lurking on your system.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As Shadow stated, you really need to attach all the logs we requested in the READ ME. I seriously doubt you are clean. Over the last 6 months Virtumonde infections have evolved and VundoFix never completely removes all signs of the infection. It would be in your best interest to follow our directions so we can truly remove all visible malware from your PC.
     
    Last edited: May 6, 2007
  13. Mycologic

    Mycologic Private E-2

    Ok, so here goes. I posted a little bit about the problems I was seeing earlier, and while it seems that the problems have gone away Virtumonde still popped up in a scan last night, so I suspect I still have a ghost in the shell. I will try to explain what happened when I went through the guide and post the logs I got. I was not able to run the online scans in safe mode, and even in normal boot mode Bitdefender didn't work. It ran for 10 hours, and then IE crashed. My IE is buggy and I don't have 7 because I use Firefox as my browser so IE gets neglected.
     

    Attached Files:

  14. Mycologic

    Mycologic Private E-2

    So as you are aware by the way this thread began, I got confused and ran Shownew right after I downloaded it, and then I ran it again when I was supposed to, though it didn't work at first on the second attempt for some reason. I looked through the Special Removal Procedures, and since Virtumonde and Smitfraud-C kept appearing in my scans I tried both of those. I didn't find anything mentioned in the Smitfraud removal guide, but Vundofix found a bunch of infected files. As per the Vundofix instructions, I got a Vundofix log and ran HijackThis. I hope I followed the guide somewhat correctly and my logs are kosher. Thanks for the assistance and let me know if I need to re-do something.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    ShowNew did not run properly! Did you see any error messages?

    I'm going to need a complete log from ShowNew before we can completely remove all of the Vundo related files. However, I will give a fix below to see if we can improve things a little.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now!

    Start by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: metaspinner GmbH - {7C7A8947-5935-4430-AC0E-E7D04697414E} - C:\PROGRA~1\BUYERT~1\IEBUTT~1.DLL
    O2 - BHO: metaspinner GmbH - {CD9B7762-DFBC-42B1-BB30-02A78287B456} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~2.DLL (file missing)
    O2 - BHO: (no name) - {D3837C1E-09AA-401C-9115-2E1149FC0503} - C:\WINDOWS\system32\yfcamxrc.dll (file missing)
    O2 - BHO: (no name) - {E96079A6-2EBB-4F36-9614-47D0B4D6F85D} - C:\WINDOWS\system32\ddccb.dll (file missing)
    O2 - BHO: metaspinner GmbH - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~1.DLL (file missing)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\hewdwmqu.dll",realset
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
    O9 - Extra button: Buyertools Reminder - {27914077-B4D6-4A0E-9763-76B6E9DD9A81} - C:\Program Files\Buyertools Reminder\ReminderIE.exe
    O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
    O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Program Files\Titan Poker\casino.exe (file missing)
    O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll
    O20 - Winlogon Notify: tuvtqpm - tuvtqpm.dll (file missing)
    NOTE: HJT will popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.


    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\ajqciogg.dll
    C:\WINDOWS\system32\hewdwmqu.dll
    F:\Media\discs\kl202e.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But if you do get this message, please let me know!)

    If Killbox does not reboot just reboot your PC yourself.

    Now run Ccleaner!

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew - hopefully it will run all the way this time! Be sure to watch the command prompt window for messages!
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  16. Mycologic

    Mycologic Private E-2

    Wow, thanks for getting back to me so fast. I don't remember seeing an error message when I ran ShowNew, but it did seem kinda slow. I uninstalled Counterspy and downloaded Pocket KillBox. Sorry, I'm feeling kinda dense, but should I run ShowNew first, and then HJT, Pocket KillBox and Ccleaner? Ugh, now I'm feeling really dense, somehow I totally missed the part about the system restore, and I am running WinXP. Doh! In my defense, I have a traumatic brain injury.:banghead I just want to make sure I understand the procedure correctly before I botch something again.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just follow the last procedure I posted exactly in the order written and run ShowNew where I request the log.


    You are not supposed to be touching System Restore at this time.
     
  18. Mycologic

    Mycologic Private E-2

    Ok, I uninstalled Counterspy, and downloaded Pocket KillBox. Then I closed Firefox and ran HijackThis. I have a few questions about HJT though. When I ran it, I didn't see some of the files you said to check, and I saw a few that I think were the same but had a slightly different name. I don't know if this will show up in the log, so I'll list these things here:

    O2 - BHO: metaspinner GmbH - {CD9B7762-DFBC-42B1-BB30-02A78287B456} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~2.DLL (file missing)
    O2 - BHO: (no name) - {D3837C1E-09AA-401C-9115-2E1149FC0503} - C:\WINDOWS\system32\yfcamxrc.dll (file missing)
    O2 - BHO: (no name) - {E96079A6-2EBB-4F36-9614-47D0B4D6F85D} - C:\WINDOWS\system32\ddccb.dll (file missing)
    O2 - BHO: metaspinner GmbH - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - C:\PROGRA~1\PRICEP~1\PRICEP~1\IEBUTT~1.DLL (file missing)

    These files showed up, but they were different. They looked like this:

    O2 - BHO: (no name) - {big-string-of-numbers-and-letters} - (no file)

    The string of numbers and letters were the same as the above files that you listed, so I assumed that they were the same thing and checked them. I also did not see any of the 09 files.

    I did NOT get a PendingFileRenameOperations prompt.

    I think/hope Shownew worked right this time. I will attach the logs I got, and thank God they make more sense to you than they do to me. So how does my system look now, and at what point should I toggle System Restore?
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still have things to fix!

    Uninstall this Windows WMF Metafile Vulnerability HotFix 1.2. You should not need this anymore since Microsoft has long since released updates to fix this problem.

    Also uninstall the below malware:
    WONswap

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: metaspinner GmbH - {7C7A8947-5935-4430-AC0E-E7D04697414E} - C:\PROGRA~1\BUYERT~1\IEBUTT~1.DLL
    O2 - BHO: (no name) - {CD9B7762-DFBC-42B1-BB30-02A78287B456} - (no file)
    O2 - BHO: (no name) - {D3837C1E-09AA-401C-9115-2E1149FC0503} - (no file)
    O2 - BHO: (no name) - {E96079A6-2EBB-4F36-9614-47D0B4D6F85D} - (no file)
    O2 - BHO: (no name) - {E9E027BF-C3F3-4022-8F6B-8F6D39A59684} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [WindowsService] rundll32.exe "C:\WINDOWS\system32\hewdwmqu.dll",realset
    O20 - Winlogon Notify: tuvtqpm - tuvtqpm.dll (file missing)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\hewdwmqu.dll
    C:\WINDOWS\system32\bccdd.tmp2
    C:\WINDOWS\system32\krxkyooc.ini
    C:\WINDOWS\system32\uqmwdweh.ini
    C:\WINDOWS\system32\ygfjsfdh.ini

    Now run Ccleaner.

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.

    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  20. Mycologic

    Mycologic Private E-2

    Are you sure I need to uninstall WONswap? I'm pretty sure it came with Countersrike to locate servers that are running the game.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. Mycologic

    Mycologic Private E-2

    Here's where I'm at now. I uninstalled Windows WMF Metafile Vulnerability HotFix 1.2, but I left WONswap because I'm pretty sure it came with Halflife/Counterstrike. I haven't been able to plat it for a while, but I hope to play it again sometime. Anyway, I ran HJT but didn't see any of the files you listed. I think they got deleted the last time I ran it? I booted into Safe Mode and deleted the files you listed, except I couldn't find: C:\WINDOWS\system32\hewdwmqu.dll. Then I ran Ccleaner, rebooted, and ran Shownew. I'm attaching the latest logs I got. Every time I run Shownew and HJT they write the new logs over the old ones right?
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but when using HijackThis you must make sure that you fix things first and then get a new log. This may explain why you said you did not see the items I just asked you to fix. You may have saved the log before fixing.


    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  24. Mycologic

    Mycologic Private E-2

    Oops, you're right, when I ran HJT I chose the scan and save log option and did not save a new log after fixing the problems. I ran Pocket Killbox and deleted all backups. Then I deleted Pocket Killbox, Vundofix and it's backups folder, ShowNew, GetRunkey, and all of the logs. I disabled System Restore on all drives, though I had to open it up in explorer as the icon on the desktop did not give me the system restore tab. On the link for Disable And Enable System Restore, it says: "disable system restore, reboot, scan for the problem and finally re-enable system restore." So should I run some more scans before I turn System Restore back on to make sure everything is clean?
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not really necessary to run any scans because disabling System Restore deletes restore points, however just to make sure that it was disabled running a full scan with your antivirus and/or a tool like BitDefender online scan could prove useful especially if they had previously showed anything in System Volume Information (which is System Restore).
     
  26. Mycologic

    Mycologic Private E-2

    I rebooted after I turned off system restore, and then I ran a full AVG scan and AVG anti-spyware. AVG didn't find anything and all AVG anti-spyware found were a few cookies. So I turned system restore back on. So have my computer's demons been totally exorcised or should I run HJT or something else again?
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once you have completed all of what I gave you in message # 23 ( including all of the How to protect yourself steps), you are finished, that is unless you are still having malware problems or new malware problems have appeared.
     
  28. Mycologic

    Mycologic Private E-2

    I did everything you said in post #23, and I followed the steps in How to Protect yourself from malware!: I already have WinXP SP2, Windows notifies me of updates automatically, I have AVG, I installed a-squared (a²) Free edition, I'm downloading ZoneAlarmFree and will use that instead of the Windows firewall, I've still got Ccleaner and AVG anti-spyware, Spybot, and Ad Aware, I adjusted the ActiveX settings, I'm a loyal Firefox user, Microsoft Java is uninstalled and I have the latest Sun Java update, my account is password protected and the Guest account is off. So I think my computer is now healthier than it's been in a long time,:celebrate THANK YOU SOO VERY MUCH, :clap YOU GEEKS ROCK!!! :major :dood
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  30. Mycologic

    Mycologic Private E-2

    Ummm, sorry to be a nuisance:eek:, but I've got one last question. I installed ZoneAlarm, but I accidently installed the ZA security suite as I didn't see the option to leave that off. When I go to ZoneAlarm in the start menu, it only list ZA security and it's uninstall. If I uninstall that, will it remove the firewall to? I want the ZA firewall, but not the extra baggage.

    E.T.A. - I just noticed that the ZoneAlarm download is named: "zaSuiteSetup_70_337_000_en.exe". Did I download the wrong thing or did I just install it wrong or am I just confused again?
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to uninstall, reboot, and then start over again.

    ZoneAlarm Internet Security Suite gets installed by default with the free firewall now. This install also includes MailFrontier ( a spam filter). During the installation you should given the choice to have ZoneAlarmFree or ZoneAlarm Internet Security Suite turned on. If you select the free version, all the components of the security suite are suppose to be turned off. I have heard rumors that this sometimes does not work. I have not experimented with this too much myself since I have a paid subscription for ZoneAlarmPro firewall.

    If you run into problems with this, use one of the other free firewalls.
     
  32. Mycologic

    Mycologic Private E-2

    I uninstalled ZoneAlarm Internet Security Suite, rebooted, and tried to reinstall just the firewall. But the download that is linked to in How to Protect yourself from malware! is the installation for the 15 day trial of the security suite and there is no option to use just the firewall. I looked at ZoneAlarm's site and found the link for just the free firewall. it's: http://download.zonelabs.com/bin/free/1025_update/zlsSetup_70_337_000_en.exe
    Once again, THANK YOU, you saved my day. :)
     
  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is not a link to only the free firewall. It is the same file as what you downloaded from the link in the How to Protect thread. Current versions of the free firewall are only available with this internet security suite application. I will have to install this on a PC to see for myself if there is a way to install only the firewall. If not, it will be time to REMOVE ZoneAlarmFree from the How to protect thread. If they continue to pursue the path they are going now, they are going to be put into the bloatware class with Symantec and McAfee.


    There are websites that still have OLDER versions of the firewall only version of ZoneAlarm available, but I'm not sure how long ZoneLabs (now Checkpoint) will allow this.
     
  34. Mycologic

    Mycologic Private E-2

    I'm not sure exactly how it's different, but it is a different download. The link in the How to Protect thread is for the Security Suite 15 day trial. With the other link I gave it is the firewall, and has an antivirus monitoring feature, but it can be turned off. It gives you the option of downloading the security suite, and includes a link to it in the program, but it doesn't come with it.
     
  35. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's strange when I download from the link you gave and from the link in the How to protect thread (which is for ZoneAlarm Free 7.0.337.000 ) I get the exact same file size but a CRC test reveals something is different about the files.

    I need to checkthis out.
     
  36. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    The link he is giving us is the exact same one we use, downloaded and mirrored. Dont know what to tell you.
     
  37. Mycologic

    Mycologic Private E-2

    Hrmm, well the file names are different, and I got different results with both downloads. The file I linked to is zlsSetup_70_337_000_en.exe, and the link from the How to Protect Yourself thread is for zaSuiteSetup_70_337_000_en.exe.

    Edit - Ahah! I think I figured out the confusion. The SuiteSetup download is what you get if you click on the Author's Site link, which is the one I used. The other links through MajorGeeks are all for the file I linked to.
     
    Last edited: May 10, 2007
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that makes more sense now since I could not see any problems after checking it out myself and I never use the authors link. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds