StopZilla, more?

Discussion in 'Malware Help (A Specialist Will Reply)' started by jk469, Apr 6, 2009.

  1. jk469

    jk469 Private E-2

    I *believe* I have StopZilla running (I see SZServer.exe running, and can't kill it), and am unable to remove it. I am also intermittently having other problems with random webpages popping up.

    I tried following the general cleanup procedure. SuperAntiSpyware and Malwarebytes Anti-Malware would not run on my computer. I attach the logs for combofix and MGTools.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. jk469

    jk469 Private E-2

    Note: since my original post I disables Szserver.exe using services.msc. (STOPzilla Service still appears in services.msc, listed as startup type disabled.) I also manually deleted any files I could that I could identify with STOPzilla.

    I ran Avenger as suggested; the log is attached. After looking at the log myself, I manually deledted the STOPzilla! folder.

    I ran MGtools; the logs are attached.

    Please advise!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good that you caught that. :)

    Now lets just be rid of two things.

    If you are still unable to run Combo, we need to use Avenger again:

    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  5. jk469

    jk469 Private E-2

    (Note: ComboFix *did* run...I never had problems with that...)

    I did as you suggested. Here are the logs. Thanks for your continued help!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is ZoneAlarm the full suite including anti-virus protection? (If not you need to install one)>

    Your logs are clean...though you need to download and install:
    Java Runtime 6.

    What issues are you still having?
     
  7. jk469

    jk469 Private E-2

    My only remaining issue is that "STOPzilla Service" still shows up when I run services.msc. (But it is disabled, so I guess this is not a big deal.)

    Also, I have already installed Java Runtime 6...why?

    Thanks again for your help. I would love to hear about any sites where one can learn the more technical details about protecting Windows.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your last log did not show any Java installed, which is why I asked you to install it.

    Look in the services for the stopzilla name...then:

    Open notepad and copy and paste the following text in the quote box into the window:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds