Win32.Zafi.B forces mY pc to re-boot!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Zackinator, Feb 2, 2009.

  1. Zackinator

    Zackinator Private E-2

    Hi guys new User here ...I wasn't going to post anthing until I followed the instructions in a previews post on how to get rid of Win32.Zafi.B but when I went to go change my msconfig to normal start up the msconfig window would begin to blink and the pc would reboot!!!

    This has happened twice already and so it seems I cant get it to start on normal start up.

    Please HELP!
     
  2. Zackinator

    Zackinator Private E-2

    Hi again....I was finally able to click on normal start up before the pc rebooted.:-D So no need to reply to the first thread.

    I am wondering why it was doing that ...i finally found out that one shoudn't use msconfig for the long run and instead use Hijack This or Administrative Tools to dissable or remove the start up of programs.

    I do have another BIG concern tho...yesterday when I noticed my internet browsers crashing along with other programs I went on a uninstall programs I didnt need spreeee....and now im findin out that when you do that while not in normal start the programs do not get uninstalled properly!!!

    So it seems im going to have to become a Manual Registry Editing Budah Master...unless anyone else can give me another alternative.

    Please help!!! because I do not want to infect my pc further and it seems I was only locking malware items into my registry. What should I do from here??
     
  3. Zackinator

    Zackinator Private E-2

    Hi again...sry dont mean to bump, but I spent all night doing ALL the steps provided to remove the Win32.Zafi.B and other malware threats given to Chris1h ....now I just have to make sure I am runing Sun Java and Buy Supera.

    Since I am a new user as of yesterday and have had no comments on my thread I will attach the 3 log files from the scans I did and hope for a helpful person to help me determine wether I need to proceed with any other preventive measures.

    Before I conclude this thread I would like to thank CHASLANG for posting that awesome step by step thread on removing malware...THANK YOUUU!!!!!

    PS: This site deserves a two thumbs up waaaay up! Thank you again.;)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any anti-virus program on this computer?

    Use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) 6 Update 2"
    Java(TM) 6 Update 3"
    Java(TM) 6 Update 5"
    Java(TM) 6 Update 7"
    URL Assistant

    Now use windows explorer to find and delete:
    c:\documents and settings\All Users\Application Data\WildTangent
    c:\program files\vghd
    C:\Documents and Settings\Al_Sabid\Application Data\69ed22
    C:\Documents and Settings\Al_Sabid\Application Data\mcs.rma
    C:\Documents and Settings\Al_Sabid\Application Data\nn.gif
    C:\Documents and Settings\Al_Sabid\Application Data\tt.gif
    C:\Documents and Settings\Al_Sabid\Application Data\yy.gif

    Now run CCleaner --> both the cleaner and the registry ( make sure you do the backup when prompted).

    Now tell me what issues you still have.
     
  5. Zackinator

    Zackinator Private E-2

    Hello TimW,

    Thank you for your time...I deleted all the items but before I run CCleaner I want to ask you how I prevent my internet history like saved passwords especially to not be removed?

    The first time I ran CCleaner it erased the password to my main internet account and now I dont remember it lol. Please tell me howto work around this.

    btw...why did I need to delete the Java updates...2, 3, 5,6 and 7?

    and what is the URL assistant?

    Thx
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just uncheck the boxes for what you don't want it to remove.

    It leaves you open to malware. You should always keep your system updated.

    Junk that usually comes on Dell computers that can cause re-directs with your browser.

    And you are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  7. Zackinator

    Zackinator Private E-2

    Hello again...

    I tried to uninstall Combo Fix but all I get is a window that says Prep. incountered a problem...the application needs to close sorry for the inconvinience blah blah blaaaah.

    And at the same time I get a pop up from AVG saying it detected a trojan....Local Settings\Temp\29.tmp\bze.dll

    Trojan Horse Back Door.Small.VX :cry WTF??? I thought I was rid of all the malware...:/

    Btw...its ok if I scan the pc all the time with all the hidden files open rite... ?

    Do I need to replace any of the Java updates with any other ones? cause for some reason it does seem that my browsers have gotten slower than usual at opening.

    And Last but not least...will it slow down my pc in any way if I leave Spybot Searcha & Destroy , Malware Bytes, CCleaner, Supera and Avg installed in my pc?

    Thx TimW
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can manually remove the combo folders.....you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that may have been created.

    Avg is doing it's job. The temp folder is a place that malware often hangs out. :) Every time you get on the web you are subject to infection. That is why you need to keep all protection software updated and use a good firewall.

    There is no need to have the hidden files showing when you scan. You can hide them again.

    You can keep all of those on your machine. AVG could be the reason for your browser being slow. Post in software for info on that. :)
     
  9. Zackinator

    Zackinator Private E-2

    One thing I forgot to ask is ....well ever since I put my pc back to normal start up using the msconfig...it takes my pc like one or two minute to start up like a dozen programs.

    Can you please tell me how to remove aaaall these programs from starting up?? It's really annoying to have to wait for my pc to start up.

    Also can you recommend a really good Firewall I can use..one of my friends told me to use Comodo Firewall with AVG but I didnt really enjoy have to keep unblocking every single connection...half the time I had no idea what it was trying to connect to lol. Thx

    One last question ...this is way off topic but I have a problem with my digital card reader...it wont detect the card from my digital cam anymore:( Im wondering If something may have gotten erased somewhere along the way.


    Thank you for all your help TimW.:)
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. Zackinator

    Zackinator Private E-2

    Unusual pc behavior...

    --------------------------------------------------------------------------------

    Hi again

    ...im just noticing my pc going back to its unusual behavior again from when it was infected by the Win32.Zafi.B...

    This time im not getting the warnings of the worm trojan, instead the computer prevents me from clicking certain things( for example..i cant open the c: drive cant open folders, start-up icons or close windows) and every time I try to get the task manager out I hear a cetain horn sound. just dont know what it means..

    After a minute or two this goes away ...thats the good news ...the bad news is that it's really annoying not being able to operate certain things cause it locks me out.

    Other thing is that the desktop Icons are begining to flicker again when I open My computer (window)mostly.

    A month ago or so I did the scan using combo fix, Malwarebytes, SuperaAntiSpyware, Spybot Search & Destroy, CCleaner, and hijackthis.
    I thought I had gotten everything out cause the pc seemed to operate much smoother but now I dont know what to think.... PLEASE HELP.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest you go back to the Read and Run FIrst instructions and do it all again.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds