Zeus Infection - Windows 10 - Need Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Loustar1, Jul 18, 2016.

Tags:
  1. Loustar1

    Loustar1 Private E-2

    F37 specs.JPG Zeus Virus page pic..JPG Hello,
    Attached are two pics. One shows may basic computer setup. The other shows the virus warning I get when I open Microsoft edge. The warning mentions the Zeus virus. I've searched through the MajorGeeks site and tried several of the suggested tools for removing the Zeus virus.

    Malwarebytes Anti Malware - scan found several things - I removed them - but after a reboot the virus still shows up when I open Edge

    ZBot Trojan Remover - from Novirusthanks - after scan it says "Zbot trojan not found on your computer"

    Hitman Pro 3.7 -- found lots of tracking cookies but did not remove the virus

    Kapersky TDSSKiller -- found no threats - possibly because running the other programs earlier.

    Rkill -- below is the log that was generated................................................

    Rkill 2.8.4 by Lawrence Abrams (Grinler)
    http://www.bleepingcomputer.com/
    Copyright 2008-2016 BleepingComputer.com
    More Information about Rkill can be found at this link:
    http://www.bleepingcomputer.com/forums/topic308364.html

    Program started at: 07/18/2016 11:04:39 PM in x64 mode.
    Windows Version: Windows 10 Pro

    Checking for Windows services to stop:

    * No malware services found to stop.

    Checking for processes to terminate:

    * No malware processes found to kill.

    Checking Registry for malware related settings:

    * No issues found in the Registry.

    Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

    Performing miscellaneous checks:

    * Windows Firewall Disabled

    [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    "EnableFirewall" = dword:00000000

    * Reparse Point/Junctions Found (Most likely legitimate)!

    * C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 => C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\INetCache\IE [Dir]

    Checking Windows Service Integrity:

    * No issues found.

    Searching for Missing Digital Signatures:

    * No issues found.

    Checking HOSTS File:

    * No issues found.

    Program finished at: 07/18/2016 11:04:43 PM
    Execution time: 0 hours(s), 0 minute(s), and 3 seconds(s)
    ____________________________________________________________________________________________________________________________________________________

    I finally decided to call the number on the screen to see what the rest of the scam was.

    A man with an extremely Indian/Pakistani sounding voice answered and told me his name "Frank Williams" - after fighting off a laugh I asked who he worked for and if he had an employee ID number ( and yes I know none of it was real but wanted to see where this was going.)

    He said he worked for Microsoft in the tech department. He told me the do the control-alt-delete (which I had already tried and it did close Edge)

    He then wanted me to start menu and hit control key and the "R" key at the same time. It could have been the windows key and the "R" key but I didn't do either.

    Told him I had to run out and asked for his callback number which he seemed all to glad to give to me. I won't post it here.

    So that is where I stand. I think the Zeus may be a decoy OR the virus has a way of preventing most basic anti virus from finding it. I did go into the control panel and allowed computer to show hidden folders but that didn't help either.

    I'm not sure what info you will need from me but I am fully ready to cooperate. As a last note I must point out that non of my other browsers are affected - google chrome - firefox all seem to be working fine.

    Thanks in advance for any assistance you can offer.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes this is a big scam! Please follow the instructions below.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Right click onAdwCleaner.exe and select Run As Administrator unless running Windows XP where you should just double click to run the tool.
      Vista/Windows 7/8/10 users right-click and select Run As Administrator
    • Accept any prompts for permission to run and then click the I agree button to accept the Terms of Use
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, you may just see a popup stating that no malicious programs were found. Just click OK to continue.
    • Now click the LogFile button and the report will open in Notepad.
      (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply. (See: HOW TO: Attach Items To Your Post )
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    Now follow the instructions in the below link so that we can make sure all of this junk is removed from your PC.

    READ & RUN ME FIRST Malware Removal Guide (incl. spyware, virus, trojan, hijacker)
     
  3. Loustar1

    Loustar1 Private E-2

    Hello and thanks for your quick response. Downloaded and ran adwcleaner - it found nothing - log file attached - I'm not very computer savvy with this sort of stuff so I have no basic idea which files are ok or bogus. Will be relying on your skills to sort through. Thanks again for you help and time. I owe you one.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Please continue on with my other instructions to run the READ & RUN ME FIRST.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds