Zeus Ransomware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by lazaruss, Nov 27, 2016.

  1. lazaruss

    lazaruss Private E-2

    Hello

    A friend of mine was fooled by the zeus ransomware virus. He paid the £100 "yearly protection subscription" and even allowed someone to remotely connect to his computer to remove it.

    I have no idea what this person would have done while they had access to his machine so was wondering if there were any other steps I should perform other than what is in the "READ & RUN ME FIRST Malware Removal Guide" thread?

    Thanks
     
  2. lazaruss

    lazaruss Private E-2

    Also, the instructions say not to run CCleaner if any icons are missing? My friend said there were icons missing on his desktop after the person remotely connected to his machine, should I miss the CCleaner step?
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Please skip the running of CCleaner for now and upload the five requested logs.
     
  4. lazaruss

    lazaruss Private E-2

    Please find attached log files as requested. CCleaner was not ran as recommended.
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Re-run Hitman Pro, enable/activate the free trial and allow it to remove all the PUPs it finds.

    Please download ZHPCleaner to your desktop.
    • Close all applications (including your web browsers and antivirus)
    • Double-click on ZHPCleaner to run the tool.
    • If you are using Windows Vista, 7/8/10; instead of double-clicking, right-mouse click ZHPCleaner and select "Run as Administrator".
    • Please click the "J'accepte/I agree" button.
    • First press the "Scanner" button. Be patient, the scan takes longer than 5mins.
    • Do NOT fix/repair anything yet! Please upload that logfile with your next reply.
    Now download the latest version of Farbar Recovery Scan Tool and save it to your desktop.

    Note: Make sure you download the correct version ( 32 bit or 64 bit ) for your PC. Only the correct version will run so if you make a mistake and download the wrong one, go back and get the other.
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press the Scan button and wait.
    • The first time the tool is run it makes two logs, FRST.txt and Addition.txt in the same directory the tool is run.
    • Please upload them in your next reply.
     
  6. lazaruss

    lazaruss Private E-2

    Hello

    Please find attached requested log files.

    Thanks
     

    Attached Files:

  7. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Re-run ZHPCleaner per previous instructions
    • After the scan has completed - press the Repair button.
    • Browsers will automatically shut down.
    • A logfile will automatically open after the scan has finished.
    • Please upload that logfile with your next reply.
    NOTE: This script was written specifically for this user for use on this particular computer. Running this on another machine may cause damage to your operating system.
    1. Save the attached (fixlist.txt) to your desktop.
    2. Right-click FRST(x32/64) and select Run as Administrator.
    3. Click the FIX button once.
    4. Wait while FRST processes fixlist.txt
    5. A report should pop up named Fixlog.txt, please upload it here in your next reply.
    As a last scan, you could go here ==> https://www.eset.com/us/online-scanner/ and click on the SCAN NOW radio button > save the esetonlinescanner_enu.exe Binary file to your Desktop > then right-click and choose "Run as Administrator". *Be patient! The scan can take 2 hours or more.
     

    Attached Files:

    Last edited: Nov 30, 2016
  8. lazaruss

    lazaruss Private E-2

    Sorry for the late reply but please find attached requested log files. I believe ZHPCleaner picked up a few more virus since the first time I scanned.

    I will also run the online virus scanner after posting this thread.
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds