Zipclix

Discussion in 'Malware Help (A Specialist Will Reply)' started by aldago, Apr 15, 2007.

  1. aldago

    aldago Private E-2

    Some time ago I found the malware Zipclix on my computer. I closed System Restore and removed every trace I could find anywhere on the computer including the registry. Now when I scan there is no malware connected with Zipclix that shows up. However, during each scan the scanner reports it is scanning in C:\Program Files\Zipclix and the scanner stays at that spot for several minutes. Anyone know if that reference to Zipclix is real or a ghost and how I can get rid of it?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi


    Do you have a folder at that location C:\Program Files\Zipclix in program files? if so delete it.
     
  3. aldago

    aldago Private E-2

    Hi Halo,
    Love your sexy picture. To answer your question there's no zipclix folder in Program Files. I've tried showing all hidden files, doing a Windows search and a desktop search with no results. I've tried deleting all my cache files in both IE and Firefox as well as quarantined folders in all my spyware searches. It still shows up. I don't think it's causing a problem but I'm really perplexed and don't like to ignore things I can't find a solution for. I hope someone at this site can help. Thanks for your reply.
    aldago
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    First time my piccy has been called sexy so thanks :)


    But what scanners are you using or which one picks this up?

    Have you run a cleanup app such as CCLeaner to clean up all junk files and clean the registry?


    Other than those steps above I would then run our guide, as a second opinion and attach all the logs requested.


    Our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  5. aldago

    aldago Private E-2

    Thanks again Halo. I was hoping that there was a simple answer and what you suggest seems like a bit much for something that's not really causing a problem. My primary spyware scanner is Xoftspy by Paretologic but I also run Spybot and Ad-aware and I have Spyware Guard and Spyware Blaster running (as you probably can tell I'm on the internet quite a bit and try to stay pretty careful). To get rid of unwanted residue in the Registry I find files via Regseeker and/or RegCleaner from jv16 tools. I did run Ccleaner and after checking the files it found I deleted them. Anyhow, thanks again. I hope I don't have to talk with you soon but if I have a problem I'll quote the Terminator "I'll be back."
    aldago
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    For easier removal instructions it wouldnt be a bad thing to check these registry locations and delete of you have them:


    HKEY_CURRENT_USER\Software\Zipclix
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Zipclix
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{319A68DB-06D0-46DA-9F93-A810D5A70836}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EC34A4B3-809A-4A71-88D4-55B5183D6041}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{BBCD25C8-A31E-4DFB-B204-B54BBA477B23}
     
  7. aldago

    aldago Private E-2

    Thank you so much. Actually, the first steps I took to get rid of Zipclix was what you listed. But, lo and behold, I redid that because of your suggestion and most of the zipclix and registry entries were back. I did run all my spyware stuff with System Restore turned off and in fact some of it in Safe Mode. Would you still suggest I run HijackThis and post the log??
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to complete all of the instructions Halo gave you in message # 4 and attach all 6 logs. HijackThis should be the last thing run.

    I also have a question! In your first message you say
    What scanner? Please always be specific in what you post. Vague responses will lead to vague and incomplete/incorrect instructions. Are you referring to Xoftspy which is well know for having false positive issues & seems to have lots of problems removing what it says it finds, which is why we have never recommended it! Is this a paid program or a free trial?
     
  9. aldago

    aldago Private E-2

    Sorry if I was obscure. I am using the Xoftspy scanner and I was not aware that there were problems with the results they come up with. The registry entries for zipclix were present and I removed them by searching for them in the registry and deleting them. And, as I mentioned previously, they returned. I've also run in Safe Mode and with System Restore off. Actually, the Xoftspy scanner is also reporting Murlo Trojan which it claims it removes but doesn't really. I've also scanned with Spybot and Ad-aware and several online scans which do not report any of the above even though I did find the registry entries for zipclix. At this point I'm going to retry all of the steps in the "read me first" page and then download a trial of Kaspersky for a complete scan. Do you agree with that as the next move???
     
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi, No just follow whats written in the guide and do not install the trial of Kaspersky as at this point its not needed, all we need are the scans listed in the guide run all steps in the order given and attached the logs when finished:)

    Also attach a log from XoftSpy if it still detects problems! And please answer the question chas asked, "Is XoftSpy a paid version or a free trial?"
     
    Last edited by a moderator: Apr 18, 2007

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds