Mobile Devices: Lite Theme Citroën: Citroën Trader | Saxo Trader | C2 Trader Peugeot: Peugeot Trader | 106 Trader Enthusiast: Saxperience


Go Back   Saxperience - Citroen Saxo Forum > Other... > Gaming, IT, Multimedia & Music
Register Member Photo AlbumsBlogs FAQ Calendar Experience

Gaming, IT, Multimedia & Music Please use this forum to discuss Gaming, IT, Multimedia & Music.

Reply
 
Thread Tools Display Modes
Old 13th March 2012, 15:44   #1
Gabbastard
Saxperience Post Whore
Track / Motorsport Prep
 
Gabbastard's Avatar
 
Join Date: Dec 2002
Location: United Kingdom
Posts: 8,390
iTrader Score: 16 (100%)
Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!
Default Fixing infected windows files?

Just got my laptop hammered by Zbot. no idea how I got it, I dont even use the laptop for porn sites!

Anyway, quite a lot of infected windows files, leading to programs not opening etc. Any idea how to fix these? I got a prompt about it last night while running the antivirus, sayinig I should put in the windows install disc to correct the files, but not had it since.
Gabbastard is offline   Reply With Quote
Old 13th March 2012, 15:46   #2
Barry123
Saxperience Hardcore!
Track / Motorsport PrepContent ContributorCentral South Region MemberNorth East Region MemberYorkshire Region Member
 
Barry123's Avatar
 
Join Date: Oct 2005
Location: Aycliffe
Posts: 32,205
Car(s): Saxo VTS
iTrader Score: 7 (100%)
Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!Barry123 is absolutely fabulous!
Default

I'd do the lazy boy approach. Get another computer and make sure it's up to date. Back up what you need and nothing else.

Format the laptop and start again.
Barry123 is offline   Reply With Quote
Old 13th March 2012, 15:57   #3
Brettles1986
Saxperience Post Whore
South Wales Region Member
 
Brettles1986's Avatar
 
Join Date: Aug 2010
Location: Little Mill, South Wales
Posts: 7,547
Car(s): Mondeo ST TDCI Saxo VTS
Brettles1986 is on a distinguished road
Default

Quote:
Originally Posted by Barry123 View Post
I'd do the lazy boy approach. Get another computer and make sure it's up to date. Back up what you need and nothing else.

Format the laptop and start again.
Very often this is the best approach, more so for your re-assurance than anything. Alternatively this, starting at step six:

http://www.bleepingcomputer.com/forums/topic34773.html
__________________
Quote:
Originally Posted by Giraffe View Post
I'm happy being a north easternly smoggie bender.
Brettles1986 is offline   Reply With Quote
Old 18th March 2012, 09:06   #4
markj_vtr
Infrequent Poster
 
Join Date: Apr 2007
Location: West Sussex
Posts: 134
Car(s): VTS with minor mods (Rotrex C30-74 etc)
markj_vtr is on a distinguished road
Default

Best way is to google and dowload/run the following:

rKill (this doesnt remove any malware just closes it if its running)
Combofix (you have to un-install/disable your anti virus)
Gmer (good call by Brettles1986)
Malware bytes
and finally give it a scan with your anti virus
All are free and easy to use
That will get rid of the majority of malware if it doesn't then it wipe/reload time.
markj_vtr is offline   Reply With Quote
Old 19th March 2012, 16:38   #5
Manu
Saxperience Addict
 
Manu's Avatar
 
Join Date: Dec 2009
Posts: 11,709
Car(s): A4 SE/A6 Le Mans
Manu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of light
Default

run ms-dos and enter the following command


c: format *.*



then reinstall.
Manu is offline   Reply With Quote
Old 19th March 2012, 22:28   #6
Brettles1986
Saxperience Post Whore
South Wales Region Member
 
Brettles1986's Avatar
 
Join Date: Aug 2010
Location: Little Mill, South Wales
Posts: 7,547
Car(s): Mondeo ST TDCI Saxo VTS
Brettles1986 is on a distinguished road
Default

What's the wildcard part all about? And formatting in dos wont do anything when the file system is being used I believe
__________________
Quote:
Originally Posted by Giraffe View Post
I'm happy being a north easternly smoggie bender.
Brettles1986 is offline   Reply With Quote
Old 20th March 2012, 09:27   #7
Manu
Saxperience Addict
 
Manu's Avatar
 
Join Date: Dec 2009
Posts: 11,709
Car(s): A4 SE/A6 Le Mans
Manu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of light
Default

Yeah, I should have been more specific: exit windows and go to dos then run the command line. Within windows, the file is being run from the ram. I have done this a few times in the past. It is more secure in the sense that most recent viruses run within windows.

[though there is a couple of old viruses called pacman and cascade, they would run within dos through the ram and delete the whole hard drive, beginning with their own system file, effectively deleting themselves first - no trace. What happened was you had either pacman going across your screen eating whatever is in front or the contents of your desktop falling to the bottom of the screen. While you're being mesmerized, your hard drive empties itself and the only solution is to pull the plug and do some damage limitation]

and it actually formats the drive. As opposed to a reinstall windows which does not actually erase everything, only reinstalling what isn't there (I'm saying this since Zbot creates command lines within win32 then spreads to most system and administrator files, steals your passwords and creates remote trojans - 'tis a nasty little shit and my guess is OP opened a zip file through some spam email or downloaded from pirate sites). For instance try leaving a few files in your bin then do a full reinstall, the files will be there once you have completed the reinstall. This is why a format is safer because you could always have some root files left.

NB: before wiping it all out, make sure you have all your drivers and recovery discs, otherwise you're in for a headache + change all your passwords from another computer before yours is safe. The purpose of this virus is to steal your bank details.

Last edited by Manu; 20th March 2012 at 09:39.
Manu is offline   Reply With Quote
Old 20th March 2012, 10:08   #8
tokyodrifte
Frequent Poster
 
Join Date: Mar 2010
Posts: 632
iTrader Score: 2 (100%)
tokyodrifte is on a distinguished road
Default

Insert install DVD - Format HDD - Reinstall

__________________
-
tokyodrifte is offline   Reply With Quote
Old 20th March 2012, 10:12   #9
Manu
Saxperience Addict
 
Manu's Avatar
 
Join Date: Dec 2009
Posts: 11,709
Car(s): A4 SE/A6 Le Mans
Manu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of light
Default

^^^ that sums it up perfectly.
Manu is offline   Reply With Quote
Old 20th March 2012, 10:20   #10
Brettles1986
Saxperience Post Whore
South Wales Region Member
 
Brettles1986's Avatar
 
Join Date: Aug 2010
Location: Little Mill, South Wales
Posts: 7,547
Car(s): Mondeo ST TDCI Saxo VTS
Brettles1986 is on a distinguished road
Default

Or using the recovery partition which is most likely dependant on the age of the laptop, this is accessed by a specific key press sequence on boot up.
__________________
Quote:
Originally Posted by Giraffe View Post
I'm happy being a north easternly smoggie bender.
Brettles1986 is offline   Reply With Quote
Old 20th March 2012, 10:38   #11
Manu
Saxperience Addict
 
Manu's Avatar
 
Join Date: Dec 2009
Posts: 11,709
Car(s): A4 SE/A6 Le Mans
Manu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of lightManu is a glorious beacon of light
Default

Quote:
Originally Posted by Brettles1986 View Post
Or using the recovery partition which is most likely dependant on the age of the laptop, this is accessed by a specific key press sequence on boot up.
Honestly, since this is Zbot, I'd do a full format, that shit does rewrite some of your system files but also drivers (.dll). I consider it serious since it's goal is to steal your bank details and upload them on a server for some cunt to pick it up and get free money.
Manu is offline   Reply With Quote
Old 29th March 2012, 11:12   #12
Gabbastard
Saxperience Post Whore
Track / Motorsport Prep
 
Gabbastard's Avatar
 
Join Date: Dec 2002
Location: United Kingdom
Posts: 8,390
iTrader Score: 16 (100%)
Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!Gabbastard is a great team player!
Default

Yeah I just ended up formatting the whole shebang after resetting all my passwords through another laptop.

Only remotely dodgy site I can think of that I have visited was a TV streaming website that Ive been using for years without a problem.

Cheers all
Gabbastard is offline   Reply With Quote
Old 29th March 2012, 11:37   #13
Brettles1986
Saxperience Post Whore
South Wales Region Member
 
Brettles1986's Avatar
 
Join Date: Aug 2010
Location: Little Mill, South Wales
Posts: 7,547
Car(s): Mondeo ST TDCI Saxo VTS
Brettles1986 is on a distinguished road
Default

for future reference:

www.apetube.com
www.tubekitty.com
www.pornhub.com

__________________
Quote:
Originally Posted by Giraffe View Post
I'm happy being a north easternly smoggie bender.
Brettles1986 is offline   Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:00.