Major malware problem that will not go away

Status
Not open for further replies.
Hey Victor

My final question is is there anyway to block/detect the WIn32/Zbot backdoor?

Apart from that, thank you greatly for all your time and help!
 
Your're welcome, I'm happy to help. :)

AndyUK said:
My final question is is there anyway to block/detect the WIn32/Zbot backdoor?
Spybot S&D and Malwarebytes Anti Malware is good at detecting it.

The best way to avoid getting your computer infected with any malware is to keep everything updated (Windows, Java, Adobe, any security software and any other installed application) as described in my post here: http://forums.spybot.info/showpost.php?p=378256&postcount=54
+ Update and run scans with your anti virus and Malwarebytes regularly.

It is also wise to avoid "destructive" behavior while using the computer online. Please read the following post and, if applicable, learn from it
http://forums.spybot.info/showpost.php?p=22806&postcount=4


Install and use Spybot Search & Destroy for the added protection
Instructions are located here. Make sure you update, reimmunize & scan regularly.


Enable Teatimer option in Spybot Search & Destroy (if you forgot to enable it during the install)
  • Open Spybot S&D.
  • Click Mode, choose Advanced Mode.
  • Go To the bottom of the Vertical Panel on the Left, Click Tools.
  • then, also in left panel, click Resident (shows a red/white shield).
  • If your firewall raises a question, say OK.
  • In the Resident protection status frame, check the box labeled Resident "Tea-Timer"(Protection of over-all system settings) active.
  • OK any prompts.
  • Click Mode, choose Default Mode.
  • Use File, Exit to terminate Spybot.
  • Reboot your machine for the changes to take effect.


Make use of the HOSTS file included with Spybot Search & Destroy
Every version of windows includes a hosts file as part of them. A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites
Spybot Search & Destroy has a good HOSTS file built in, to enable the HOSTS file in Spybot Search & Destroy.
  • Run Spybot Search & Destroy.
  • Click on Mode, and then place a tick next to Advanced mode.
  • Click Yes.
  • In the left hand pane of Spybot Search & Destroy, click on Tools, and then on Hosts File.
  • Click on Add Spybot-S&D hosts list.

Note: On some PCs, having a custom HOSTS file installed can cause a significant slowdown. Following these instructions should resolve the issue:
  • Click Start > Run
  • Type services.msc & click OK
  • In the list, find the service called DNS Client & double click on it.
  • On the dropdown box, change the setting from automatic to manual.
  • Click OK & then close the Services window.

For a more detailed explanation of the HOSTS file, click here.

Please do not use MVPS Hosts or any other hosts file if you use Spybot's hosts file. Do not use Winpatrol if you use Teatimer.


I will now ask for this thread to be archived.

Safe Surfing! :)
 
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.

Note: If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send me a private message (pm). A valid, working link to the closed topic is required.

If you have been helped and wish to donate to help with the costs of this volunteer site, please read :
Your donation helps improving Spybot-S&D!
 
Last edited:
Status
Not open for further replies.
Back
Top