Perhaps the settings were wiped out and initialized to the default? The only thing I suggest you need to do is to use windows explorer and remove these: C:\Documents and Settings\Simon Timperley\Application Data\Ezom C:\Documents and Settings\Simon Timperley\Application Data\Yzcyh Then run CCleaner and Close any open browsers or any other programs that are open.2. This is done by tailoring configuration files that are compiled into the Trojan installer by the attacker. https://forums.malwarebytes.com/topic/124800-trojanzbotrgen-is-it-really-gone/?do=findComment&comment=666861

After doing the above, you should work thru the below link: How to Protect yourself from malware! GEOGRAPHICAL DISTRIBUTION Symantec has observed the following geographic distribution of this threat. In this particular case, Trojan.Zbot also downloaded copies of W32.Waledac.

Functionality This Trojan has primarily been designed to steal confidential information from the computers it compromises.

The message body warns the user of a problem with their financial information, online account, or software and suggests they visit a link provided in the email. Infection The Trojan.Zbot files that are used to compromise computers are generated using a toolkit that is available in marketplaces for online criminals.

I ran ComboFix as instructed and the log is at the end of the post. weblink Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Please copy and paste the contents of that file here.Please download aswMBR to your desktop.Double click the aswMBR.exe icon to run it it will ask to download extra definitions - ALLOW By the way speed is normal now.

Unless you purchase them, they provide no real time protection. http://wpquickadminthemes.com/general/trojan-ci-a.html SafeBoot-WudfPf SafeBoot-WudfRd . . . ************************************************************************** . Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures. Please copy and paste the contents of that file here.If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of

Please re-enable javascript to access full functionality. Using the site is easy and fun. uStart Page = hxxp://www.jw.org/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet have a peek here Completion time: 2012-03-23 17:33:01 ComboFix-quarantined-files.txt 2012-03-24 00:32 .

DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by Paul at 22:54:33 on 2012-03-21 Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.2046.728 [GMT -7:00] .

If you are running Win 7, Vista, Windows XP or Windows ME, do the below: Refer to the cleaning procedures pointed to by step 7 of the READ ME for your CONTRIBUTE TO OUR LEGAL DEFENSE All unused funds will be donated to the Electronic Frontier Foundation (EFF). This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.Double click on combofix.exe & follow the prompts. I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us1.Do not run any other I was freaking out that now some criminals have all my bank login details. Check This Out A couple of questions, if you don't mind. 1.

Malware removal from a National Chain = $149 Malware removal from MajorGeeks = $0 Help Support MajorGeeks Buy Discounted Software @ Majorgeeks Store. This allows a remote attacker to command the Trojan to download and execute further files, shutdown or reboot the computer, or even delete system files, rendering the computer unusable without reinstalling Upon reading other posts on this forum I ran: TDSS Killer and it was clean ATF Cleaner and cleared some junk Rootkit buster (Latest) and it was clean I also ran Goto the C:\MGtools folder and find the MGclean.bat file.

adding a date of birth field to a banking Web page that originally only requested a user name and password). ERROR The request could not be satisfied. Writeup By: Ben Nahorney and Nicolas Falliere Summary| Technical Details| Removal Search Threats Search by nameExample: [email protected] INFORMATION FOR: Enterprise Small Business Consumer (Norton) Partners OUR OFFERINGS: Products Products A-Z Services As requested here is my DDS log: .

Request blocked. C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k Did it remove these entries and, if so will I run into any problems down the road with running VS or. I am attaching RRlog.txt (from RootRepeal) and MGlogs.zip.

A log file should appear. The reports claimed there were as many as 75,000 machines compromised by this newly discovered threat.

I have no idea how I picked up the virus as I am not a typical computer user.