Go Back   TechArena Community > Technology > Networking & Security
Become a Member!
Forgot your username/password?
Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: , , , ,

Sponsored Links


How to remove TSPY_ZBOT.ARJ malware from my system

Networking & Security


Reply
 
Thread Tools Search this Thread
  #1  
Old 10-02-2010
Member
 
Join Date: Nov 2009
Posts: 585
How to remove TSPY_ZBOT.ARJ malware from my system

Sponsored Links
Hi everybody, I am finding a solution to remove TSPY_ZBOT.ARJ malware from my system. This malware tightly grabbed my system and I am unable to delete it. This malware steals my important data and information from my hard disk and tries to sending this stolen data to the server when I try to connect my system to the internet. Can any provide me solution for this, please?

Reply With Quote
  #2  
Old 10-02-2010
Steve123's Avatar
Member
 
Join Date: Feb 2008
Posts: 2,615
Re: How to remove TSPY_ZBOT.ARJ malware from my system

TSPY_ZBOT.ARJ malware always tries to access a Web site to download and install a specific file. The described file having important information from where this malware can be download an fresh copy of its own, and it knows where to send this stolen important information. This configuration file also having a list of targeted bank-related Web sites from which it steals some important information.
Reply With Quote
  #3  
Old 10-02-2010
Shen's Avatar
Member
 
Join Date: May 2008
Posts: 2,915
Re: How to remove TSPY_ZBOT.ARJ malware from my system

Please try to delete these malware keys from in the registry:
In Registry Editor, in the left panel, do double-click on the below:
HKEY_USERS>.DEFAULT>Software>Microsoft
In the left panel, find and remove the key:
Protected Storage System Provider
In the left panel Registry Editor window, do the double-click on the below:HKEY_USERS>.DEFAULT>Software>Microsoft
Find and remove the following keys:
  • {43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
  • {19127AD2-394B-70F5-C650-B97867BAA1F7}
Reply With Quote
  #4  
Old 10-02-2010
Big Fish's Avatar
Member
 
Join Date: Jan 2006
Posts: 3,742
Re: How to remove TSPY_ZBOT.ARJ malware from my system

TSPY_ZBOT.ARJ malware also generates the given registry entries as component of its installation part:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile
EnableFirewall = "0"

HKEY_USERS\.DEFAULT\Software\Microsoft\
Protected Storage System Provider

HKEY_USERS\.DEFAULT\Software\Microsoft\
Windows\CurrentVersion\Explorer\
{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
{3039636B-5F3D-6C64-6675-696870667265} = "F7 09 F2 0D"
{33373039-3132-3864-6B30-303233343434} = "47 09 F2 0D"

HKEY_USERS\.DEFAULT\Software\Microsoft\
Windows\CurrentVersion\Explorer\
{19127AD2-394B-70F5-C650-B97867BAA1F7}
{23343233-2C66-3B33-3432-343233343233} = "F6 0B F4 0E"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\
CurrentVersion\Network
UID = "{computer name}_{random numbers}"
__________________
Truly, if there is evil in this world, it lies within the heart of mankind. -Edward D. Morrison

Old soldiers never die- they just fade away.
Reply With Quote
  #5  
Old 10-02-2010
Snake08's Avatar
Member
 
Join Date: Apr 2008
Posts: 3,323
Re: How to remove TSPY_ZBOT.ARJ malware from my system

Some other information of TSPY_ZBOT.ARJ malware

This malware having the given SHA1 hash:

* e54e4b4243b04007087c6bd548621e7e87e3e807

This malware having the given MD5 hash:

* 8d89fe43d50db9cefeb97ac1c49a9f80

This malware will these platforms:
  • Windows NT
  • Windows 2000,
  • Windows XP,
  • Windows Server 2003.
Reply With Quote
Reply

  TechArena Community > Technology > Networking & Security


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "How to remove TSPY_ZBOT.ARJ malware from my system"
Thread Thread Starter Forum Replies Last Post
Replaced CCleaner for Advanced system care and malware bytes for IObit Malware Fighter Deshawn Networking & Security 5 01-03-2012 04:27 AM
How to remove TSPY_ZBOT.AZL malware DeMario Networking & Security 5 23-02-2010 04:05 AM
Want to remove TSPY_ZBOT.WL spyware Daniel23 Networking & Security 4 12-02-2010 03:13 AM
How to remove TSPY_ZBOT.PWQZ from my system Cruzz Networking & Security 5 09-02-2010 04:13 AM
Want to remove TSPY_ZBOT.AFT grayware Doroteo Networking & Security 5 07-02-2010 04:34 AM


All times are GMT +5.5. The time now is 10:50 AM.