Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Suspected malware from website


  • This topic is locked This topic is locked
1 reply to this topic

#1 xjeez

xjeez

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:03:58 PM

Posted 25 March 2010 - 03:37 AM

Update : Managed to clear it on the first run of ComboFix, where everything else failed. So this topic can be closed or removed, apologies for any inconvenience caused.

After visiting a website running a Flash file earlier, my Firefox browser crashed and not long after that my ZoneAlarm firewall started prompting for permission for Services and controller app to run (services.exe).

I temporarily denied access, and shortly after Avast reported as suspected virus pattern by c:\windows\system32\drivers\zxalsz.sys

Googling it didn't return much results, but as I went and check the folder, I discovered 3 more additional files were also created at the same time :-

zxalsz.sys
kgpcpy.cfg
fidbox.dat.szfi
SBREDrv.sys

From there I found that these files appear a lot in cases in of browser hijack malware's and I was trying to find a cleaner or quick solution to remove it, but so far after full virus scan with Avast, and malware scan with Ad-Aware did not seem to solve the problem.

I noticed some of the similar problems was fixed here using ComboFix, but as its highly advised not to run ComboFix without the guidance of a helper here, I figured it would be much safer to post here to request for further assistance first.

So far the only symptoms I noticed is my PC slowing down, and the file zxalsz.sys keeps updating every minute, my firewall still blocks the Services and controller app request to access the Internet.


Edited by xjeez, 25 March 2010 - 04:58 AM.


BC AdBot (Login to Remove)

 


#2 Pandy

Pandy

    Bleepin'


  • Members
  • 9,559 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:58 AM

Posted 25 March 2010 - 10:55 AM

This topic is closed at the request of the Original Poster. If you need this topic reopened feel free to ask any moderator and it will be done for you.

Do not anticipate trouble, or worry about what may never happen. Keep in the sunlight.

Hide not your talents. They for use were made. What's a sundial in the shade?

~ Benjamin Franklin

I am a Bleeping Computer fan! Are you?

Facebook

Follow us on Twitter





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users