Zinblog (Virus). Registry settings.

Divestar

Senior Member
Joined
Sep 12, 2008
Messages
543
Reaction score
31
Location
Witbank, South Africa
I removed a few viruses from a friend's PC. I need help with some stuff:

One of the virusses changed the PC registry settings. I am unable to access the "run" command, I can't change the Internet explorer home page from zinblog.com and I get errors on all websites running scripts.

Could someone please help me solve the registry issues (with a .bat file or free software.)

Thank you!
 
Hirens boot CD has some registry tools, TBO I've not used them, however logic says unless you have a backup of his registry somewhere there's no real way of recovering it.

You can try create another user login and see if 'run' is still disabled. Further to that it probably disables taskmanager and regedit, quicker to do a recovery install. IMO
 
I've tried the recovery install, but I don't think I'm that advanced... It seems to go fine untill I need to enter the non-existent administrator password...
 
I've tried the recovery install, but I don't think I'm that advanced... It seems to go fine untill I need to enter the non-existant administrator password...

Too soon, go install and you'll get another recovery option when it searches for previous versions of windows.

As TL pointed out, maybe take that drive out and scan it in another PC first.
 
http://forums.spybot.info/archive/index.php/t-39256.html

The following instructions have been created to help you to get rid of "Zinblog" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site (http://www.safer-networking.org/index.php?page=donate).

Threat Details:

Categories:
trojan

Description: Zinblog disguises as "Task Manager" to run at system start and eats up system resources. Also changes the startpage of the Internet Explorer. Also loads CoolWWWSearch.OleHelp on the victim´s PC.
Removal Instructions:

Autorun:

Please use Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd), RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer) or msconfig.exe to remove the following autorun entries.

Entries named "Task Manager" and pointing to "<$WINDIR>\svhost32.exe".

Files:

Please use Windows Explorer or another file manager of your choice to locate and delete these files.

The file at "<$DESKTOP>\zin.exe".
The file at "<$WINDIR>\svchost.exe".
The file at "<$WINDIR>\svhost32.exe".
Make sure you set your file manager to display hidden and system files. If Zinblog uses rootkit technologies, use our RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).
You will have to use a global search for files without a name specified. Be extra careful, because just the name might not be enough to identify files!

Registry:

You can use regedit.exe (included in Windows) to locate and delete these registry entries.

Delete the registry value "Search Page=http://zinblog.com" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\".
Delete the registry value "Start Page=http://zinblog.com" at "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\".
If Zinblog uses rootkit technologies, use our RegAlyzer (http://www.safer-networking.org/index.php?page=regalyzer), RootAlyzer (http://forums.spybot.info/downloads.php?id=8) or our Total Commander anti-rootkit plugins (http://forums.spybot.info/downloads.php?id=3).

Browser:

The following browser plugins or items can either be removed directly in your browser, or through the help of e.g. Spybot-S&D (http://www.safer-networking.org/index.php?page=spybotsd) or RunAlyzer (http://www.safer-networking.org/index.php?page=runalyzer).

Please check your bookmarks for links to "http://64.26.25.75".
Please check your bookmarks for links to "http://lucyblog.com".
Please check your bookmarks for links to "http://unitedreporters.org".
Please check your bookmarks for links to "http://zinblog.com".

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
Please read these instructions (http://forums.spybot.info/showthread.php?t=288) before requesting assistance,
Then start your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) where a volunteer analyst will advise you as soon as available.
 
Seems to be working

Too soon, go install and you'll get another recovery option when it searches for previous versions of windows.

As TL pointed out, maybe take that drive out and scan it in another PC first.

"Keeping my fingers crossed..."

This seems to be working... I'll let you know what happened after the setup is complete...

Than you all!
 
Is there any way to extract the product key from Windows XP?
The version of windows has been verified, but there is no sticker on the box.

What now?
 
Ok! I just learned that once the installation has begun, you can't stop it and revert to the old Windows...

Any ideas?
now is a good time to buy a legit copy of windows, and perhaps a good time to upgrade to windows7 if the machine can handle it.
 
now is a good time to buy a legit copy of windows, and perhaps a good time to upgrade to windows7 if the machine can handle it.

FYI, it is legal software. The certificate was stuck to the previous case and no longer available...

I downloaded and installed the Microsoft Advantage Notification software and it passed the Microsoft test...

That doesn't help me with the current problem. I need to fix the registry settings on XP. I tried the setup (repair) and got stuck on installation.

How can I cancel setup and revert back to the old windows?
 
Top
Sign up to the MyBroadband newsletter
X