ISP informed me of a possible zbot/zeus infection

Hello,

My ISP emailed me a couple days ago to inform me that the laptops on my network might be infected with zbot/Zeus Trojan.

They recommended I scan with Microsoft Safety Scanner and a Symantec Zbot Removal Tool. Both of those scans came back clean.
I also used Superantispyware and that found some adware cookies.

Could anyone tell me if I am infected?

Thank you

check back tomorrow for a reply

also check your router here > https://campaigns.f-secure.com/router-checker/en_global/

Thank you, Pondus. The F-Secure Router Checker found no issues.

FIRST >>>>

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Fix with Farbar Recovery Scan Tool
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[b] This fix was created for this user for use on that particular machine.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif

https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
Running it on another one may cause damage and render the system unstable.
https://sites.google.com/site/cannedfixes/home/hosted-images-formatting/icon_exclaim.gif
[/b]Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

SECOND >>>>

AdwCleaner by Xplode

Download AdwCleaner from here or from here. Save the file to the desktop.

NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.

  • Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.
    You will see the following console:

http://i1351.photobucket.com/albums/p785/dbreeze2/Scanners%20screens/AdwCleaner_v6_start_zps5nymee4e.png

	[li]Click the [b]Scan[/b] button and wait for the scan to finish.
	- After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: [b]Waiting for action. Please uncheck elements you don't want to remove.[/b]
	- Click the [b]Clean[/b] button.
	- [b]Everything checked[/b] will be deleted.
	- When the program has finished cleaning a report appears.
	- Once done it may ask to reboot, allow this
[/li]

http://1.bp.blogspot.com/-vitKqfMQS4o/UEDylIQ7HJI/AAAAAAAABLc/Hx-IwqKoaxg/s1600/adwcleaner_delete_restart.jpg

  • On reboot a log will be produced; please attach that in your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[C0].txt

Optional:

NOTE: If you see AVG Secure Search being targeted for deletion, Here’s Why and Here. You can always Reinstall it.

Thank you, dbrisendine. I’ve attached the files.

Did anything indicate that I had a zbot or something dangerous? And could you tell me what was deleted with the Farbar fix, was it anything bad?

The Fixlist removed one malware file and cleaned up left over settings / keys that needed to be closed so malware could not use them in the future. AdwCleaner removed a setting for a bad IM that is no longer on the system (again for the same reason; so nothing can use that key / setting in the future).

I did not see specific instances of Zbot / Zues but your ISP may have just been saying that there was a network traffic pattern that matched the infection. Please let us know if your ISP continues to see this “infection”.

Wow, that’s scary, none of the other scans showed anything. Was the malware something really dangerous? Also, is it okay if I post scan logs for my dad’s laptop on this thread? It’s the only other Windows using thing on my network and I want to be doubly cautious now.

Also, is it okay if I post scan logs for my dad's laptop on this thread?
You can ;)

Thanks again for the quick reply, Pondus! I’m sorry it took me a while to get my dad’s laptop. Here’s the files form the scans.

Your father’s logs look clean. Are they experiencing any issues or are you just checking?

I was just double checking because you found malware on my laptop and I thought I was safe. Was the malware you found on mine anything scary? Also, my dad’s laptop is agonizing slow so I thought there was for sure something there.

Thank you guys so much! Its such a huge relief to know that it was a false pos from my ISP.

Is there anything new for removing the zbot since May 12 2017?