Comprolive.com offers free remote tech support using Google Chrome Remote Desktop. Please contact sanjayrajure(at)gmail.com by GMail/ GTalk/ Audio/ Video.

Zbani

Unwanted - App

An application named Zbani has appeared in a virus analysis report. You can see it  on this link

The information in the analysis report can be useful if you need to remove this program manually

  • The installer of this program is of about 7.3 MB
  • You can see the user ratings given to the website associated with this program on this link
  • It may download more files from the internet.
It creates a.exe, FlashPlayer.exe and other files on the infected computer that you need to search and delete. You should end these processes  from Task Manager and also remove their entries from the Windows Startup. The removal process may require using System Restore, Enabling to view Hidden files and folders, removing entries from Windows Startup, booting in Safe Mode, using System File Checker  etc. These steps are slightly different for different versions of Windows.

Some steps are essential, they are
# Removing virus processes from the Task Manager
# Searching and deleting virus files from the hard disk. You may have to enable to view Hidden FIles before you search otherwise virus files inside the windows system folders will not be searched.
# Removing obsolete registry keys using CCleaner

You can find detailed instructions and a number of free Tools on this link

You may also look at different ways to prevent malicious files from entering your computer on this link.


Deleting files

Delete the following files and folders. Boot in safe mode or boot in the dos prompt if needed. You can use windows search utility to search for a.exe, FlashPlayer.exe

Files
%DesktopDir%\learn_to_fly.lnk
%Programs%\zbani\learn_to_fly.lnk
C:\Program Files\Zbani\a.exe
C:\Program Files\Zbani\a.html
C:\Program Files\Zbani\batch.bat
C:\Program Files\Zbani\facebook_login_new.bmp
C:\Program Files\Zbani\firefox_toolbar.zip
C:\Program Files\Zbani\FlashPlayer.exe
C:\Program Files\Zbani\learn_to_fly.swf
C:\Program Files\Zbani\zbani232.bmp

Folders
%Programs%\zbani
C:\Program Files\Zbani

Files in Temp folder
%Temp%\zbani.ico
%Temp%\nsc3.tmp\nsProcess.dll
%Temp%\nsc3.tmp

( You can find full path of the short folder names  on this link. )

 

Reprinted with permission from Threatexpert.com  

Before you proceed, Please see the Disclaimer 


FAQ

Subscribe to me on YouTube