Hi Community.

Can anyone tell me how to remove REG/Zapchast.H and BAT/Zapchast.CE viruses?

Thanks,

scripted

Dani AI

Generated

As described, this showed up right after opening a bogus card. As cautioned, treat it as a serious compromise and act deliberately.

First actions: isolate the PC (unplug Ethernet, turn off Wi‑Fi), disconnect any USB drives and backups, and do not log into sensitive accounts from that machine. Make a copy of any irreplaceable personal files to an external disk for later scanning, but avoid executing or opening those files on the infected PC.

After the scans recommended by , use focused diagnostic tools to find persistence and running components. Autoruns (Sysinternals) highlights runkeys, scheduled tasks, services and browser helper objects—use "Hide Microsoft Entries" and inspect image paths and publisher signatures before removing anything. Process Explorer (Sysinternals) lets you inspect running processes, DLLs and network connections; note suspicious parent/child relationships or unsigned binaries. For any suspicious executable, submit the file or its hash to VirusTotal to see vendor detection consensus before deleting or quarantining it (Autoruns (Sysinternals), Process Explorer (Sysinternals), VirusTotal).

If infections persist or a rootkit is suspected, boot a known-clean rescue environment and run offline scans—Microsoft Defender Offline is one supported option. Disable System Restore during cleanup so infected restore points cannot reintroduce malware. If multiple components or rootkits are present, a full OS reinstall from trusted media is the safest recovery; restore personal files only after scanning from a known-clean system ().

Assume credentials may be compromised: change passwords from a different, clean machine and monitor financial accounts. Preserve and attach logs (Malwarebytes, ESET, HiJackThis/Autoruns output) when asking for further help—these help responders see exactly what remains.

Recommended Answers

All 4 Replies

Hi Community.

Can anyone tell me how to remove REG/Zapchast.H and BAT/Zapchast.CE viruses?

Thanks,

scripted

Nobody can give any info until WE have info...operating system, av program, firewall, anti-malware programs and, most important, how do you know you have these on the computer?

Nobody can give any info until WE have info...operating system, av program, firewall, anti-malware programs and, most important, how do you know you have these on the computer?

Thanks for getting back to me jholland. I'll give you what info I have and hopefully it will be enough.

My OS is WindowsXP
AV program is provided by my ISP, Bell Sympatico
I know I have these viruses because I did a virus scan, after a pop-up from my ISP security program indicated I'd been infected. I got that message seconds after I opened a bogus Hallmark card.

I hope that helps. Any assistance you can provide would be very appreciated.

Regards, scripted

Please Download ATF-Cleaner.exe by Atribune Save it to the desktop for easy access.
RUN ATF-Cleaner.exe.

-- Click on ATF-Cleaner to run it
-- Where it says Select Files To Delete, Check the Select All Option
-- Click Empty Selected > OK

If you use Firefox browser, do this also:

* Click Firefox at the top and choose Select All from the list.
* Click the Empty Selected button.
* NOTE : If you would like to keep your saved passwords, click No at the prompt.

Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.
REBOOT the computer.

Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

Reboot the computer.
When the computer has rebooted then Right Click on the desktop and choose New Folder. A new folder will be created on the desktop.
Rename this folder HJT.
Next Download and save it to this folder.
Now run a Full System scan with HiJackThis and save the log.
Post back here with the MBA-M log, the ESET log and the HiJackThis log.
Judy

What you are dealing with can and is very dangerous. Both of these files are from ONE trojan...so far. Unless you get this cleaned up there most likely will be many more.

Here are links below where I found the info I have posted below the links.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=BAT_ZAPCHAST.C

Trojan.Zapchast
This one is considered High Risk.
High risks are typically installed without user interaction through security exploits, and can severely compromise system security. Such risks may open illicit network connections, use polymorphic tactics to self-mutate, disable security software, modify system files, and install additional malware. These risks may also collect and transmit personally identifiable information (PII) without your consent and severely degrade the performance and stability of your computer.
Trojan.Zapchast puts a copy of itself in the registry as a Window's runkey so that is it activated when Windows starts. When active, this trojan will execute another trojan, Trojan.Pakes, which downloads other malware.

Creates an executable file in the fake Recycle Bin folder with the purpose of concealing its presence in the system.
Creates fake Recycle Bin folder.
Must be removed

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.