Trojan Horse TR/Zlob.K.2

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by welshrich, May 6, 2006.

  1. welshrich

    welshrich Private E-2

    I got my first virus this week when my girlfriend clicked on the following email titled "Help":

    Hi! How are you?
    You know I've created my own website!
    Can you check how it works?
    It's republika.pl/ferasdi/video
    Can you see video?
    Bye!

    I contracted puper.dll and FakeAlert-B. I switched off my system backup and tried to nuke them with McAfee in Safe Mode and I also hit them with AntiVir Guard. I seemed to have tamed them slightly - less popups at least. However, I know they are still there. And possibly others. For example, AntiVir just told me it had deleted the Trojan Horse TR/ZlobK.2

    Also in my Registry - HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/Current Version/policies/explorer/run/kernell32.dll it says
    C:\WINDOWS\system32\atmclk.exe

    which is a bad thing from what I can gather.

    I have also seen message from TR/Agent.IV.3

    I then ran a free trial of Spyware Doctor and it told me I had loads of stuff but would have to pay for removal. And then I discovered Major Geeks and Hijackthis so am turning to this forum for help.

    As you can tell I am no computer expert but I cam able to follow instructions around the computer.

    I have attached my log file. Can anyone out there please help me?

    Thanks

    Richard (Wales UK)
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Before getting started on fixes, uninstall one of your antivirus programs. You must have one installed. Also uninstall the Spyware Doctor demo as it is of no use to you and a waste of system resources.

    Now run the below procedure and attach the smitfiles.txt log as requested:

    SpywareQuake & SpyFalcon Removal Procedure

    How are things working now?
     
  3. welshrich

    welshrich Private E-2

    Chaslang,

    I have attached the bdscan and activescan logs from the sticky thread 'Read Me and Run Me first Before Asking for Support' steps 1-6. I did this before reading your reply to my original request.

    I then carried out the instructions you told me to and have attached the resulting smitfiles.txt

    No probs yet!

    Let me know what you think of the log files.

    Thanks
    Rich
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to delete the messages in you Outlook Express email folders that Bitdefender was unable to delete. Look at the Bitdefender log yourself and find those messages and delete them.

    Now post a follow up HJT log so we can make sure everything is gone.

    Is everything working okay now?
     
  5. welshrich

    welshrich Private E-2

    Carried out instructions as described.
    All is still working ok.
    Attached my latest Hijack this log file .
    Cheers
    Rich
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Is Ewido a a paid version or free trial version? If free, uninstall it and keep Windows Defender. If Ewido is a paid version, uninstall Windows Defender and keep Ewido.


    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds