Zlob.downloader, Zlob.AR, Zlob is a Slob!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by alysser, Feb 1, 2009.

  1. alysser

    alysser Private E-2

    Hi folks!

    My mother's neighbor has a 15 yr old son who repeatedly messes up his computer with tons of viruses. The child keeps getting shuffled about to his mother's home (god help her computer!) and then the father asks me to help fix his computer. The first time (5 months ago?) I just reformatted the entire thing.

    This time I came here. You guys have helped me before when some virus got in my machine. Anyway.....

    I ran the Read Me & the XP Cleaning Processes & have attached what logs I *could* get below. I ran into some difficulties. ComboFix.exe will not run on the machine (it is a Dell Dimension 3000 running WinXp sp2...with only 256 mb of RAM I might add)

    ComboFix repeatedly gives me the "Incompatible OS" message in 17 different languages. It does this both in Safe Mode & out of Safe Mode.

    MGTools only flashes a DOS window after I extract it. The window flashes for a second and disappears.

    After seeing what SD Search & Destroy reported (Zlob.Downloader, etc), I came here & looked for a removal tool, found the Smithfraudfix.cmb thread and tried to run that. Same deal, DOS window flashes for a second and is gone. Spybot finds these 3 things, but even when I let it run on startup, it cannot remove them.

    Same with MBAM, I just get stuck in the same cycle of scanning and attempting to remove & rebooting. ARGH!

    One other thing, the AVG Free Virus Vault was so full of 92kb files that I had to entirely uninstall the program and then manually delete the 20,000 files in the Vault to get these logs down to right size. Not to worry though, this rig is off the internet for now, in my home next to my non-sick computer. Same thing with the system32 folder, it had 35,000 .tmp files in it all 92kb. It was threatening to have me scanning into next Christmas. Zlob is a nasty, nasty bugger!!

    So anyway, I will attach the SAS, MBAM & HJT logs below, but that is all I could get. I can't get any further without your help, and your efforts are greatly appreciated. :)

    PS. I tried to manually delete those registry keys but the machine tells me it experienced an error in doing so. Ya! The error is Zlob doesn't wanna go away! Thanks for your help.
     

    Attached Files:

    Last edited: Feb 1, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I need the entire C:\MGLogs.zip, not just the HJT log.
     
  3. alysser

    alysser Private E-2

    Thanks for your reply, but like I said in my original post from 2 days ago,

    MGTools would not run. and yes it is on the root of c:/

    ComboFix would also not run.

    I followed all the directions meticulously.

    And I already tried the TDSSserv Non-Plug & Play Driver Disable fix for this, but there was no TDSSserv present in View Hidden Devices.
     
    Last edited: Feb 3, 2009
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you need to tell me what errors you got. The reason I said I need the entilre log is that you posted this:
    C:\MGtools\analyse.exe
    So you have a C\|MGTools folder. Within it is a C:\MGtools\GetLogs.bat file --> double click it to get new logs.

    This all indicates to me that it ran. Do you not have a C:\MGLogs.zip?

    You said this:
    This is not a zip file, it is an exe file and only need double clicking to run.
     
  5. alysser

    alysser Private E-2

    Wow I'm really so sorry here Tim, I forgot to explain that it was GetLOGS.bat that blinked & disappeared when I clicked on it.

    I downloaded MGTools.exe to the C://

    it created the MGTools folder. When I go into the MGTools folder, in Safe Mode (yes Safe Mode) open that folder & then double click GetLOGS.bat, a DOS window appears for a split second and disappears.


    I know you all volunteer for free, but that is also what I'm doing here.

    Next time I'll tell the guy where to go with his poisonous computer.

    Death to MySpace.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please see this thread for possible solutions:
    Using MGtools

    I can't proceed until we can get the logs to know what is going on in this system. :(
     
  7. alysser

    alysser Private E-2

    I am in Safe Mode & I double click on C:/MGTools/GetLogs.bat and nothing happens.

    I ran all the steps on the Using MGTools thread to address error messages even though I don't get any error messages.

    Oh, wait one second.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is strange.

    OK, you are saying that these still exist:
    If so, Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    ]

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Reboot and see if they still exist.
     
  9. alysser

    alysser Private E-2

    ahh forget that machine, I'm reformatting
     
  10. alysser

    alysser Private E-2

    Oh Tim I didnt see your reply before I already started the reformat. Yeah....kinda why I posted those other logs.

    Ah well.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since MBAM showed it had removed them, I missed that you were trying to manually remove them. :(

    At least you will know you are clean now. :)
     
  12. alysser

    alysser Private E-2

    OK, so here i am on the newly reformatted machine. Thank you Tim, very much for trying to help me!! I am taking this machine back to my mom's neighbor tomorrow and recommending he never, ever let his son on it ever, ever again. :)
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  14. alysser

    alysser Private E-2

    oh that's what he HAD - and his Dad swore up and down the kid wasn't even going to come home and use the machine anymore. But I created his a passworded account with NO admin & passworded the Dad's account. And he still mucked it all up in like 5 days!

    I'll tell ya though, this is seriously the best birth control I have ever encountered!

    I will set your thread as his home page :-D
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If he is a smart kid, then you better password safe mode.
     
  16. alysser

    alysser Private E-2

    oh yeah good idea, I am on it!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds