Zlob.DNSChanger trouble

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by pansygirl, Aug 14, 2007.

  1. pansygirl

    pansygirl Private E-2

    Every time I run Spybot, I get the Zlob.DNSChanger and even though I remove it, every time I run it, I get the same problem. What do I do now?

    I'm running WinXP. I also run:

    Spybot
    AdAware SE Professional
    PestPatrol
    CCleaner
    Cleanup
    Eset NOD32
    SpywareBlaster
    WinCleaner OneClick CleanUp
    SpySweeper
    TrojanHunter

    I can't imagine, with all of this stuff, that garbage still gets through. I guess I lack suffient imagination and knowledge...lol.

    Please help!

    Thanks,
    pansygirl
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Running to many realtime antispyware tools can be as bad as running more than one antivirus program and it can make each tool less effective. Are your copies of Pest Patrol & Spy Sweeper paid versions or free trials? You should not have both of those and also Ad-Aware SE Professional installed and running.



    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    How are things working now?
     
  3. pansygirl

    pansygirl Private E-2

    Well, there's a problem right away. I did exactly what you said to do with the SmithfraudFix zip. When I extract it, it refuses to extract the Process.exe file. Without it, the smithfraudfix.cmd will not run. Now what? I've completely deleted at and re-dowloaded and unzipped it with no success. Can't imagine what can be wrong. The error I get is: "Process.exe is missing!! Unzip all archives in a folder."

    Also, I have paid versions of Pest Patrol and Spy Sweeper. I have uninstalled Pest Patrol and run CCleaner to remove everything. I still have Ad-Aware SE Professional installed and running, but it only runs when I turn it on.

    Any ideas??
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown your antivirus and antispyware programs. They could be getting in your way. Then follow the directions.

    Do you mean you don't have Ad-Watch enabled? And you only use Ad-Aware SE as a scanner?
     
  5. pansygirl

    pansygirl Private E-2

    Ok, Here is the text log for step#1

    Now, in order to get this done, I had to uninstall NOD32, SpySweeper, Pest Patrol. Also a note, I only use Adaware SE Professional to scan separately. I don't run Ad-Watch, it is not enabled.

    I'm not going to do step #2, till I am sure this is done correctly.

    Thanks,
    pansygirl
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need to move on to step 2 immediately.
     
  7. pansygirl

    pansygirl Private E-2

    Okie Dokie... here's the new rapport log:

    After this is done, I need to reinstall NOD32 and one of the spyware software options. Do you recommend any of these?

    Spyware Blaster
    Pest Patrol

    In my original post, I listed what I scan with, some daily and some weekly, except for the ones installed to run all of the time.


    Thanks,
    pansygirl
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First a question, how is everything working?

    Spyware Blaster should be installed no matter what else you have. Pest Patrol is not as good as Spy Sweeper so if you have a paid up to date copy of Spy Sweeper, use it.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    2. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    3. After doing the above, you should work thru the below link:
     
  9. pansygirl

    pansygirl Private E-2

    Ok, looks like everything is fixed. I'm running Spybot to to be sure, but so far all is looking ok. I'm not going to reinstall pest control or counterspy. I'll stick with SpySweeper, and have reinstalled that and NOD32.

    Thanks so much for all of your help! I greatly appreciate it. I'm gonna make sure that my kids pcs are running the same things as mine, as we have 5 pcs on our lan.

    Thanks again!
    pansygirl
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. pansygirl

    pansygirl Private E-2

    Hey Chas...

    I ran a virus scan with NOD32 today and got the following report:

    File C:\Documents and Settings\Linda\Desktop\SmitfraudFix.zip is infected with application Win32/PrcView. The file can be deleted. It is strongly recommended that you back up any crucial data before you proceed.

    I've deleted it, but wanted to let you know that I downloaded this from the link that was sent in the email below. I am rescanning, but don't expect to find anything else, because I deleted the file and emptied the recycling bin. I had uninstalled NOD32, in order to download this file so I could clean out the other virus.

    Just reporting the problem.

    Thanks again for your help.
    pansygirl
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    It's legit, that utility is flagged due to it's nature. There is no real problem to worry about.

    You can delete anything that was used during your fixes including anything that was installed during the READ ME.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds