Help please with Zlob

Discussion in 'Malware Help (A Specialist Will Reply)' started by Leepy Lee, Aug 1, 2007.

  1. Leepy Lee

    Leepy Lee Private E-2

    Hi all,
    I hope someone will be able to point me in the right direction with this problem.

    I keep finding that web page links that I click on, take me to totally different websites. Not a major problem but its now getting annoying!

    I have read and followed all the steps in the Malware Removal Guide but I'm not entirely certain what to do next.

    The requested logs are attached below. Apart from the symptom described above, everything seems to be working OK, but I'm concerned about this Zlob virus that is continually identified by Spybot S&D. I keep letting it fix the problem, but it always comes back on the next scan, even if I run the scan immediately after S&D reports it has fixed the problem.

    I would appreciate some help from you experts out there please.

    Thanks in advance.

    PS I couldn't run Counterspy in Safe Mode - it reported in a window with the title 'Windows Installer', 'The systemadministrator has set policies to prevent this installation'. Even though I am logged on as the administrator.

    Other than that, all the scans completed successfully and I let them fix problems where they could.
     

    Attached Files:

  2. Leepy Lee

    Leepy Lee Private E-2

    Next scan reports...

    HJT scan from the method described in step 7.

    I have also disabled and then re-enabled system restore.

    Still S&D is finding Zlob on the machine and I'm still getting re-directed to different websites.

    Thanks again for any help.

    Lee
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 10"
    J2SE Runtime Environment 5.0 Update 11"
    J2SE Runtime Environment 5.0 Update 8"
    J2SE Runtime Environment 5.0 Update 9"
    J2SE Runtime Environment 5.0"
    Java 2 Runtime Environment Standard Edition v1.3.1_04

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking fix, exit HJT.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt
    Attach new logs for:
    ShowNew
    HJT
    Avenger
     
  4. Leepy Lee

    Leepy Lee Private E-2

    Thanks for the response TimW...

    Have followed your instructions and the requested logs are attached.

    When the PC rebooted, Avenger caused an error and gave me tyhe option to retry, which I did a couple of times, continue, which didn't seem to do anything, finally to cancel, which then brought up the attached print.

    What next please?

    Thanks
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you create the ShowNew and HJT logs before running Avenger?
    If so:
    Please run those two (ShowNew and GetRun) again and attach.
     
  6. Leepy Lee

    Leepy Lee Private E-2

    No, I did them in the order you requested at the foot of your last instructions. When I tried to upload the ShowNew & HJT logs it told me I'd already loaded them on a previous post so I renamed them ....2 etc. It still told me I'd already uploaded them so I added a line return and a few spaces to the end of each file. Then it accepted them both.

    That's why they are in the order they appear attached to the post.
     
  7. Leepy Lee

    Leepy Lee Private E-2

    Another GetRun log attached as requested...
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This happened because you are attaching the same logs! You need to get new logs as was requested.
     
  9. Leepy Lee

    Leepy Lee Private E-2

    OK so here are new ones ' fresh off the press...' as they say.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Delete the below file:
    C:\WINDOWS\system32\drivers\odbblrt^.sys

    Boot into safe to delete it if you cannot delete it in normal boot mode.

    After deleting the above file, make sure you reboot either way and then tell us if you are still having any problems.
     
  11. Leepy Lee

    Leepy Lee Private E-2

    Well it finally looks to have gone!!

    I've run AVG Virus Scanner
    AVG AntiSpyware
    Spybot S&D
    AdAware 2007

    They all report no problems!!

    So I just need to say a real BIG thankyou to TimW & chaslang for your help with this.

    I hope I don't need to trouble you for help again.

    Thanks again - I really appreciate your help and the time you must put in to helping everyone.

    Lee
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  13. Leepy Lee

    Leepy Lee Private E-2

    Thanks again chaslang. Have followed the Protect yourself from Malware Guide and I feel more confident now about the safety of my PC.

    Appreciate all your help and advice.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    On behalf of MG's....you're welcome....safe surfing.:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds