zlob - dns changer

Discussion in 'Malware Help (A Specialist Will Reply)' started by IcemanGER, Nov 4, 2008.

  1. IcemanGER

    IcemanGER Private E-2

    Hi there,
    I was trying to post in an existing thread but didn't had the permission. I hope this is ok.
    I have this malware about 2-3 days now.
    I read pretty much all the existing threads and worked to the how to as well(http://forums.majorgeeks.com/showthread.php?t=139313), without any luck.
    I've 2 laptops and 2 pc's in the network and all are infected.
    The malware got spread through the router and I'm only running 1 machine right now till I get this problem fixed.
    Should I run all the programs again and post the log's or should I wait till someone will tell me what to do and when?
    Help is much appreciated !!!
     
  2. IcemanGER

    IcemanGER Private E-2

    So, I tried it over and over again. It is still there !
    Here are some report files.

    Could someone please look into them and give me some advice?

    Thank you.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    READ & RUN ME FIRST. Malware Removal Guide

    Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  4. IcemanGER

    IcemanGER Private E-2

    Thank you for getting back to me.

    Here is an interesting Update:

    I did a fresh install of XP Pro on my laptop.
    I connected to the cable modem directly and everything runs just fine.
    No "Zlob" anymore !

    Here is the problem:

    As soon as I hook up my Linksys router, connect my "clean" laptop and open internet explorer, I get the malware right away !!!

    Did a reset and a fresh flash. NO Changes !

    Could it be, that "zlob" is hidden in the router ???
     
  5. IcemanGER

    IcemanGER Private E-2

    UPDATE !

    overlooked the cause for a couple of days. :(
    Thought by resetting and flashing the router it would take care of all settings.
    It doesn't !!!

    DNS Servers are still in the router.

    Here are the bad IP addresses:

    - 85.255.112.150
    - 85.255.112.234
    - 1.2.3.4

    don't think the 3rd one is an actual address though.

    Problems solved.
    Reinstalling a fresh OS on every PC in the house and I should be fine.

    cheers
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not sure that you have to reinstall OS's....removing those dns items on the router should be sufficient. You will have to reset them on each computer as well...with static addresses if I recall correctly. I will get back to you on that.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  8. IcemanGER

    IcemanGER Private E-2

    GREAT !

    That actually worked.
    Thank you very much.

    cheers
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome....
    If you ran any of the scans, we can clean that up:
     
  10. IcemanGER

    IcemanGER Private E-2

    OK, did everything what was mentioned and read the post of chaslang.

    Thanks again :wave
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know if you have any other problems...and you are welcome. :)
     
  12. IcemanGER

    IcemanGER Private E-2

    everything is fine. no more problems. back to normal. thank god.

    just would like to know who those ip's belong to.
    traced them without any luck.
    lots of time outs.

    cheers
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can always lookup ip addresses ...google "whois". And you are welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds