spycrusher and zlob virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Becci, Jun 28, 2007.

  1. Becci

    Becci Private E-2

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please attach the other 3 requested logs from the READ ME.

    • CounterSpy - only for Windows XP, 2K, & NT users
    • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
    • newfiles.txt - the log from ShowNew.bat
    • HijackThis
     
  3. Becci

    Becci Private E-2

    counterspy file will follow once I find it on system
     

    Attached Files:

  4. Becci

    Becci Private E-2

    the counterspy programme found NO files and therefore I could not produce a .txt file from the results:)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then uninstall CounterSpy now since we are finished with it.

    What program is detecting SpyCrusher and zlob (which are the samething)? Is is NoAdware which is notorious for false positives? Please attach a log or cut and paste in exactly what is being found.


    Also uninstall the below old Sun Java version:
    J2SE Runtime Environment 5.0 Update 6


    Are the below things that you installed?
    O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
    O2 - BHO: askBar BHO - {5A074B21-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll
    O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
    O3 - Toolbar: Ask Toolbar - {5A074B29-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll


    Also what are the below?
    O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
    O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe
     
  6. Becci

    Becci Private E-2

    Okay then uninstall CounterSpy now since we are finished with it. - OK will do

    What program is detecting SpyCrusher and zlob (which are the samething)? Is it NoAdware which is notorious for false positives? Please attach a log or cut and paste in exactly what is being found. it was stopzilla which I uninstalled as instructed during stages 1-6


    Also uninstall the below old Sun Java version:
    J2SE Runtime Environment 5.0 Update 6 - will do


    Are the below things that you installed?
    O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing) - don' t recognise
    O2 - BHO: askBar BHO - {5A074B21-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll - yes but I uninstalled
    O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing) - don' t recognise
    O3 - Toolbar: Ask Toolbar - {5A074B29-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll - yes but I uninstalled


    Also what are the below?
    O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe - don' t recognise
    O4 - HKLM\..\Run: [Domino] C:\WINDOWS\Domino.exe - don' t recognise
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you positive? Take a look at the below:

    http://translate.google.com/transla...4&ct=result&prev=/search?q=ZSSnp211.exe&hl=en

    http://www.liutilities.com/products/wintaskspro/processlibrary/domino/


    Does anything in those links refresh your memory on what these may be for?

    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
    O2 - BHO: askBar BHO - {5A074B21-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll
    O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
    O3 - Toolbar: Ask Toolbar - {5A074B29-F830-49de-A31B-40463F552DA4} - C:\Program Files\MyDailyVideo\bar\bin\askBar.dll

    After clicking Fix, exit HJT.:

    Now reboot in normal mode


    Now locate the below folders and delete it if found:
    C:\Program Files\MyDailyVideo
    C:\Program Files\VMNTOO~1 or C:\Program Files\VMN Toolbar

    Now run Ccleaner

    Now attach a new HJT log

    Are you having any current malware problems?
     
  8. Becci

    Becci Private E-2

    I don't recognise it or remember loading it but it looks genuime:

    Company Profile

    Uniblue Systems Ltd is a provider of leading software utilities products designed to deliver superior performance, protection and security to PC users in the home, SoHo and Business markets.

    The European company, based in Malta since 2003, has developed a unique combination of award-winning products and services that are marketed globally today.

    domino.exe - domino - Process Information

    Process File: domino.exe or domino
    Process Name: Vimicro

    Click Here to Run a Free Scan for domino.exe Related Errors

    Description:
    domino.exe is a Vimicro from Vimicro belonging to BIGDOG
    Click Here to Scan Your PC including domino.exe to Detect any Security Threat

    Also do not recognise other program:

    Process documents : ZSSnp211.exe什么是进程?ZSSnp211.exe What is the process?
    进程名称:Name of the process : ZSSnp211.exeZSSnp211.exe
    英文描述:English Description : N/AN / A
    进程分析:process analysis : ZSMCSNAP摄像头驱动程序。ZSMCSNAP camera driver.
    推荐:Recommended :

    So should I delete these programs?



    Will now run hijack and post separate reply

    thanks for all help
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I do not know what they are exactly other than what the links refer to. So let's not delete them yet.

    Complete my other steps first and attach the new log. Then tell me what problems if any your are having.
     
  10. Becci

    Becci Private E-2

    All actions completed plus attached files are

    1. stopzilla log first scan today showing zlob virus

    2. stopzilla log after cleaning using stopzilla removal tool

    3. latest hijack this log after above deletions
     

    Attached Files:

  11. Becci

    Becci Private E-2

    In relation to problems - none seem to be present only that stopzilla still found virus after going through all steps and I am still concerned about using computer for any financial transactions.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You never had a Zlob infection. It was blocked from being extract. Thus you have nothing to worry about. In addition Zlob is not a password stealer.

    You attached HJT log from an improperly named HijackThis program. Your earlier log was fine but this one is not.

    Also, why do I now see Stopzilla when I did not see it earlier and why is CounterSpy still installed when I asked you to uninstall it back in message # 5

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, and the C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    9. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  13. Becci

    Becci Private E-2

    You never had a Zlob infection. It was blocked from being extract. Thus you have nothing to worry about. In addition Zlob is not a password stealer.

    I did keep getting the spycrusher icon in the bar at the base of the screen on the right and it kept giving pop-ups which then connected me to the spycrusher website if you clicked the box. These have now gone

    You attached HJT log from an improperly named HijackThis program.

    I do not understand so I will attach another one after your instructions

    Your earlier log was fine but this one is not.

    Also, why do I now see Stopzilla when I did not see it earlier

    I reinstalled Stopzilla as this was the program which alerted me to the fact that I still had the zlob virus after running avg as I wanted to show you the logs and the fact that it was still stating that my computer was infected - both of which I deleted before proceeding to step 5

    and why is CounterSpy still installed when I asked you to uninstall it back in message # 5 - I did uninstall it through add/remove programs so do not understand why it is still loaded?!

    Points 1 to 10

    We did not install any of the files mentioned in points 1 to 7 - should we have done?

    points 8 & 9 will be completed and a final log will be attached next posting

    Point 10 - will work through - do you suggest I run AVG or Stopzilla(I have bought 1 years registration), or both of them.

    Thanks for help
     
  14. Becci

    Becci Private E-2

    final hijackthis log attached
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I was commenting based on the logs you attached. There were no signs of an active Zlob infection showing in any logs. Perhaps you removed it before coming here.

    It is still wrong in your current log! You are getting your log from running this:

    C:\Program Files\HijackThis\HijackThis.exe

    See step 7 of the READ ME. It should be this:

    C:\Program Files\HijackThis\analyse.exe

    In your first HJT log in message # 3 you had the below which is not exactly what we asked for but was okay.

    C:\Program Files\analyse\analyse.exe


    Are you saying Stopzilla (which is not a favorite of mine) is finding problems now.

    Sorry! It's gone now! Perhaps I had pulled up the older log.


    That is a generic boiler plate. The key word is IF


    Do you mean AVG Antivirus or AVG AntiSpyware? I assume you mean AVG AntiSpyware. If you subscribed to it, I would use it. You should not use multiple antispyware tools with realtime blocking capabilities.
     
  16. Becci

    Becci Private E-2

    See step 7 of the READ ME. It should be this:

    C:\Program Files\HijackThis\analyse.exe

    new log attached

    Are you saying Stopzilla (which is not a favorite of mine) is finding problems now

    Stopzilla still found it after all steps taken on 1/7/07 and then removed it but does not find it now if run

    Do you mean AVG Antivirus or AVG AntiSpyware? I assume you mean AVG AntiSpyware. If you subscribed to it, I would use it. You should not use multiple antispyware tools with realtime blocking capabilities.

    I have avg anti-virus only and stopzilla anti spyware
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why did you install AVG Antivirus???? You did not have it installed before. Now you are violating step 3 of the READ ME. This was a bad thing to do. Make up your mind on whether you want AVG Antivirus or McAfee and uninstall one of them.
     
  18. Becci

    Becci Private E-2

    avg is now uninstalled and only mcafee is running - what next?
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not having anymore malware problems and if you have completed all the instructions in message # 12 then we are finished.
     
  20. Becci

    Becci Private E-2

    :)Many thanks for all your assistance

    I am leaving

    * after the fact scanner - spybot
    * non-realtime protection no scanner - spywareblaster

    installed as per instructions in step 10 message #12 and using Stopzilla as active spyware monitor (Realtime blocking)at present. When this licence expires what would you recommend that I switch to of those listed as either pay or free tools?

    Becci
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There aren't too many free realtime blockers. When your license expires, check out what is listed in the How to protect thread and which you prefer.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds