Another on Trojan.Zlob

Discussion in 'Malware Help (A Specialist Will Reply)' started by Guy, Dec 4, 2007.

  1. Guy

    Guy Private E-2

    Hi all. First post and let me say what a great forum you all have here. It has been a tremendous help so far.

    I have finished the READ & RUN and am attaching my log files.

    HOW I GOT THE TROJAN

    Tried to stream media off some random blog. When I clicked to start the stream I was prompted to install. Not paying attention (my bad), I assumed it was some sort of usual (safe?) ActiveX install. The rest is history.

    I am experiencing symptoms similar to the symptoms described by others:

    -Google redirects all searches to "You Tube Porn".
    -Constant pop-up with "Critical System Warning" about Trojan.Zlob-x.a.

    Running IE 7.

    Any/all help is very much appreciated. Thanks!
     

    Attached Files:

    Last edited by a moderator: Dec 4, 2007
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Please run FixIEDef which removes IE Defender, AntiSpyPro and the associated Trojan.Downloader.Delf infection.
    1. Download FixIEDef.zip by ShadowPuterDude to the Desktop.
      • NOTE: It must be saved to your Desktop or it may not work properly
    2. Double-click FixIEDef.zip, this will create a folder named FixIEDef on your Desktop.
    3. Double-click of the FixIEDef folder.
    4. Locate FixIEDef.bat and double-click on it.
    5. FixIEDef will now run.
    6. Press any key to close the CMD Console when the script is finished.
    Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

    Now uninstall all of the below old Sun Java versions:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created


    Make sure you tell me how things are working now!
     
  3. Guy

    Guy Private E-2

    Hello, and thank you for the response. I have gone through the READ & RUN steps, as well as the steps you described below. The problem seems to have been fixed.

    In any event, I am attaching the logs for your review. Let me know if there is anything further I should do to remove the trojan?!

    Thank you again, the help is very much appreciated!

    View attachment MGlogs.zip
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.

    You logs will be okay after doing the above. However I see a big problem. Why are you running your PC without any protection? No Antivirus, no antispyware, and no real birdirectional firewall!! Step 11 in the below will address this.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  5. Guy

    Guy Private E-2

    Everything seems to be workign a-ok again. :D

    Really appreciate all the help and guidance on this forum. Thanks a million!

    -Guy
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds