AVG found Trojan ZLOB, WQZ & WTK HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by bsfisher, Aug 31, 2006.

  1. bsfisher

    bsfisher Private E-2

    :mad: How do I get rid of these THorse's
    I do have HJT log if needed
    THANK YOU ! FOR READING

    Trojan horse Downloader.Zlob.AZZ C:\WINDOWS\system32\regperf.exe regperf.exe
    Trojan horse Downloader.Zlob.BDI C:\WINDOWS\system32\hp100.tmp hp100.tmp
    Trojan horse Downloader.Zlob.BTA C:\WINDOWS\system32\simpole.tlb simpole.tlb
    Trojan horse Downloader.Zlob.CSC C:\WINDOWS\system32\ld101.tmp ld101.tmp
    Trojan horse Generic.WQZ C:\WINDOWS\system32\guxxa.dll guxxa.dll
    Trojan horse Generic.WTK C:\WINDOWS\system32\1024\ld4C8A.tmp ld4C8A.tmp
    Trojan horse Generic.WTK C:\WINDOWS\system32\1024\ld42C6.tmp ld42C6.tmp
     
  2. matt.chugg

    matt.chugg MajorGeek

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support Paying attention to the special removal procedures link
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat[/B]
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. bsfisher

    bsfisher Private E-2

    THANKS, I think that got rid of them, I'm not sure which scan did it but I think I'm okay now!!!! THANKS AGAIN!!, I will follow those steps first next time
    I I hope there is no next time
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't think you will find that you are completely clean. You should finish all the steps and attach all the logs as requested so we can be sure.
     
  5. bsfisher

    bsfisher Private E-2

    okay, not a problem.....will do
     
  6. bsfisher

    bsfisher Private E-2

    it seems clean now, but I was told to post my logs anyway to make sure,
    let me know if you need any other info. THANKS for all your help
    bsfisher
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As suspected, you are not clean! And also you are running a lot of very old outdated software. You have a 3 year old version and a 2 year old version of Spybot installed. You have outdated Sun Java and Firefox too. And even worse.... your HijackThis version is also over two years out of date. You should have follow the instructions in the READ ME and all of your software would have been updated. Get the proper versions of ALL software installed now! Old outdated tools cannot find not fix new malware!


    Now Download SmitfraudFix (by S!Ri) to your Desktop.

    Extract all the files to your Destop. A folder named
    SmitfraudFix will be created on your Desktop.

    Open the
    SmitfraudFix folder and double-click smitfraudfix.cmd
    Select option #1 - Search by typing 1 and press Enter
    This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach that log in your next reply.

    Note:process.exe ( which is used my SmitFraudFIx ) is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. The below is a link to what process.exe is.

    http://www.beyondlogic.org/consulting/proc...processutil.htm


    IMPORTANT: Do NOT run any other options until you are asked to do so!
     
  8. bsfisher

    bsfisher Private E-2

    you want me to run the SmitfraudFix (by S!Ri) to my Desktop first???? before I download any current program versions?

    http://www.beyondlogic.org/consulting/proc...processutil.htm comes up with a broken link?

    I know I had updated those programs within the last 6-9 months but then I got infected and I couldn't even come up in safe mode my HP laptop (zt1170) would power off, (I think I also may have a fan or heatsink problem also?) after I get rid of these bugs I will try and diaganose that problem.......but I was able to go back to a prev. date and was finally able to logon, I think by going back probably screwed up what I thought was current version downloads.

    I know I went out and got all the updates for everything but I may not have had the current versions running, I know with spybot you had to get the new version and I had done that before, but maybe my going back messed that upalso .....

    I'll start by getting the most current program versions then the updates, or do you want me to do the SmitfraudFix steps first?
    -Scott
     
  9. bsfisher

    bsfisher Private E-2

    :confused: smitfraudFix ran and rapport.txt log is attached :rolleyes:
     

    Attached Files:

  10. bsfisher

    bsfisher Private E-2

    smitfraudFix ran and rapport.txt log is attached
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    PLEASE READ ALL OF THESE INSTRUCTIONS FIRST BEFORE DOING ANYTHING. Ask any questions that you may have before starting.

    Please print out or copy these instructions to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. Again, if there's anything that you don't understand, ask your question(s) before moving on with the fixes.

    Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    After doing the above and attach the new rapport.txt log, also attach a new HJT log and a new log from ShowNew!
     
  12. bsfisher

    bsfisher Private E-2

    :eek: Todays Logs attached: rapport / showNew / HJT Log (v.1.98.2)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    HJT logs must be obtained from normal boot mode. However there is a bigger problem. You never follow the steps in the READ ME completely. Your version of HijackThis has not been used in almost 2 years. Follow the directions in step 7 of the READ ME and install and rename HJT properly. You have two versions of Spybot installed! One is over 2 years old and the other is 3 years old. You need to uninstall them, reboot, and install the one from the READ ME as instructed.

    You also never updated your Sun Java version and also your FireFox version is way out of date. Uninstall the below:
    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.0.7)

    Then install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    What problems are you having at this point?
     
  14. bsfisher

    bsfisher Private E-2

    :rolleyes: Sorry, But I never received an answer when I asked if you wanted me to update those programs before I do the READ & RUN ME ow your very busy, so I went ahead and ran the R&R ME steps and to see if that was clean before I updated those pgms. I did the READ & RUN ME and it looked like the virus was gone but when you looked at my logs from R&R ME you say I was still infected and scolded me for not updating those programs and the HJT needed to scan in normal mode but no where did you say to be in normal mode, the last you said was be in safe mode and also attach HJT and ShowNew logs, sorry for not running them in normal mode. It's hard to remember which mode to be in, safe, normal, normal safe , save here, save there, rename XXX to yyy then a page later instructed to RUN XXX but it is now named yyy and saved in /here not /there all very confusing as if R&R ME was written by a programmer?

    I thought I was clean but you say my previous logs show I was infected
    I have removed all the old/outdated pgms as you told me to
    I have downloaded new pgms as instructed....spybot, java, firefox
    Do you want to see new HJT logs in normal mode?
    Do you want to see ShowNew logs? normal or safe mode?
    Do I need to start over and do the READ & RUN ME again?

    now I'm getting "ERROR SENDING RESPONSE TO KEYBOARD"

    "Reboot your computer into Safe Mode per the safe directions in the READ & RUN ME.

    Open the SmitfraudFix Folder of your Desktop, then double-click smitfraudfix.cmd file to start the tool.

    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

    The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. BUT Reboot in Safe Mode.
    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please attach this log along in your next reply.

    After doing the above and attach the new rapport.txt log, also attach a new HJT log and a new log from ShowNew
    !"
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry it was not clear in my last instructions. That's because as stated in the READ ME, we always want HJT logs from normal boot mode.

    Here is the simple answer, unless we directly ask for logs from safe mode, we always want them from normal boot mode.

    I want you to update all the programs that you had the wrong versions for as requested and then attach a new HJT log and a new log from ShowNew (update ShowNew too since it changed).

    Are you having any malware problems?
    Note: Keyboard problems are not malware problems.
     
  16. bsfisher

    bsfisher Private E-2

    :eek: HJT & newfiles logs attached from today 9/17

    other than the "command to keyboard" error, this lap top is shutting down after an hour or two so I'm trying to determin if it's a virus, or bad HD or bad fan/heatsink?:rolleyes:

    when I was first infected, I could run firefox okay but when I used IE the AVG virus window pop up showed I was infected with Trojan ZLOB,WQZ,WTK
    now after doing the read me first and run steps that pop up is gone, but after I showed logs you say I was still infected.

    I hope these new logs help THANKS -BSF:)
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But now you did not install and rename HJT properly. You ran it from inside the ZIP file. This is how it shows in your log:

    C:\DOCUME~2\Owner\LOCALS~1\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe

    We don' need a new log though because your clean now.

    You were but running SmitFraudFix removed the rest of the malware. However as stated above your clean now.

    It is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  18. bsfisher

    bsfisher Private E-2

    Will I ever get it right:rolleyes:
    if there is ever a next time, I will read, re-read and re-read again
    I have printed and saved all your post and will follow the steps to protect against malware
    THANK YOU!! THANK YOU!! THANK YOU!! for all your help!! :)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! But remember that if you ever do come back to get help for malware problems, you MUST follow the procedures in the current online guides. They change frequently (because malware changes too) and anything saved locally on your PC will not be current with our procedures. While you local copies may help you, they may be out of date with ours. Things like ShowNew and GetRunKey can sometimes change 5 times in a week (although right now they are not).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds