Help! Can not remove Zlob Downloader.vcd

Discussion in 'Malware Help (A Specialist Will Reply)' started by emanpa, Mar 14, 2008.

  1. emanpa

    emanpa Private E-2

    I have tried the other posts for cleaning up this nasty problem; however, it has not worked. Can you help me?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We also need the C:\MGLogs.zip...from running the C:\MGTools.exe.
     
  3. emanpa

    emanpa Private E-2

    Sorry, I forgot to attach the Hijackthis log, so here it is,
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not what I asked for ...in order to remove the infections, I need the C:\MGLogs.zip...not just the HJT log. Please attach the requested log.

    You can re-run HJT and have it fix these items (after disabling your anti-virus and spyware programs while you do this):
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O21 - SSODL: btrklfr - {304ABBDC-E0FC-4C88-98F2-697C6959682E} - (no file)
    O21 - SSODL: apdqnxp - {A2384D4D-CB6D-4A0D-8D6D-01B26B6BFC93} - C:\WINDOWS\apdqnxp.dll
    After checking fix, just exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file!
     
  5. emanpa

    emanpa Private E-2

    I have completed the instructions in your last post and finally attached the correct file MGlogs.zip. I apologize for not attaching the correct file the first time!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good...things aren't so bad.

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.
    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  7. emanpa

    emanpa Private E-2

    Well, I have been running my Aunt's computer for a couple of days and the Zlob Downloader.vcd is not appearing, so I think it is gone. I am not finding anymore viruses but the computer is still running slow. I have attached the MGZip.log and the Advenger log. Thanks for your help!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be aware that Norton could be slowing you up....and have you deleted all of your temp files?

    Be sure to tell us how things are running.
     
  9. emanpa

    emanpa Private E-2

    Well, I completed the last set of instructions and have attached the logs for Avenger and MGlogs. I have cleaned all the temp files a number of times. I think Norton is the culprit for the slow speed of the computer. When I disabled all the Norton junk, the computer work noticeably faster. Thanks again for all your help!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Looking good....Is Norton a paid subscription? (Yes, it is a resource hog and will slow thing down when on the internet).

    Let's just do some cleaning for your startup items:
    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Are you having any other issues? If not: it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2.
    * Click START then RUN
    * Now type combofix /u in the runbox and click OK.
    * Note: The space between the X and the /U, it must be there.
    3. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    4. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    5. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. emanpa

    emanpa Private E-2

    Re: Help! Can not run the Malware removal programs

    I am not quite sure what happened. When I was on the internet, my computer simply shut off. I have tried to run SuperAnitSpyware and Spybot; however my computer keeps shutting done at some point in the scan. It does the same when running McAfee. I can run CCleaner and Malwarebytes, Combofix, MGTools and Hijack this, but still doing the same. I have included the Combo Fix, MGtools, and Hijackthis files for your review. Any help would be greatly appreciated.:confused
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools is very out of date, you need to delete it and download the latest version form the Read and Run First instructions. Have you updated the virus definitions for SAS and MBAM?

    Use windows explorer to find and delete:
    C:\WINDOWS\system32\TDSSrppe.dat

    Now attach the new log from running the new version of MGTools and see if either SAS or MBAM will run.
     
  13. emanpa

    emanpa Private E-2

    Thanks so much for your assistance! I deleted the TDSSrppe.dat file. Removed and reinstalled SAS, SB, MBAM, Combo Fix and the new MGTools. I was able to run all programs in the "Read This..." and they found nothing. I have attached the logs. I feel like an idiot because I believe the problem was my laptop was overheating! I placed it on a fan and was able to run everything! :-D If you see anything that needs to be corrected, please let me know. System runs a bit slow, but don't they all! Thanks, again!
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Some times it is hard to tell the difference between malware and overheating..:), but in your case, it looks like you had both.

    You still need to disable the guest account in user accounts and Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    You may wish to use a Startup Manager

     
    Last edited: Nov 24, 2008
  15. emanpa

    emanpa Private E-2

    Thank you so much for your help and time! :wave
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds