Help with Zlob Removal Step 2

Discussion in 'Malware Help (A Specialist Will Reply)' started by trisha, Dec 22, 2007.

  1. trisha

    trisha Corporal

    I ran the suggested steps for Malware removal up to and including SpyBot SD.

    I ran SB in Safe Mode and it detected Zlob.Defender.rid.

    I ran step 1 of the generic Zlob removal tool. The next suggestion is to attach the report before proceeding to step 2. SpyBot said it successfully removed the file. However, earlier today when I ran Avast! it found 10 files and put them into quarantine. They were all Win32.Trojans. I instructed all the files to be sent to quarantine but when I checked the quarantine area there were only 5 files there.

    Please read the file produced by running the Zlob removal tool and advise.

    Thanks. Oh, I am running WindowsXP
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should complete step 2 with SmitFraudFix and then attach the second rapport.txt log. Then you should complete the remainder of the READ & RUN ME and attach the requested logs from it.
     
  3. trisha

    trisha Corporal

    I ran step 2 of the Zlob Removal and attached the resulting report. Zlob removal step 2 was run in safe mode.

    Prior to viewing your reply and while talking to a friend I happened to glance over at my computer a saw several popups. Upon closer inspection of the pop ups they mentioned YourPrivacyGuard. I did not do anything to cause these pop ups to appear as I was not sitting at the computer. The last action was to hit reply to an email.

    Since running step 2 the pop ups have stopped.

    I will continue with the remainder of the Read and Run This procedures and await your reply regarding the results of the rapport.txt file.
     

    Attached Files:

  4. trisha

    trisha Corporal

    I completed the remainder of the steps in Read and Run First including a rescan in safe mode using SpyBot.

    SpyBot: Nothing found

    AV: Nothing found

    All requested files are attached.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java(TM) 6 Update 2
    Spybot - Search & Destroy 1.4

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: BDEX System - {7F719D62-623C-4F70-9244-8CAEC58B041B} - C:\WINDOWS\ttvbonfwt.dll (file missing)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: The leosrv - {C31D988D-A314-49BB-BA51-7F57DEE5EA34} - C:\WINDOWS\leosrv.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now reboot.

    After reboot, run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.


    Make sure you tell me how things are working now!
     
  6. trisha

    trisha Corporal

    All tasks performed and log file is attached.

    The only problem I had was after removing Windows Messenger. Outlook (not Outlook Express) hung twice when I tried to open the program. It still loads really slow.

    What AV do you recommend? I am less than happy with Avast! because it fails to alert 100% of the time. When I read the log file there is usually a bunch of warnings listed about Trojans but the program did not produce an audio/visual alert at the time of the occurrence. Of course I am asking about your recommendation of a free AV.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    DO the below in Outlook:
    1. On the Tools menu, click Options, and then click the Other tab.
    2. Click to clear the Enable Instant Messaging in Microsoft Outlook check box, and then click OK.
    The above comes from: http://support.microsoft.com/kb/302089

    Avast is one that is on our recommended list. You will see others in when you get to the link in the below final instructions. You could try AVG Free. Make sure you uninstall Avast first.


    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  8. trisha

    trisha Corporal

    I should have been clearer about the version. I am running Outlook 2003 and MS did away with the option you indicated.

    I could not locate that file in the Windows folder.

    I am not having anymore problems so I toggled system restore. I will consider your suggestion of trying AV Free. I realize that Avast! is causing Outlook to hang.

    Thank you for all of your help.

    Have a Merry Christmas or should I say Happy Holiday? Hmmm

    Trisha
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it is already gone. ;)

    It is probably doing a scan of email which is one of the features in Avast.

    You're welcome. Enjoy your holidays too!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds