Please Help! Win32:Zlob

Discussion in 'Malware Help (A Specialist Will Reply)' started by Maltesefalcon, May 23, 2006.

  1. Maltesefalcon

    Maltesefalcon Private E-2

    Hi, I hope someone out there cn help me. I have a pc that is infected with the Win32:Zlob virus and I cannot get rid of it. I have followed the MajorGeeks "READ & RUN ME FIRST..." post as far as I can - the only bit that I haven't done is section 6, the online scanning. I'm behind a firewall and cannot get Bitdefender or Panda Active Scan to work.
    In safe mode I've run Crapcleaner, then MS Windows MSRT then Ad-aware SE, then Spybot S&D, followed by MS Windows Defender, and then just to make sure, I've run a thorough scan of all drives using the Avast AV software that's installed. Ad-aware foun the Win32:Zlob, then Avast found it again. I deleted the suspect files, wnet through all the scans again, found that I was then clean and so rebooted in normal mode. As soon as I logged on the little blighter was back, laughing at me when I checked processes in Windows Task Manager - "hpqtra08.exe". So I did all the above again, with the same result, - clean in safe mode, infected in normal mode. Running the scaners innormal mode, the virus is found but cannot be deleted, moved or renamed - it's in use by something else. Please see the latest Hijackthis log file attached. Please help!
     

    Attached Files:

  2. Maltesefalcon

    Maltesefalcon Private E-2

    Forgive my mistake - hpqtra08.exe is a red herring. I was confusing it with the various incarnations of hp9a4c.tmp / hpd1be.tmp, etc, that the virus has been using.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So am I and many others who have run the procedure. There is should be no problems running those online scanners thru the firewall. You should run them and attach the logs.

    Also run the below and attach the smitfiles.txt log:

    SpywareQuake & SpyFalcon Removal Procedure
     
  4. Maltesefalcon

    Maltesefalcon Private E-2

    Hi,
    I ran the Spywarequake and Spyfalcon removal procedure that you advised, with the following results:

    * %System32%\__delete_on_reboot__stickrep.dll
    * %System32%\dvdcap.dll
    * %System32%\dxmpp.dll
    * %System32%\fyhhxw.dll...
    etc - didn't have any of those files.

    # %System32%\dcomcfg.exe
    # %System32%\regperf.exe
    # %System32%\simpole.tlb
    # %System32%\stdole3.tlb
    These were present and so I deleted them.
    Rebooted in normal mode and the virus seems to have gone.
    Smitfiles.txt attached.

    Thanks for the help.
    Still can't get either Bitdefender or Panda Activescan to run, even after turning firewall off. Never mind though - problem fixed!
    Many thanks.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That just proves what I said.....it was not a firewall related issue. ;)

    You need to make sure the below lines from your HJT log are fixed:
    O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hpD1BE.tmp
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)


    Aftewards, if you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds