Request for Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by craftyfrog, Feb 13, 2007.

  1. craftyfrog

    craftyfrog Private E-2

    Hi,
    I have a system alert flashing on my system tray, and it is trying to get me to download antispyware tools.. I have not done so as I suspect it to be rogue spyware. I believed I have a trojan, as files were in my favourites list which I did not put there. I deleted them and have run antivrus and spyware programs. My cable suppliers anti virus discovered nothing , but Lavasoft Ad aware detected a trojan. Zlob.gen.1

    I then followed the directions given in the read and run me first file on this forum.
    Panda found nothing , and counter spy detected the trojan but did not give me an option to view and save a report, just scan, result and exit.

    After rebooting in normal mode I still have the alert flashing.
     

    Attached Files:

    Last edited: Feb 13, 2007
  2. craftyfrog

    craftyfrog Private E-2

    hijack this log
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?

    Also please try something for me! Run CounterSpy in normal boot mode and see if your can fix things and save a report this way!
     
  4. craftyfrog

    craftyfrog Private E-2

    Thanks

    Step one log attached
     

    Attached Files:

  5. craftyfrog

    craftyfrog Private E-2

    Step Two log attached.

    System alert popup has now disappeared.
    Will attach next set of logs, then run counterspy in normal mode
    Thanks for your help !
     

    Attached Files:

  6. craftyfrog

    craftyfrog Private E-2

    logs attached
     

    Attached Files:

  7. craftyfrog

    craftyfrog Private E-2

    results from counterspy
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    Mozilla Firefox (1.5)
    System Alert Popup <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O21 - SSODL: didymiums - {e6adaaf0-79b2-4cf1-a660-50a0b33991a1} - C:\WINDOWS\system32\vblhanf.dll (file missing)

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now reboot in normal mode

    Now locate the below folder and delete it if found:
    C:\Program Files\Video ActiveX Object

    Now run Ccleaner

    Now attach the below new logs and tell me how the above steps went.
    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  9. craftyfrog

    craftyfrog Private E-2

    sorry I missed some of the first steps .. I should also have mentioned that I was unable to remove the system alert popup at the time. (have done so now)


    I followed steps above

    Counterspy did not leave files behind.

    I was unable to find this line in Hijack This : C:\WINDOWS\system32\vblhanf.dll (file missing)

    Video Active x was also not present in Program files.


    (Have had my cable supplier change owners recently and they have made some changes to their antivirus/spyware package and Windows updates have also been installed today)

    No visible signs now of malware and system running quickly.

    Thanks again, I appreciate your time. Hope I 've followed instructions properly.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you don't appear to have Symantec software installed anymore, goto Add/Remove programs and uninstall LiveReg (Symantec Corporation)

    Also use HJT to fix the below lines:
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
    O21 - SSODL: didymiums - {e6adaaf0-79b2-4cf1-a660-50a0b33991a1} - (no file)


    Your logs are clean other than the above. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. craftyfrog

    craftyfrog Private E-2

    Many Thanks !!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds