TrojanDowloader.Zlob.300

Discussion in 'Malware Help (A Specialist Will Reply)' started by FreddyB, May 2, 2006.

  1. FreddyB

    FreddyB Private E-2

    Hi.

    I've managed acquire! some spyware by accident, that is causing me problems. It started with Puper.dll which was highlighted and then deleted by my AOL online version of Mcafee virus scanner, that seems to have gone away and now another Trojan TrojanDowloader.Zlob.300 is operating in the same manner. The result is my IE Browser is hijacked and it keeps sending me to Maware removal sites. I am a fairly inexperienced user but have managed to run a number of Spyware programs as posted on various bulletin boards but to no avail.

    Can anyone help please? I have a HJT log file if this is any use?

    Thamks FreddyB
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi there FreddyB

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    Please follow the guide steps in the order they are listed,

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
     
  3. FreddyB

    FreddyB Private E-2

    Thanks, will do later this evening when I'm back from work.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After running what Halo gave to you and attaching the three logs that were requested, you should work thru the below procedure if you are still having problems:

    SpywareQuake Removal Procedure

    Make sure you attach the smitfiles.txt log afterwards.
     
  5. FreddyB

    FreddyB Private E-2

    Hi, at last I completed the process - BUT with no result!

    I have attached all the log files you asked, hopefully you can find something that's causing the problem.
    A quick update on sumptoms - I still have puper.dll infecting various random files ( i though this had gone away but it hasn't), I now also have about:blank, I have followed the procedures outlined in this forum but its still there!!

    A summary of attempted fixes:

    malicious software removal found no files infected
    Ad-aware 4 negligable objects cleaned
    Spybot - log attached some infected file removed
    Defender - no unwanted files found
    CWShredder - no files found
    Kill2me - Look2me has been removed if present - it said!
    Bitdefender - logfile attached
    Panda -file attached.

    Some other - maybe unconnected things but I will list them anyway:
    Standby button is greyed out on restart - so is inoperable
    If I access your site in safe working mode (with networking - because safe working mode alone will not get past MPUP file load) I get a screen freeze if I enter my logon details.

    Thanks in advance.

    FreddyB
     

    Attached Files:

  6. FreddyB

    FreddyB Private E-2

    further files...
     

    Attached Files:

  7. FreddyB

    FreddyB Private E-2

    and finally..
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And finally what? Did you forget to post something? Like the smitfiles.txt log from running the SpywareQuake procedure????

    You did not follow the directions in step 6 for obtaining a Bitdefender log and as a result you post a log summary which is of no use to us. It does not indicate where problems were found and if they were even fixed. The directions must be followed in the READ ME as specified to get a proper log.

    You also did not follow the instructions in step 7 of the READ ME for installing HijackThis. You put it here:

    C:\Documents and Settings\Dad\Desktop\HijackThis.exe

    This is exactly where the instruction specify not to install it. Please fix this.

    Are your copies of Spyware Doctor and Spy Sweeper paid versions or free trials?
     
    Last edited: May 5, 2006
  9. FreddyB

    FreddyB Private E-2

    Ok sorry, I'm not an experienced user that's why it took me so long to do this routine. I will clear everything and go through it all again and hopefully post information that you can use.

    Thanks.

    The 'and finally' is a file that somehow will not attach it was the bdscanlog.txt file - I'll give it another go here.

    Spyware doctor is a free trial, Spy sweeper is purchased.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps it is too large to attach. You need to watch for error messages.

    Then uninstall Spyware Doctor and Windows Defender and keep only Spy Sweeper. Make sure Spy Sweeper has updated definitions.

    Also uninstall Viewpoint Media Player as mentioned in step 0 of the READ & RUN ME.

    You also need to run the below procedure mentioned earlier:

    SpywareQuake Removal Procedure

    Then attach the requested smitfiles.txt log.
     
    Last edited: May 5, 2006
  11. FreddyB

    FreddyB Private E-2

    Hi.

    Ok, here goes again, O pray I have got thios right for you guys this time.

    Followed all tasks, including Spyquake removal and about:blank removal - note I still have problems with about:blank even so.

    The only files found in your list on Spyquake removal were :-
    dcomcfg.exe
    atmclk.exe

    simpole.tlb (this is the one that Mcafee keeeps telling me has been infected by puper.dll)

    Files that should be attached are :

    Ab1.txt
    Ab2.txt
    Activescan.txt
    bdscan.txt
    hijackthis.log
    smitfiles.txt

    Good luck and thanks.

    FreddyB
     

    Attached Files:

  12. FreddyB

    FreddyB Private E-2

    .. and the final 2...
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not have an about:blank hijacker problem, thus you do not need to run any of those procedures anymore.
    You forgot to uninstall Windows Defender. You don't need it and do not want it if you have Spy Sweeper installed. Uninstall it now before continuing. Then shutdown (not uninstall) Spy Sweeper or at least disable all real time protection from it. Then continue with the below.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O3 - Toolbar: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - (no file)
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)

    After clicking Fix, exit HJT.:

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  14. FreddyB

    FreddyB Private E-2

    Hi Chaslang.

    Carried out those steps, now deleted Windows Defender and sticking with Spysweeper!

    New HJT log attached.Please note that the following entries DID NOT exist in the HJT scan this time around, not sure if this is significant or not?

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)


    Info that might explain this - since my last post I have removed MS Java and also removed and reinstalled Sun Java as your last post advised. A scheduled Mcafee virus scan ran overnight and found the puper.dll infection again, this time in 4 files that were in the Restore files. Also TrojanHunter found TrojanDodownloader.Zlob.350 this time - in the restore files again?

    Hope all this helps

    Thanks again for your work here, it feels like we're getting clean

    FreddyB
     

    Attached Files:

  15. FreddyB

    FreddyB Private E-2

    ... just read back my earlier post and it may be confusing. For clarity, the entries I detailed in my last post did not exist in the HJT I ran as per your last post request, so I ran Click and Fix on the remainder, ok?

    Also forgot to mention things look okish, I still get the Windows32 folder openend up on the desktop at startup - not sure why this is? and the Stabdby button is still greyed out (and hence you can't use it) on the restart function, not sure if these are related problems or not.

    FreddyB
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you forget to fix these two:

    O4 - HKLM\..\Run: [MyWebSearch Email Plugin]
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe

    They are still in your log! Try fixing them again but you must make sure NO browsers are open and you must shut down Spy Sweeper before fixing. Fix them and make sure they are gone. The System32 folder opening at startup is normally due to a corrupt startup item trying to loading. The MyWebSearch Email Plugin one could be doing it. Post a new HJT log so we can be sure they are gone.

    Also run the below procedure and attach the runkeys.txt log.

    Using GetRunKey
     
  17. FreddyB

    FreddyB Private E-2

    Hi Chaslang.

    Please find attached new HJT file and also runkeys.txt

    Thanks.
    FreddyB
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Shutdown Spy Sweeper before doing the below or it may not work!! You may also need to shutdown any McAfee active protection as it could be blocking changes too.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to add into the registry.
    Now reboot your PC and attach a new HJT log! Also see if the system32 folder problem is gone.
     
  19. FreddyB

    FreddyB Private E-2

    ...new HJT attached, Win32 screen at startup now dissappeared, PC seems to be running really well now, a lot faster than before. Standby button still not working? maybe this isn't connected with the malware problems?

    Thanks again

    F.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it is not a malware issue but I'll give you something to try. If it does not work, you should try the Software Forum.
    1. Click the Start button
    2. Select the Control Panel
    3. Click the System icon within the Performance and Maintenenace section
    4. Select the Advanced tab
    5. Click Settings within the Performance section of the form
    6. Select the Advanced tab
    7. Near the bottom there is a Change button, click on this button
    8. Within the Virtual memory section there is a System managed size button. Click this button.
    9. Now click OK -- about 3 times, to exit the settings.
    10. Reboot your PC.
    Is the Standby button working now?

    Your HJT log was clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  21. FreddyB

    FreddyB Private E-2

    ... I will try the standby fix suggestion when I get back home from work ta.

    Also, I will complete the Disable System Restore step and things should be just fine from now on???

    I really appreciate your help here, I'm intrigued as to how / why you help complete strangers out of a mess which is mainly self inflicted? do you do it for love?

    You're a real star anyway Chaslang, thanks again...

    FreddyB
     
  22. FreddyB

    FreddyB Private E-2

    ... Restore disable and enable completed, all ok now. Standby fix didn't work though? what do I need to do raise another thread?

    Ta. FreddyB
     
  23. FreddyB

    FreddyB Private E-2

    Srandby fixed thanks to one of your colleagues, it was a video driver related problem thanks again.

    fB
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! I'm happy to hear you got that last issue worked out. Make sure you complete the steps in the How to protect thread!
     
  25. FreddyB

    FreddyB Private E-2

    I'm ok to close this thread now. Have a great day.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds