win32.trojandownloader.zlob false positive/causing disconnects?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by zeliad, Nov 26, 2006.

  1. zeliad

    zeliad Private E-2

    Hi,

    I'm using Ad-aware and every time I check my system with it it shows win32.trojandownloader.zlob infection...over and over again even if Ad-aware fixes this the next scan shows an infection.
    Now I don't have any particular problem with it because there are no pop-ups/system slowdown issues with my comp but recently I'm experiencing strange things with my ADSL: the dataflow suddenly stops (it appears to be totally random when) and after 2-3 minutes my connection breaks up and I can't even redial, I have to reboot my modem to be able to reconnect. My ISP says they checked the logs and according to them the modem disconnects are always "called", so there must be a prob with my LAN card. I checked 4 different LAN cards and the issue is still here. Could it be that this win32.trojandownloader.zlob causing the problem?
    I did all the steps mentioned in "READ & RUN ME FIRST Before Asking for Support" post and here are the logs you request (except Panda because it didn't offer saving a log...it didn't find anything tho).

    Thanks in advance for helping!

    Zel
     

    Attached Files:

  2. zeliad

    zeliad Private E-2

    And the remaining logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majrogeeks!

    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.


    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. zeliad

    zeliad Private E-2

    Hiya Chaslang,

    Unfortunately Ad-aware still detects win32.trojandownloader.zlob after doing the 2 steps you suggested, on the other hand I didn't have the chance to reproduce the net connection brake. Here are the logs.

    Zel
     

    Attached Files:

  5. zeliad

    zeliad Private E-2

    ...and the others :)
     

    Attached Files:

  6. zeliad

    zeliad Private E-2

    Ahh nevermind my post it DID clean the malware :) A lot of thanks to you!

    Zel
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well your logs are basically clean but I see some things to fix.

    You did not install the proper version of Spybot given in the READ ME. What you are using has not been used in more than two years. You should fix this.

    You also need fix a few things with HijackThis but they may not fix since you are running Spybot's Teatimer which we asked you not to run in the READ ME. So uninstall your old version of Spybot and then fix the below.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - (no file)"
    O20 - Winlogon Notify: winaqh32 - winaqh32.dll (file missing)
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    After clicking Fix, exit HJT.


    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6

    Now install the current version of Sun Java from: Sun Java Runtime Environment
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds