Zlob found in spybot S&D

Discussion in 'Malware Help (A Specialist Will Reply)' started by TsMachine, Jun 16, 2008.

  1. TsMachine

    TsMachine Private E-2

    I'm doing what I can for a neighbor's computer. In running the SpyBot S&D, ZLob was found. I saw a thread for special removal for this, and I do have a question.

    Do I continue the "read and run me first" and then do the special procedure, or stop and run the special procedure instead?

    Thank you for any help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Since many newer infections are causing additional problems on most PCs, I recommend that you follow the instructions in the READ & RUN ME and skip the SmitFraudFix procedure.
     
  3. TsMachine

    TsMachine Private E-2

    Thank you Chaslang, I'll proceed on then.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. When finished, just attach the requested logs to your next message in this thread.
     
  5. TsMachine

    TsMachine Private E-2

    Ok. This machine has some big problems. My neighbors have zero capability with any form of malware eradication. She is only *now* learning to use the computer, and he speaks only spanish and has minimal skills using the computer. (fortunately both Mrs, and my roommate speak fluent spanish for later instruction on how to avoid this in the future).

    What has been happening and why I was asked to see what I can do for it, is they're having two applications (yahoo yop.exe, and ares, a music site they belong to) give continual error messages that the exe is corrupt, unreadable and to run chkdsk. This doesn't resolve the issue. When I first got to this machine, I downloaded, installed and ran the SpyBotS&D. (which after I did, was when I made my first post.

    During the entire READ ME FIRST tutorial process, anything I downloaded, installed popped up error after error (name of exe corrupt and unreadable, run chkdsk) During the mbam it was particularly frustrating with a spate of errors.

    Here are the logs as requested in this post and the next.

    WinXP home SP2 Dell Dimension DV051 Pentium (R) 4 CPU 3.20GHz 3.19GHz, 504 MB RAM
    connect via broadband DSL att yahoo
    Firefox Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.14) Gecko/20080404 Firefox/2.0.0.14
     

    Attached Files:

  6. TsMachine

    TsMachine Private E-2

    and the 4th log

    Thank you in advance once again!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This issue may not be due to malware. You may need to uninstall them, reboot and then reinstall but let's see what happens after finishing the below.

    Uninstall the below software:
    LiveUpdate 3.2 (Symantec Corporation)
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. TsMachine

    TsMachine Private E-2

    It was successful.



    the two logs are attached.

    I'm getting errors with each step and application that I use to scan with (at the bottom in the systray section) of corrupt exe. One I got was "attrib.exe is corrupt and unreadable. Please run chkdsk".

    It's still saying as well that the yop.exe is corrupt and unreadable please run chkdsk. The concern is that is some part of their DSL connection.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  10. TsMachine

    TsMachine Private E-2

    I know neither of my neighbors did (as neither would know how) but the machine was bought from a Rent to Own company, and they serviced it several months ago before my neighbors had finished paying it off. Mrs called the company and the rep there looked up the servicing and said that a system restore had been performed.

    When I tried to attach the gmer log I got this error:

    :confused
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If this is the root of the problem (like in the link I gave) then a reinstall may be necessary.

    Compress the log into a ZIP file and attach the ZIP.
     
  12. TsMachine

    TsMachine Private E-2

    Just attaching that now.

    I was able to run the chkdsk in safe mode, after I got those scan results for the gmer. Glad to say I've had it booted in regular mode and haven't had any errors demanding a chkdsk. I will say this, that chkdsk took WAY longer than those on my own machine! (mine.. less than five mins. Theirs... more than three hours)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you still having any problems with this PC?

    The rootkit scan was clean.
     
  14. TsMachine

    TsMachine Private E-2

    It's working beautifully!! I ran another spybotS&D and got the congratulations, no threats detected screen. I also did a defrag on this as well. My next step will be to teach Mr and Mrs how to prevent these kinds of problems in the future.

    One thing tho, one of the scans had said it was going to change the clock to a 24 hour clock but would change it back when it completed.. yet, it's still on 24 hour time.

    Other than that, it's working great and we thank you so very much!!

    :cool:):wave
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can fix your clock from Control Panel ->Regional and Language Options and then on the Regional Options tab click the Customize button then on the next form click the Time tab. Then change the Time format to what you want. It explains there what the lower case and upper case letters will do. Upper case H is giving you 24 hour clock settings.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds