zlob removal via remote

Discussion in 'Malware Help (A Specialist Will Reply)' started by nosmo king, Jun 14, 2006.

  1. nosmo king

    nosmo king Private E-2

    Hi
    my first post here
    My pal has the zlob trojan and all the fake spyware pop ups and shields etc talked about in this forum.
    My question is, can I clean his pc for him via remote assitance using the tips you have provided in the other posts?
    Thanks in advance
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You would probably run into some problems trying to do that since you need to get into safe mode to do some steps.
     
  3. nosmo king

    nosmo king Private E-2

    managed to get the pc to me and did what you sugessted in another post
    can you look at logs and advise please
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You got rid of Zlob but you have other issues to take care of. You need to run the below procedures to get help with those. We do not use HijackThis at the first stage since it does not give a full picture of problems. Also HijackThis must be installed and run properly and MSconfig must not be used to control startups.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  5. nosmo king

    nosmo king Private E-2

    thaks Chaslang and sorry for the delay. I got my pal to read in here and he has sent me his logs for you to look at
     

    Attached Files:

  6. nosmo king

    nosmo king Private E-2

    oops 1 missing
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to get HijackThis installed correctly per step 7 of the READ ME. It is being run exactly how we specify not to run it. And that is, directly from the ZIP file. No backups can be created while running this way.

    You need to uninstall either Bitdefender Antivirus or AVG. Read step 3 of the READ ME again. If you installed Bitdefender Antivirus while doing step 6 of the READ ME, then you did the wrong thing. Step 6 is an online scan only. It does not ask you to install Bitdefender's Antivirus application. Either way I need a log per step 6 for the Bitdefender online scan.

    Is the installed copy of Ewido a paid version or a free trial? If free, uninstall it and keep Windows Defender.
    If Ewido is a paid version, keep it and uninstall Windows Defender.

    After correcting the above, continue to the below!


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - Default URLSearchHook is missing
    O2 - BHO: ohb Class - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\system32\SearchTool\nsg69.dll

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\system32\SearchTool <--- the whole folder
    C:\Documents and Settings\carl\Local Settings\Temp\temp.frAB2D <--- the whole folder
    C:\Documents and Settings\carl\Local Settings\Temp In fact, it would be best to delete all files and subfolder s in this Temp folder. Windows will not let you delete ones from the current date. That's OKAY!

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Jun 27, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds