zlob Trojan and VideoAccess problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by holycowbabe1, Dec 6, 2008.

  1. holycowbabe1

    holycowbabe1 Private E-2

    I noticed that on Friday around noon, my PC started freaking out. It started popping up web pages in IE (and I use Firefox). So I guess that some how I got a virus/trojan. I am guess that it was from doing a search on a news artical that I saw on the Yahoo link when I was reading my Yahoo mail. Cannot figure out were (or when) else it was from :-(
    The worst thing, is that I did not have a copy of a restore point. Not sure if one of the virus/trojans that I was infected with did that, but I made DANG sure I am going to have a few restore points from now on. As a side point, is there a way to "protecting" your restore points (making them so that they cannot be deleted?)?

    I was running McAffee, but it was expired. It only expired about a week ago :-( Unfortunately when McAffee expires, it no long lets you run a scan. I had already bought Kaspersky and installed it on my other machine. I had a bit of difficulty installing it so that is why I did not have it installed on the new PC (I am expected to support my other family members PCs, so I need to make sure that it was a good product and knew how to install it properly). Kaspersky found a few viruses and trojans and I though I was good. However, I was still getting strange behavior like xeplorer not shutting down when you reboot. So I got a free copy of spyhunter and it found a number of different trojans, viruses, and malware :-(

    I followed your steps on the sticky thread " Read & Run Me First, Malware Removal Guide" and it seemed to have cleared out a few more. However, according to SpyHunter, I still have:
    Zlob.Trojan
    Zlob.VideoAccess

    So following your steps in the link, here are the first two logs.
     

    Attached Files:

  2. holycowbabe1

    holycowbabe1 Private E-2

    Here are the second two files :

    (apparently I already posted the first time around, but it timed out so I thought it was not posted ... but it was ... and you can ignore this comment since I am just babbling :)
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Not really. Malware would just bypass it just like it bypasses the current protections that Windows already has inplace. In addition, many forms of malware can make a PC unbootable in either safe boot or normal boot mode. System Restore will not help you when your PC cannot be booted; however, using the Recovery Console, you can restore some registy hives yourself to sometimes work around this.


    Not recommended. In fact, I suggest that you uninstall it.

    We have a little more work to do.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 12

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. holycowbabe1

    holycowbabe1 Private E-2

    Well.. Unfortunately, according to spyhunter I still have a trojan on the PC. I have not found another scan utility that detects this trojan. So I am not too sure I want to uninstall it at this point.

    I did uninstall the java application already. I do not see the J2SE application in the add/remove programs. I also cannot find it on my PC (unless I have hid it on my self :)

    Here are the logs that you requested.

    Unfortunately, I do feel comfortable with my PC yet. So I will simply reload it. I wish I would have done that from the start. At least I would not have waisted your time (and mine).

    Thanks for your help, but you can ignore this thread now.
    Sorry to take up your time. Was hoping for a quick fix.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was one of the main reasons for not recommending it. At one time this program was even considered a rogue application. It finds things that don't exist or that are not real problems (called false positives) or it finds trivial non-issues and makes them out to be issues. I would be willing to bet the Spy Hunter had no idea about all the things I just had you remove in the last fix.

    At anyrate, if you have already reinstalled, none of the above matters anyway but a reinstall was not necessary because your logs were clean. We just needed to cleanup System Restore points (in fact Spy Hunter may have just been referring to System Restore) and perform other final cleanup steps but I will not post them since you are reinstalling.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds