Zlop detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Amandalynn, Mar 7, 2007.

  1. Amandalynn

    Amandalynn Private First Class

    Well just when you think you have your basis covered BAM you find something. needless to say here goes.

    Basic Computer Maintenance--Completed
    Preliminary House Cleaning and Setup--Completed
    Secondary House Cleaning -- Completed
    Enabled hidden files etc -- Completed
    Virus Scanner -- Norton
    Installation of programs -- completed

    Now for the fun part

    Step 5: In safe mode no networking

    Ccleaner--Completed
    Spybot--Completed
    CounterSpy-- Completed but with difficulties
    -Explanation- Detected four problems. At end of scanner it asked that I restart.. Unfortunately and without thinking I attempted to restart going back into safe mode. Clearly after giving some thought to the matter it makes sense that the program needed to start in normal mode as to not be stop (as safe mode doesn't let anything boot up). In Normal boot mode the Anti-spyware program ran its boot time cleaner and all was well (tip for those of us who like to follow order to the T you might want to put that in the directions ^_^ so that we don't panic when we can't get back into safe mode until booting once back into normal mode when the program asks us to restart)

    Step 6: Ok this is where things really went wrong

    Attempt one: In Safe Mode with networking

    Bitdefender -- would not update virus signatures and therefore did not run. It kept stalling around 23% and after 20 minutes of sitting I aborted the program.

    Panda ActiveScan -- Would not run at all in this mode

    Attempt two: In normal mode all extra processes shut down.

    Bitdefender -- After about an hour of running successfully the program just closed itself down. I was continually checking on the pc and it appeared to be going well and when I returned (I think the scanner had only 10 minutes to go) all the windows were just closed. However I did note that it had attempted to fix, then failed, then deleted, but failed to update a file that was in Systematic directory. Though I don't remember 100% of it it did have the words Banker and Trojan. (pitiful i know but thats all I remember.)

    Panda ActiveScan -- After updating itself and me selecting My Computer for it to scan it appeared after 30 minutes to be just sitting there having not progressed at looking past the Memory...

    Step 6b:

    GetRunKey.Zip -- Completed
    ShowNew.Zip -- Completed

    Step 6c:

    Not going to lie to you I didn't touch this one as I am a bit burnt out and am not sure my problems fall to any of these special cases.

    Step 7:

    Installed Hijack in D:\ProgramFiles\HJT
    Renamed to analyse.exe
    Saved file

    Step 8:

    This is where i stopped no need to do this until someone tells me I am safe and clean

    So on your word and after you look at what I have attached hopeful I can call it a night

    Peez oh peez let me be clean /sigh
     

    Attached Files:

  2. Amandalynn

    Amandalynn Private First Class

    And the Hijack This file
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's Zlob not Zlop. ;) And yes you should have looked at the Special Removal procedure since it is mentioned.

    First start out by fixing all thos junk O18 lines in your HJT log from that stupid Logitech Desktop Messenger. That will make your log smaller and save me the trouble of fixing them later. I even recommend uninstalling that piece of junk. Most people don't use it anyway and it just clutters up your registry and HJT logs with unnnecessary garbage.


    I'm going to post two sets of instructions below. Each will be enclosed in separate Quote boxes. Make sure to complete the first one 100% before moving on to the second one.

    ATTACH THE FIRST LOG NOW BEFORE CONTINUING OR YOU WILL OVERWRITE IT!!!! And then immediately continue on to the below steps.

    Now attach new logs from:
    • GetRunKey
    • ShowNew
    • HJT
    How are things working now?
     
  4. Amandalynn

    Amandalynn Private First Class

    Re: ZloB detected

    ok ok lol quick question is this in normal or safe mode?

    Bah n/m i see step to specifies and step one doesn't so it must be ok to do in normal I shall proceed
     
  5. Amandalynn

    Amandalynn Private First Class

    Ok i cleaned out an o18 lines with logitech desktop manager in them and will post a new Hijack this report when done with step two

    This is the rapport as requested in step 1
     

    Attached Files:

  6. Amandalynn

    Amandalynn Private First Class

    ok Step two completed and file attached i will make a new post with the request getrunkey shownew and HJT
     

    Attached Files:

  7. Amandalynn

    Amandalynn Private First Class

    Ok heres the GetRunKey ShowNew and HJT

    As for how things are working now... well Zone Alarm is starting up in lock mode where it stops all internet activity (not really a big deal) And well my desktop went from being my background of choice to blue (again not a big deal) and finally I am booting up a bit slower though i want to point out that before i ran the initial scans and what not I have had my pc in selective start up with all the boxes underneath checked (I remember doing that at one point but i don't remember why... so yeah that might be why i am starting up slower as i had some start up programs disabled ^_^)

    Lastly I wanted to ask you if removing the logitech desk top manager would have any ill effect on my G15 keyboard or wireless mouse.. Yeah ima gamer and well the keyboard is just something i can't live with out any more ^_^

    Oh snap i am sorry i didn't look in the special removal procedures... Let me know if i should do that now or if we are already doing it
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Check your settings. Under Program Control do you have Autolock enabled. This is not malware. If necessary, uninstall, reboot and reinstall.

    That's due to removing your Zlob infection.

    You should not be using MSconfig that way anyway. It is only meant to be used for temporary debugging and using it like you were for long term can result in a variety of issues and problems with uninstalling applications and all kinds of junk can be left behind making cleanup difficult. It even cause problems like seen in your log where you have things trying to load multiple times. Like these:

    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "D:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE


    Uninstall things you don't need.
    Configure program that you do need but don't want to load at startup in their own settings. If they don't provide those setting, delete the registry key loading them at startup using HJT or similar.

    I'll give you some pointers at the end of this message.

    Not as far as I have ever seen. It is basically adware in my book. Here is a blurb about it:
    Not anymore! ;) Are you still having problems.


    Pointers about Startups!
    1. Uninstall unnecessary items:
      • example we are finished with CounterSpy
      • Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
        • D:\Documents and Settings\All Users\Application Data\Sunbelt Software
        • D:\Program Files\Sunbelt Software
      • Also you should have uninstall all of the below in step 6 of the READ ME
        • J2SE Runtime Environment 5.0 Update 10
        • J2SE Runtime Environment 5.0 Update 11
        • J2SE Runtime Environment 5.0 Update 6
        • J2SE Runtime Environment 5.0 Update 8
        • J2SE Runtime Environment 5.0 Update 9
      • And then you should have installed the current version of Sun Java from: Sun Java Runtime Environment
      • Also consider if Logitech Desktop Messenger can be uninstalled. You don't really need it.
      • Check to see if you have other stuff you can uninstall if you never use it.
    2. Things that are never needed at startup: here are a few in this category
      • O4 - HKLM\..\Run: [HP Software Update] D:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      • O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.5.0_11\bin\jusched.exe" <-- this number will change when you install the new version
      • O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      • O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
    3. Things you may or may not need: Only you can answer that. Research them and figure out what to do with them
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE​

      O4 - HKLM\..\Run: [LanguageShortcut] "D:\Program Files\CyberLink\PowerDVD\Language\Language.exe"​

      O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE​

      O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Files\Logitech\Video\ISStart.exe​

      O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Files\Logitech\Video\LogiTray.exe​

      O4 - HKLM\..\Run: [HP Component Manager] "D:\Program Files\HP\hpcoretech\hpcmpmgr.exe"​

      O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "D:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE"​

      O4 - HKLM\..\Run: [ehTray] D:\WINDOWS\ehome\ehtray.exe​

      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE​

      O4 - HKLM\..\Run: [Launch LGDCore] "D:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE​

      O4 - HKLM\..\Run: [Launch LCDMon] "D:\Program Files\Logitech\G-series Software\LCDMon.exe"​

      O4 - HKCU\..\Run: [ATI Remote Control] D:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe​

      O4 - HKCU\..\Run: [Fraps] H:\FRAPS\FRAPS.EXE​

      O4 - HKCU\..\Run: [CTSyncU.exe] "D:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"​

      O4 - HKCU\..\Run: [ResChanger 2005] D:\Program Files\ResChanger 2005\ResChanger2005.exe​

      O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe​
     
  9. Amandalynn

    Amandalynn Private First Class

    Blah >.< and here i though i didn't miss any steps /sigh. Any why heres the actions to you last post

    Zone Alarm has been uninstalled and reinstalled and seems to be a happy camper now

    I have changed my back ground back to black ^_^

    And yeah I know I actually can't believe I had left it like that >.<

    Now as to the Pointers about startups

    CouterSpy has been removed and it appeared that the two additional folders have been too. (I am assuming that by doing this that it deleted files in the quarantine?) If not i am in big trouble as i didn't delete anything that it quarantined in the first round!

    Java updates have be uninstalled an the current version from Sun Java installed.

    Logitech desktop Messenger (manager?) has been removed.

    I have gone through and removed a few other things that i don't think I need but not much because you never know.... lol

    2. The 4 entries in HJT have been fixed

    3. I am going to do some research on these before I take them out but right now its to late to work on making my system gleam ^_^

    Now the only thing i would like to do before we call the case close is ask you if there are any tricks to removing Norton and what would be the best (least system resource hog) Freeware virus scanner i can get? As Norton once again messed up my subscription and I went from 280 days to 0 in two weeks...

    Lastly I am noticing an application that is flashing across my task bar. It is not named and is only appearing briefly. Its a bit hard to explain and i am not sure i can give you much more detail than that. Other than there is no application name nor recognizable application symbol. confused confused confused

    And yeah i am trying to squeeze in as many questions as i can before you have me toggle system restore and close my case ;)

    Let me know if i need to post any more reports or do anything else :)
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Norton can often be just as bad as malware to get removed. Here is what I would suggest:
    • Reboot just before doing the below but DO NOT run anything other than these steps
    • shut down all other applications (every thing in the tray ...etc) including antispyware tools
    • goto add/remove programs and uninstall all Symantec and Norton software
    • reboot and take a quick peak at your HJT log for anything left over from Symantec or Norton.
    • if there are left overs run this: Norton Removal Tool (SymNRT)
    • then reboot and check another HJT log. If you still have things from Symantec or Norton you may need help from us to remove because often times they are services which must be stopped and disabled before they can be deleted.
    I suggest you use AVG Free which is one of the tools give in the How to protect link further down in this message.

    • Does it happen in safe mode?
    • Does it happen after uninstalling Norton?
    • How often does it happen?
    • Does it happen when not connected to the internet?
    • Is anything else in particular running when it happens?
    It could just be some periodic activity from a scanning tool, or from one of the other many items you are running.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. Amandalynn

    Amandalynn Private First Class

    Re: ZloB detected

    Ok I ran the steps suggested to remove Norton. I did not see anything in my HJT log however i do notice a few missing files or missing buttons. But would like your guidance on whether or not to remove them.

    Now as to the mysterious application in my task bar it just so happens that it pops up quite a bit and is rather annoying as i play games in window mode and it makes my screen go inactive for the 15 or 20second it takes for it to load past. I did not notice this at all in safe mode. Now for the juicy part. It popped up while i was removing Norton and just so you can see i have attached a pic ^_^

    I am not really sure it it happens when connected to the net or not as i am always connected ^_^ love me some cable internet!

    As for the final steps I will delete the shownew.zip and getrunkey.zip once you take a last look at my HJT. My only other question is do i need to run CCleaner one last time before i do the system restore ^_^
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: ZloB detected

    No! They are not missing. It is a HijackThis bug and the they have nothing to do with Norton anyway.

    You can always just unplug the cable which means you are not connected. That is an easy enough thing to do.

    Let's run a couple other tools before moving on to those final steps I gave you. Since it does not show in safe mode, it could just be due to some application you run in Normal boot mode but not in safe mode. However, I want to dig in a little deeper to check for possible rootkits.

    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

    And as a backup to the above run this Using Sophos Anti-Rootkit and attach the requested log.



    Also run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT
     
  13. Amandalynn

    Amandalynn Private First Class

    Ok here you go. It is still popping up and yes it only appears to be happening when i am connected to the internet >.<
     

    Attached Files:

  14. Amandalynn

    Amandalynn Private First Class

    show new log
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well there are no rootkits and there is no obvious malware based on your logs. It would appear that your problem is not malware but rather just something you are running.

    And it does not occur in safe mode either based on a previous message.

    Thus I suggest you use MSconfig for its intended debugging purpose. Use it to disable all startups and selectively enable them one at time with a reboot after each one (yes it is tedious - a faster method may be the powers of 2 method, i.e, do half at a time and each time no problem is found half the group is eliminated....etc). See if you can isolate the problem this way. If the problem is not in the Startups tab area of MSconfig, you will need to try the same thing with the Services tab of MSconfig although you may want to start by hiding all Microsoft services to save yourself some time.
     
    Last edited: Mar 9, 2007
  16. Amandalynn

    Amandalynn Private First Class

    Don't think i have given up! i am working on this ^_^ and just wanted to keep you posted I shall return when i have news!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So then I assume you knew what I meant by using MSconfig to debug this?
     
    Last edited: Mar 9, 2007
  18. Amandalynn

    Amandalynn Private First Class

    Yep you want me to control what is starting up... select half of the programs in a selective start up and see if it happens... then eliminate by half etc to try to nail whats doing this. Now if i can't figure it out using the programs then i move to the services tab hiding window's processes (as to not totally mess up my computers OS from starting) ^_^ Yep i got it! I have to do work on my machine for work so i have had to cut back i a bit of my selective start up so i can get my stuff done ^_^ but i should have time this weekend to figure it out!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Good luck and let me know your test results! ;)
     
  20. Amandalynn

    Amandalynn Private First Class

    An Update

    I have yet to isolate the mysterious program that keeps popping up >.< However my MSN now hates Lineage causing major lag client side while playing the game and speaking in ventrillo.. I have posted in the software thread about this issue and hopefully i can find a way to resolve it so I wont go into detail here.

    The hunt continues!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: An Update

    Have you stopped all processes from loading at startup?

    What about Services?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds