New win32:zlob variant?

Hey guys,

Avast came up with a couple of new trojans and it’s really irritating me, been working on my computer ever since I got home from work lol. They are: win32:Spyware-gen [trj] and win32:Zlob-CP [trj]. I turned off system restore and ran a boot scan, deleting them as they came up. A search on this site comes up with the -CP variant having been updated in the VPS on 5.22, but somehow still made it through to infection. Other than that, I can’t find ANYTHING anywhere (at least on sites I trust to open) about this variant. I tried looking at what some of it’s cousins are doing, and tried to follow removal procedures for those, but it doesn’t seem to be working. I even tried trying to find the values it adds to the registry, but couldn’t find them. (weird?) These guys have hijacked my computer in such a way, that any program I run that connects to the net (firefox, IE, iTunes, World of Warcraft), doesn’t seem to be able to make a connection. But, I am connected, I can ping any domain in the world succesfully. It also seems to have hijacked windows firewall, I always keep it on, but when I came home, it was turned off and I can’t turn it back on. Any help you guys could offer would really help, tired of pulling my hair out on this one.

Running XP SP2 and Avast 4.7 Home Ed.

I know it’s a generic answer but, can’t you scan your system with antispywares and antitrojans applications?
Ad-Aware, Spybot Search and Destroy, A-squared, Ewido or Microsoft AntiSpyware or TrojanHunter (shareware).

Antispyware applications (freeware): download, install, update and run it.
Ad-Aware
Spybot Search and Destroy
Spywareblaster
A-squared
Ewido
X-Cleaner Free
TrojanHunter

About legit antispyware applications or the bad ones: http://www.spywarewarrior.com/rogue_anti-spyware.htm#sites

Some useful info here: http://www.slyck.com/spyad.php?page=1

I started having the same problem yesterday afternoon but the main issue is that I don’t have internet access even though I can connect to the network and therefore Avast is unable to update, it keeps coming up with errors and I am unable to download any software.

Help! how do I get back my internet access.

Can’t you download the avast updates in another computer and update your avast off-line?
Can’t you schedule a boot time scanning with avast?

Zlob is usually associated with SmitFraud, so it’s worth running SmitFraudFix followed by Ewido.

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

*If this fails to work, you probably have a new variant of the malware- new variants are emerging very rapidly with this one- and you will need to submit your log to a specialist anti-spyware forum- they will direct you to another forum where you can upload the file causing the problem for analysis. SmitFraudFix will then be updated to fix your problem.