Trojan-Downloader-Zlob and other problems found.... Need Help Please

Hi,
I am also having a lot of the same issues. I am not sure what I clicked on in the internet but now I have gotten a Trojan-Downloader-Zlob, adware.gen and also eqiso toolbar. I have run ad-aware, hijackthis, and others but I can’t get this one resolved or removed. I have downloaded spybot but I can’t install the program because something is blocking the program from connecting to the host server. Any thoughts on how to get rid of the above problems? I mean if worse comes to worse I can always try and back up all of my crap and reload the O/S but I don’t want to do that if I don’t have to. Attached is a picture of the results I got from Spysweeper but because that is only a trial version obviously I can’t clean the infections. Any help would be greatly appreciated.

Thanks,
Joe

Rogue Anti-Spyware Removal. - Usually associated with ZLOB detection.

Try this tool, RogueRemover, available here http://www.malwarebytes.org/rogueremover.php

HOSTS file redirect - 127.0.0.1 check your HOSTS file using notepad or a text editor of your choice, C:\WINDOWS\system32\drivers\etc\hosts or do a search for HOSTS to find it if not there. http://en.wikipedia.org/wiki/Hosts_file

There is no picture attached, but what may be helpfull is the malware name, file name and location.

:slight_smile: Hi Joe :

 Zlob is a very nasty piece of malware, best handled by an experienced,
 trained, certified, VOLUNTEER malware-fighting Expert . Since you have
 Spysweeper, I recommend you ask for help on THEIR Support Forum at
 www.castlecops.com/f163-Spysweeper.html  ; IF this particular forum
 can NOT help, they will refer you to another forum within this EXCELLENT
 group of Forums .

Please post the HJT log.

Ok, I will try this tonight and see what results I get. It is just puzzling as I have never had an incident where I could not install spybot and others and clean the system. I have been doing IT work for a long time and this is a first one for me. Anyway, I will let you know tomorrow

I will have to post the HJT log in tonight

No problem - I’ll check later on.

Spybot’s update seemed buggy to me this morning - a couple computers went into an endless installation loop. Maybe your problem with it is unrelated to the malware.

I don’t know if we’ll need these tools or not, but you might as well download them now and burn them to disk. That way if your internet connection is effected we can still do some work

ComboFix: http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe

OTMoveIt: http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

That would be nice if that was unrelated but that just seems weird that it won’t install. I have tried the download from several different sites and they all produce the same results. So, my only guess at this point is that it is somehow related to the problems I am having. By the way, ever since I got these problem, I now can’t update my Symantec Virus definitions either. That too will not connect to their servers.

I still have internet connectivity so that is good so that I can continue to work on this at home. I never got to the point of downloading the combofix last night so that is on my agenda for tonight as well. Malware, spyware, adware, etc all bite!..lol

Is the AV still running, or has it been disabled (not necessarily by you)?

AV is still working to this point. But it doesn’t seem to detect any of the problems and I do run a full scan every night

Well, we’ll get it sorted. See you tonight …

Hi

Have you checked the hosts file?

When you attach a picture, don’t use the preview button before posting.

Good morning,
Here is a copy of the Hosts log:

Copyright (c) 1993-1999 Microsoft Corp.

This is a sample HOSTS file used by Microsoft TCP/IP for Windows.

This file contains the mappings of IP addresses to host names. Each

entry should be kept on an individual line. The IP address should

be placed in the first column followed by the corresponding host name.

The IP address and the host name should be separated by at least one

space.

Additionally, comments (such as these) may be inserted on individual

lines or following the machine name denoted by a ‘#’ symbol.

For example:

102.54.94.97 rhino.acme.com # source server

38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 www.drivecleaner.com ## added by CiD
127.0.0.1 www.errorprotector.com ## added by CiD
127.0.0.1 www.errorsafe.com ## added by CiD
127.0.0.1 www.systemdoctor.com ## added by CiD
127.0.0.1 www.utils.winfixer.com ## added by CiD
127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
127.0.0.1 www.win-virus-pro.com ## added by CiD
127.0.0.1 www.winantispam.com ## added by CiD
127.0.0.1 www.winantispy.com ## added by CiD
127.0.0.1 www.winantispyware.com ## added by CiD
127.0.0.1 www.winantivirus.com ## added by CiD
127.0.0.1 www.winantiviruspro.com ## added by CiD
127.0.0.1 www.windrivecleaner.com ## added by CiD
127.0.0.1 www.windrivesafe.com ## added by CiD
127.0.0.1 www.winfixer.com ## added by CiD
127.0.0.1 www.winfixer2006.com ## added by CiD
127.0.0.1 www.winsoftware.com ## added by CiD

Here is the ComboFix log:

Here is the HJT log:

Here is the AlternativHJT log:

I ran SpyDoctor last night and it did detect the trojan-downloader and supposedly cleaned/deleted it but then when I rescanned it was still present. Again, spybot will not install because it can’t contact the host website and AV will not update. I have post my other logs to this point for any help that can be provided

OK, let’s do a little work.

EDIT: I just notice that HijackThis v1.99.1 is running from your desktop while v 2.02 is in a temp folder. You should move these to their own folders before proceeding as backups of the things we fix will be made. We don’t want to risk deleting those backups. We really only need v1.99.1 for this - make the fixes below using this version.

After relocatiing HJT and if you haven’t already, download OTMoveIt by OldTimer and save it to your desktop. Don’t do anything with this just yet.

Now download NoLop to your desktop from

http://www.spywareedge.net/nolop/NoLop.exe

Close any other programs you have running as this may require a reboot
Double click NoLop.exe to run it
Now click the button labeled “Search and Destroy”
<>
When scanning is finished you will be prompted to reboot only if infected, Click OK
Now click the “REBOOT” Button.
A Message should popup from NoLop.
If not, double click the program again and it will finish.

–If you receive an error, “mscomctl.ocx or one of its dependencies are not correctly registered,” please download mscomctl.ocx to your system32 folder then rerun the program.-- http://www.boletrice.com/downloads/mscomctl.ocx

A log will be produced which you should include in your next response.

Next, open OTMoveIt and copy the file paths below to the clipboard by highlighting it and pressing CTRL + C (or, after highlighting, right-click and choose copy):


C:\WINDOWS\system32\laf2.dll
C:\WINDOWS\system32\jrpkmgh.dll

Return to OTMoveIt, right click on the “Paste List of Files/Folders to be moved” window and choose Paste.
Click the red Moveit! button.
Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply
Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Now open HijackThis and click to Do a System Scan Only. When complete, place a check mark next to these lines:
[b]

O4 - HKCU..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\WEATHER.EXE 1

O22 - SharedTaskScheduler: haruspicy - {60dea04c-9817-4309-bfa2-f8a1766c3cd1} - (no file)

O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/ADMINI~1/LOCALS~1/Temp/msohtmlclip1/01/clip_image001.jpg
[/b]
Note that the line in red above is adware but many people choose to keep it on their computer. Fixing this line is optional - do not check it if you wish to keep Weather Bug.

Now make sure all other windows are closed, including your browser, and click Fix Checked.

When that’s finished closed HJT and boot to safe mode. Uninstall the following in Add/Remove Programs (if found)

AntiVirGear

And, optionally,

Weather Bug

Still in safe mode delete the following folder (if found)

C:\ProgramFiles\AntiVirGear 3.7

Reboot to normal mode and Download Deckard’s System Scanner (DSS) to your desktop.

Close all other windows before proceeding.
Double-click on dss.exe and follow the prompts.
When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

What DSS will do:

create a new System Restore point in Windows XP and Vista.
clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.

Note: If you don’t have HijackThis installed on your computer, dss will prompt you to download and install it for you, please allow this to happen !

Now post the following:


NoLOP log
OTMoveit results
DSS log

Finally, upload this file to Virus Total and post the results of the scans


C:/DOCUMENTS AND SETTING/ADMINISTRATOR/LOCAL SETTINGS/Temp/msohtmlclip1/01/clip_image001.jpg