geek ('gēk), noun. 1. Obsessive Computer User: somebody who enjoys or takes pride in using computers or other technology, often to what others consider an excessive degree 2. Someone with greater than normal computer skills.
Welcome Guest ( Log In | Register ) to Geeks to Go Computer Help Forum! Here you'll find free, friendly help and support for all your computing questions. Once registered - you'll have the ability to post your question in the appropriate category below. Additionally, if you can assist another member by sharing your computing knowledge, please feel free to post a reply! Best of all - Registration and all assistance, is FREE! Once you've completed registration, simply click the appropriate category below, click on the "new topic" button, and post your question! What are you waiting for? (registering removes advertising)
Often these infections can be found placed in fake MySpace profiles, and other social websites. They are fake codecs. They install the Zlob.trojan.Media-Codec which pops up fake alerts in an attempt to make you buy software, and will hijack your homepage.
Option 1 (smitfraudfix by S!Ri): Instructions for SmitFraudFix (by S!Ri)
SmitFraudFix only works with Windows XP or 2000
Please download SmitfraudFix (by S!Ri) Extract the content (a folder named SmitfraudFix) to your Desktop. Don't use it yet.
Reboot into Safe Mode: ( without networking support !) °To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
(Warning : running option #2 on a non infected computer will remove your Desktop background and set it blank again. But you can reapply your desktop background again afterwards
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; save that log in case you need it to reply together with a hijackthislog. The report can also be found at the root of the system drive, usually at C:\rapport.txt
Option 2 (smitrem by noahdfear): Instructions for Smitrem (by noahdfear)
Reboot into Safe Mode: ( without networking support !) °To get into the Safe mode as the computer is booting press and hold your "F8 Key". Use your arrow keys to move to "Safe Mode" and press your Enter key.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Wait for the tool to complete and disk cleanup to finish.
The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Save that log and post it if needed along with any others if you need to start a new topic.
Group: Admin
Posts: 16,277
Joined: 21-May 03
Member No.: 1
Operating System:
Windows Vista Ultimate
This topic has been left open to allow specific questions and comments related ONLY to this guide. It's NOT for posting HJT logs, links to your logs, or any other general malware help. Replies not following these rules will be deleted. Thanks for your cooperation.
Group: Member
Posts: 12
Joined: 23-July 07
From: Victoria
Member No.: 219,818
Operating System:
Windows XP
Hi, I have run the SmitFraudFix yet when i run XoftXpySE (which i have the trial version of) it still shows that the MediaCodec Zlob Trojan is on my computer. Any ideas of how to get rid of it? thanks
Group: Geek U Moderator
Posts: 6,981
Joined: 22-June 05
From: Maryland USA
Member No.: 76,027
Operating System:
Windows XP Pro SP2
elliot5637,
I recommend that you go here and follow the directions for posting a hijackthis log in the Malware Removal forum. Let one of our malware team help you make sure you're clean.
--------------------
No one can do everything, but everyone can do something
Please do not PM me asking for support. Post on the forums instead :) One of us will help you as soon as we can. Please be courteous, polite, and say thank you. I promise to return the favor! Please post the final results, good or bad. We like to know!
I am a volunteer. I try to respond as quickly as possible, but sometimes my job, my family, or life in general gets in the way. If you think I've forgotten about you, please send me a PM reminder. I am more active on weekdays than weekends, so my response may be slower then.
Group: Member
Posts: 1
Joined: 19-August 07
Member No.: 222,183
Operating System:
windows xp home
I have worked with a few customers who have had the zlob torjan. The easiest way i have found to remove it is to download 2 main programs, both are free. These are ad-aware and windows defender. windows defender picks it up and finds it really fast, and i use ad-aware to clean up anything left over that may be hiding on the system.
Group: Geek U Moderator
Posts: 18,588
Joined: 5-July 04
From: Boston Ma.
Member No.: 2,804
Operating System:
XP Pro,ME, 98
QUOTE
I have worked with a few customers who have had the zlob torjan. The easiest way i have found to remove it is to download 2 main programs, both are free. These are ad-aware and windows defender. windows defender picks it up and finds it really fast, and i use ad-aware to clean up anything left over that may be hiding on the system.
Hello and welcome insectdude I m sure that works as well on the older variants, s!ri's tool is updated almost daily. so if your method fails for any reason give smitfraudfix a run
--------------------
Please do not PM me asking for support. Post on the forums
Don77 Malware Page <--Have I helped you? Please consider donating to help me continue the fight against malware, Thank you
Group: Member
Posts: 30
Joined: 29-July 07
From: Florida
Member No.: 220,301
Operating System:
WinXP
Greetings,
During a scan with SpyBot S & D very early this morning I saw a lot of these names going by...Zlob in front of most of them . What should I do as I'm not sure that I'm infected with them. I'm not getting pop-ups of any sort, just trying to clean up my laptop.
Group: Member
Posts: 3
Joined: 8-January 08
Member No.: 234,858
Operating System:
XP SP2
I`m sorry to bother, but I have a problem which I don`t know how to solve. My computer is now called Ahsan`s computer, my Documents is called Ahsan`s documents, my network places is now Ahsan`s places..... I think microsoft word 2003 professional is deleted from my system, as well as a few other applications. How do I remove this? I`m sorry if I`m not writing in the appropriate topic. I`m a complete beginner when it`s about malware.
The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.