Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Not exactly sure malicious trojandownloader.zlob [RESOLVED]


  • This topic is locked This topic is locked

#16
gambitman

gambitman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
Sorry for this turninng into a book! I ran the Kaspersky Online Scanner and I showed 20 viruses and 80 infected objects. However I could not figure out how to save as a textfile. I could see nothing to click on, nothing to save other than the stop scan button. I ran the ActiveX control and I followed your instructions (I think) was able to run the scan, but was unable to save a textfile. I am running it again but I was wondering if there was something I could do differently or if there was a different scanner I could use? The performance of the computer seems fine so I don't know if those are serious issues or not . Thx.
  • 0

Advertisements


#17
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
What that scanner more than likely is seeing is files that are already deleted in system volume information and also in a folder called qoobox.
These are no longer a threat but will be dealt with in a bit.

If you cannot save it then try this scanner. :
Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

  • 0

#18
gambitman

gambitman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
okay I htink it worked this time. Here is file from Kaspersky

Tuesday, February 05, 2008 7:36:24 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/02/2008
Kaspersky Anti-Virus database records: 550336


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics
Total number of scanned objects 88847
Number of viruses found 20
Number of infected objects 50
Number of suspicious objects 0
Duration of the scan process 01:29:42

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012008020520080206\index.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\chandir.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\chandir.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\chn.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\chn.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\D0000000.FCS Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\inuse.txt Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\L0000027.FCS Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\main.log Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_die.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_die.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_dnd.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_dnd.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_ext.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_ext.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_rcv.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\prs_rcv.idx Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\storydb.dat Object is locked skipped

C:\Program Files\Updates from HP\137903\Users\Default\Data\storydb.idx Object is locked skipped

C:\QooBox\Quarantine\C\Program Files\Dot1XCfg\Dot1XCfg.exe.vir Infected: Trojan-Downloader.Win32.Adload.pr skipped

C:\QooBox\Quarantine\C\WINDOWS\mrofinu572.exe.vir Infected: Trojan-Downloader.Win32.Agent.idv skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ceqipigw.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\clegpmnc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gip skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\cvvwhnap.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\hxlacogb.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\jijpcfvr.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\juanmfbc.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nuhulytw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\nxbiobhn.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ofycwncy.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\pcgmignw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\pjdtrfhn.dll.vir Infected: not-a-virus:AdWare.Win32.SuperJuan.auj skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\ppwagcqu.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tet3\tewdrives22.exe.vir Infected: Trojan-Downloader.Win32.Small.hwg skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\tmntdqu.dll.vir Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\wejohmgu.exe.vir Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\windows.vir Infected: Trojan.Win32.Zapchast.dt skipped

C:\QooBox\Quarantine\C\WINDOWS\system32\xprfjgqj.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\catchme2008-02-02_ 84946.67.zip/mllmj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\catchme2008-02-02_ 84946.67.zip/xprfjgqj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\QooBox\Quarantine\catchme2008-02-02_ 84946.67.zip ZIP: infected - 2 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0080296.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0080321.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gs skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0081328.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0081348.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0081391.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP265\A0081417.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082466.exe Infected: not-a-virus:AdWare.Win32.Insider.a skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082467.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082490.exe Infected: Trojan-Downloader.Win32.Agent.hcn skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082526.exe Infected: Trojan.Win32.Scapur.k skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082527.exe Infected: Trojan.Win32.Agent.edq skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082528.exe Infected: Trojan-Downloader.Win32.PurityScan.fj skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082529.exe Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082530.exe Infected: Trojan-Downloader.Win32.Agent.hvj skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082531.exe Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082534.exe Infected: Trojan-Downloader.Win32.VB.cge skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082535.exe/data0001 Infected: not-a-virus:AdWare.Win32.PurityScan.gp skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082535.exe NSIS: infected - 1 skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082536.dll Infected: not-a-virus:AdWare.Win32.ZenoSearch.ad skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082537.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP266\A0082539.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.dxb skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP268\A0082720.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082755.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082761.exe Infected: Trojan-Downloader.Win32.Agent.idv skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082762.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082763.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082764.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082765.dll Infected: not-a-virus:AdWare.Win32.PurityScan.gv skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082766.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082767.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082768.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082769.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082770.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082771.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082772.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082773.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082774.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082775.dll Object is locked skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082787.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082788.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP270\A0082793.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP271\A0082866.exe Infected: Trojan-Downloader.Win32.Adload.pr skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP271\A0082867.exe Infected: Trojan-Downloader.Win32.Small.hwg skipped

C:\System Volume Information\_restore{7F7BE6F8-0D6A-488B-ABDC-75393719A72D}\RP272\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
  • 0

#19
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
A little left to go and you are on your way. :)
================================
Please update your Java:
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems

Ugrading Java:After that
  • Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
========================================
Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK


    • Posted Image

    The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Clean System Restore points.

Also delete anything that we used that is left over.
==================================
After that Your log is clean. :)

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein ->Here
  • 0

#20
gambitman

gambitman

    Member

  • Topic Starter
  • Member
  • PipPip
  • 47 posts
Thankyou. A donation has been sent.
  • 0

#21
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
You are welcome and thank you as well :)


Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If your the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#22
kahdah

kahdah

    GeekU Teacher

  • Retired Staff
  • 15,822 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP