Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: trojan-zlob  (Read 3154 times)

0 Members and 1 Guest are viewing this topic.

MT89

    Topic Starter


    Greenhorn

    trojan-zlob
    « on: August 21, 2008, 07:08:23 PM »
    I seem to have become infected with a trojan! After running the prerequisites, Webroot  says I'm clean but would like some confirmation...

    Logs attached. Thanks!!!! Reading the previous threads has been very helpful in "battling" this infection.


    [recovering disk space -- attachment deleted by admin]

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: trojan-zlob
    « Reply #1 on: August 21, 2008, 08:08:52 PM »
    Getting ready to take a look right now.  This should only take a few moments...
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey

    CBMatt

    • Mod & Malware Specialist


    • Prodigy

    • Sad and lonely...and loving every minute of it.
    • Thanked: 167
      • Yes
    • Experience: Experienced
    • OS: Windows 7
    Re: trojan-zlob
    « Reply #2 on: August 21, 2008, 08:21:57 PM »
    Well, the scans seem to have picked up just about everything, so let's just remove these entries with HijackThis (close all other windows, including this one)...

    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)

    O16 - DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} (v4 silent install) - https://hef.metafileonline.com/tsweb/v4rdpchk.cab
    O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://hef.metafileonline.com/tsweb/v3rdpchk.cab



    You may want to consider removing this one as well...
    O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l

    It is not malicious, but some people think of it as a form of spyware.  It's up to you.  Removing it will not harm your Earthlink connection.

    Also, you have a program on your computer called SpiralFrog.  Is this related to the music site?  If so, you can leave it alone.

    Another thing...you have anti-spyware, but I didn't notice any anti-virus.  You should look into getting a program such as Avast! or AVG.  I also don't see a reliable firewall.  You're vulnerable without a firewall, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo.  They're all good free firewalls.  Just be sure you only have one installed at a time!  Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall.




    How's your computer running?
    Quote
    An undefined problem has an infinite number of solutions.
    —Robert A. Humphrey

    MT89

      Topic Starter


      Greenhorn

      Re: trojan-zlob
      « Reply #3 on: August 21, 2008, 08:38:27 PM »
      Awesome! Thanks for the help.

      I do use the music site SpiralFrog so that's the origin of that. Also, I use Webroot Spy Sweeper with Anti-Virus so I thought I had anti-virus protection. I'll take your firewall advice as well!

      CBMatt

      • Mod & Malware Specialist


      • Prodigy

      • Sad and lonely...and loving every minute of it.
      • Thanked: 167
        • Yes
      • Experience: Experienced
      • OS: Windows 7
      Re: trojan-zlob
      « Reply #4 on: August 21, 2008, 09:08:17 PM »
      Webroot is considered anti-spyware, which doesn't work the same as anti-virus.  I see that you have Symantec products on your computer, but it doesn't appear to be related to anti-virus (but I could be wrong).
      Quote
      An undefined problem has an infinite number of solutions.
      —Robert A. Humphrey