0
doug925

Anitvirus 2009 (.zlob trojan warnign) is making another circuit around the net

Recommended Posts

Watch out for a fictitious Microsoft Security Center Alert of
"... Warning firewall blah blah blah has detected trojan.zlob on your computer. Click here to enable protection"

This is a rogue spyware extorting people to buy Antivirus 2009!

I know most of us :D are smart enough NOT to click on it, but my I.T. buddies are seeing it everywhere. (and my wife mistakenly clicked on it too) :S

If you do get it, it is a BITCH to get rid of, as MOST anti spyware programs won't touch it right now.


Here is a quick way to disinfect:

This solution works for the latest Trojan.Zlog.G popup problem where no internet connection works and repeated fake warnings to 'activate' Defender anti-virus program.

No use running any ant-virus/soyware programs, they don't seem to detect this latest Trojan. Only manual removal works perfect:

Start in safe mode (press F8 at startup)
Delete following:

kjzna1562565.exe
spcffwl.dll
T-Scan (entire folder)

their location would be C:\Documents and Settings\{username}\Application Data\Google\

It looks so simple in hindsight, entire day wasted in efforts.


This is just FYI

Doug.
I have never developed indigestion from eating my words.
Winston Churchill

Share this post


Link to post
Share on other sites
Here's a simpler solution that I used.
There are other variations on this Trojan too....

Go to the link below
Download the software
Download the updates from the update tab
Run the quick scan.
Click show results
Fix the selected results
Reboot your machine

http://majorgeeks.com/downloadget.php?id=5756&file=10&evp=693ee0b20204960edfd909666f809b26


Also use a disk cleaner like
http://majorgeeks.com/CM_DiskCleaner_d4012.html

"The reason angels can fly is that they take themselves so lightly." --GK Chesterton

Share this post


Link to post
Share on other sites

This never stopped going around. Its currently in its 5th generation of code. Most AV picks it up in some form if you have the updates applied and have huresitcs enabled. The hijacked site will not be picked up but as soon as you click the "run" button it picks up the code.


I know way more about this piece of code then I ever care to know... :S

Yesterday is history
And tomorrow is a mystery

Parachutemanuals.com

Share this post


Link to post
Share on other sites

You are right. It has popped up with its newest revision.


Marcanddalyse,

The "malwarebytes" has worked for some, but not all. Even then you are waiting for 30-45 minutes to scan the drives. I was only pointing out he quick way of deleting it.
Just another option.

Doug.:)

I have never developed indigestion from eating my words.
Winston Churchill

Share this post


Link to post
Share on other sites
Quote

WTF are you guys doing, i mean, i surf PLENTY of pornsites, but i never get shit like that.. :S

i think i got one virus in a lifetime or something.. :S



You need to delve deeper into the porn realm Sir!
Sheesh, you're not looking at good enough porn unless the viruses embedded make your computer explode!:ph34r::ph34r::ph34r:
I have never developed indigestion from eating my words.
Winston Churchill

Share this post


Link to post
Share on other sites
I just pulled the database up and I am counting 500+ file names on page 1 of my query as the logged names that we have for this so far. These "instructions" might get a subvariant of it but if you only follow these instructions you will miss a ton of the variants and dropped files.
Yesterday is history
And tomorrow is a mystery

Parachutemanuals.com

Share this post


Link to post
Share on other sites
Quote

I just pulled the database up and I am counting 500+ file names on page 1 of my query as the logged names that we have for this so far. These "instructions" might get a subvariant of it but if you only follow these instructions you will miss a ton of the variants and dropped files.



Uh, oh shit!

I might need to borrow said list.:o
I have never developed indigestion from eating my words.
Winston Churchill

Share this post


Link to post
Share on other sites
My dad clicked on one of those fake link about a few months ago and we ended up with Anivirus 2009 on our desktop. I spent hours trying to get it off of the computer! I went it and removed it manually, but it took me a bit to figure out all the path names and files that it went into. I think that I have it all removed now.

Share this post


Link to post
Share on other sites
i got it last weekend and i have avast. we were out of town so we just tried to use the computer until we got home so i could try to fix it, but by the time we got home my computer was locked up so bad i couldn't get online or do much of anything. i ended up reformating my hard drive and reinstalling windows. this was the reason for the thread about computer help i started earlier this week. fortunately all i had stored was a few pics i had taken over the weekend and i was able to get them transfered to a flash drive. i've heard from other sources as weel that avast is one of the best ones out there as well. i was beginning to doubt that when i caught the virus, but is nothing else is picking it up right now, maybe it is a good av program.


"Your scrotum is quite nice" - Skymama
www.kjandmegan.com

Share this post


Link to post
Share on other sites
This is up to its 1000+ variant right now from a few vendors. Looking at the code its really easy to get it pass all but the bleeding edge AV drivers since it is a server side polymorphic that generates unique code for each person that clicks on the link. This trojan and others in its family will only get installed if you actually click and tell it to download the file. Most vendors are able to add detection to it in the next update or so but some samples will remain undetected until the sample gets sent in for analysis by the researcher since its code is one that they have not seen yet.

If you know how to collect a sample and send the files to your AV company they can normally updated their driver and get full cleaning for it with in a day or two.
Yesterday is history
And tomorrow is a mystery

Parachutemanuals.com

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

0