HardwareLogic

Go Back   HardwareLogic > General Discussions > General Computing > Troubleshooting
Home Forums Rules All AlbumsBlogs Subscriptions Register Mark Forums Read

Troubleshooting Need help figuring out what went wrong? Wanna know where you screwed up?

Reply
 
LinkBack Thread Tools
Old December 7th, 2007   #1
 
Join Date: Aug 2007
Posts: 284
Default Dads computer hijacked?

Hay guys... Im having a issue with my dads computer. We start up the IE and a pop up shows up saying he has some sortta trojan on his computer by the name of TrojanZlob.x.a and wants us to install software to remove it.. obviously I know better.

Avg anitvrius doesn't seem to be finding it. Adaware SE hasn't picked anything up. I have shut off a few satart up programs via Winpatrol, but nothing has seemed to help. I know somethings wrong becasue on occasion when IE is started, it goes to some porn website homepage instead of Yahoo.....

anyone have any suggestions?? I am going to install NOD32 and see if that finds anything...... but all sugestions are welcome....

thanks



E6600 Dual Core @3.4GHZ (1511 FSB)@1.325volts
2x 8800 GTX KO ACS3 PCI-E 630MHZ 768MB 2.0GHZ
Raptor 74GB
WD Caviar 250GB HD
Antec 1200 Hundred Case
4 gigs of Corsair XMS2 TWIN -6400C4 2GB DDR2-800 CL 4-4-4-12-2T
680I SLI LGA775 MOBO
Samsung DVD+RW
Enermax Galaxy 1000 wats PSU

24" Samsung SynMaster

Cooling:
Swiftech Dual rad
Swiftech Micro Res
Swiftech Apogee GT Cpu block
2x Koolance 8800 GTX Full Coverage Water blocks
Feser One Blue Fluid
frostybrad is offline   Reply With Quote
Old December 7th, 2007   #2
Eat from the right tree
 
Join Date: Oct 2007
Posts: 837
Default Re: Dads computer hijacked?

If the "nasty" will let you go to "trend micro's" housecall ... then may times that online scanner can clean your pc up.

If it is a sophisticated trojan with assorted bugs ... it may not let you connect.

Search for "housecall"
Tech Geek Deluxe is offline   Reply With Quote
Old December 7th, 2007   #3
T-Rex
 
polobunny's Avatar
 
Join Date: May 2006
Posts: 5,058
Blog Entries: 6
Default Re: Dads computer hijacked?

Here's how I proceed normally when cleaning a computer with virus and spyware;
Run
AVG Antivirus Free
HiajckThis!
Spybot Search and Destroy
Windows Defender
Lavasoft Ad-Aware 2007
CCleaner
smitfraud fix (http://siri.urz.free.fr/Fix/SmitfraudFix.exe)
VundoFix (VundoFix.exe - www.atribune.org)



polobunny is online now   Reply With Quote
Old December 7th, 2007   #4
vincit qui se vincit
 
Carl Martin's Avatar
 
Join Date: Dec 2006
Location: Upper Michigan
Posts: 479
Default Re: Dads computer hijacked?

I've encountered various Zlob trojans and have always had success with SpyBot. (It's worked twice when Spy Sweeper failed.)

What ever you use, be sure to delete all system restore files to avoid reinfection.

Carl



Core 2 Duo E6750
Arctic Cooling Freezer 7 Pro
Abit IP35 Pro
2x1GB Crucial Ballistix DDR2 800
EVGA 8800GT
500GB Seagate Barracuda 32MB Cache
Coolermaster RC-690
OCZ StealthXStream 600 watt
Acer AL2216W 22" monitor
Windows XP Pro SP2
Carl Martin is offline   Reply With Quote
Old December 7th, 2007   #5
I don't know how to put this, but, I'm kind of a big deal.
 
One4yu2c's Avatar
 
Join Date: Jan 2006
Location: Land of the Lounge Lizards
Posts: 2,725
Blog Entries: 3
Default Re: Dads computer hijacked?

With a quick jaunt on Google, it looks like others haven't had much success catching it with anti-virus suites, either. As mentioned, turn your attention towards anti-spyware programs. If it were me, I'd scan with Spybot Search and Destroy, Adaware, A-Squared, and if it still persists, I'd recommending scanning with HijackThis! and post a log for us to look at (HijackThis! doesn't discern between good and bad entries, so don't delete/'fix' anything unless you're sure it doesn't belong).

And hey, thanks for bringing up a prime opportunity to pimp myself:
Heal and Inoculate Your PC - Paul Lilly



One4yu2c is offline   Reply With Quote
Old December 7th, 2007   #6
ako the pinoy
 
halutzparilla's Avatar
 
Join Date: Jul 2006
Location: by the beach
Posts: 1,698
Default Re: Dads computer hijacked?

i had same problem before and here is my thread i hope it help...

Pop Up annoyance



Abit IP35-E
C2D E6750 G0 @ 2.66ghz [TR Ultra120EX]
EVAG 8800GTS [TR HR03]
Corsair [2gbDual@800]
820GB HDD[120/200/500]
Antec TP 550W
Silverstone Temjin 09
Saitek Eclipse1 & Razer DeathAdder
Windows Vista Ultimate 32bit
halutzparilla is offline   Reply With Quote
Old December 7th, 2007   #7
T-Rex
 
polobunny's Avatar
 
Join Date: May 2006
Posts: 5,058
Blog Entries: 6
Default Re: Dads computer hijacked?

Quote:
Originally Posted by One4yu2c View Post
With a quick jaunt on Google, it looks like others haven't had much success catching it with anti-virus suites, either. As mentioned, turn your attention towards anti-spyware programs. If it were me, I'd scan with Spybot Search and Destroy, Adaware, A-Squared, and if it still persists, I'd recommending scanning with HijackThis! and post a log for us to look at (HijackThis! doesn't discern between good and bad entries, so don't delete/'fix' anything unless you're sure it doesn't belong).

And hey, thanks for bringing up a prime opportunity to pimp myself:
Heal and Inoculate Your PC - Paul Lilly
I tried free A-Squared. So-so program, even more since there's a resident program running always in the background (doing nothing) even when the program is closed...



polobunny is online now   Reply With Quote
Old December 7th, 2007   #8
 
Join Date: Aug 2007
Posts: 284
Default Re: Dads computer hijacked?

Okay, not sure if I have it licked or not, but heres what I did...

ran Spybot and it found nothing..... Ran AVG and found nothing (then uninstalled it) . Ran Adaware Se and it found a few minor things but not the main virus. I installed Winpatrol which is a great little program (in my opinon its the program to have). This allowed me to disable the services that i didn't need running (should say "he") and narrowed the services down to what I thought was the bad one. this allowed me to stop the process and remove it from memory. I installed NOd32 and it found 7 traces of the infection in various parts of the computer, and I also did a disk cleanup and also shut off system restore to erase the restore points..... I wouldnt have done that so thanks for that tip!!

and so far the message has not come back, even after rebooting. Winpatrol tells me there is a startup program asking for permission to start when windows starts, and I beleive this is the file.... %^&%Rotate.dll (can't remember at the moment whats infront of the word rotate), but at least with Winpatrol I just say no, and it won't activate....... obviously I need to remove that file still, but its cornerd and won't start!!


thanks for the thoughts and help guys..... muchly appreciated as always, thanks..



E6600 Dual Core @3.4GHZ (1511 FSB)@1.325volts
2x 8800 GTX KO ACS3 PCI-E 630MHZ 768MB 2.0GHZ
Raptor 74GB
WD Caviar 250GB HD
Antec 1200 Hundred Case
4 gigs of Corsair XMS2 TWIN -6400C4 2GB DDR2-800 CL 4-4-4-12-2T
680I SLI LGA775 MOBO
Samsung DVD+RW
Enermax Galaxy 1000 wats PSU

24" Samsung SynMaster

Cooling:
Swiftech Dual rad
Swiftech Micro Res
Swiftech Apogee GT Cpu block
2x Koolance 8800 GTX Full Coverage Water blocks
Feser One Blue Fluid
frostybrad is offline   Reply With Quote
Old December 7th, 2007   #9
T-Rex
 
polobunny's Avatar
 
Join Date: May 2006
Posts: 5,058
Blog Entries: 6
Default Re: Dads computer hijacked?

Use HijackThis! to remove the rogue file. It's almost guaranteed to work. :)



polobunny is online now   Reply With Quote
Old December 7th, 2007   #10
HL's Technomancer
 
Stormcrow's Avatar
 
Join Date: May 2007
Location: Frozen North
Posts: 1,168
Blog Entries: 1
Default Re: Dads computer hijacked?

Yep, HijackThis! has removed various trojans from the family Dell computer.
|MG| Trend Micro HijackThis 2.02
It runs in it's own folder, no need to install it. After it scans your computer, leave it open but save the .txt file it generates.
Then go here: HijackThis Logfileauswertung
Upload the logfile, and it'll display the results of whats a nasty infection and whats not. The site is used worldwide and each threat is rated by people who use the program, so I have no trouble finding whats a virus/trojan/malware.
Then just match up the trojan it finds with the same name as one in the program itself (this is why you didn't close it), and fix it. Pretty straightforward, might make a good guide to write to include pictures and such.
Also as mentioned, delete your system restore files so that it doesn't reload the trojan by mistake.



Stormcrow is offline   Reply With Quote
Reply

  HardwareLogic > General Discussions > General Computing > Troubleshooting

Tags
computer, dads, hijacked


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Is your NEW computer REALLY new? LaKraven User Guides/Reviews 0 October 7th, 2008 13:07
Dads Mouse Death_blooms Troubleshooting 9 July 20th, 2007 11:45
Old Computer Ads Jokerswild HL Lounge 9 June 7th, 2007 16:52
Where to Get A Really Old Computer? jabagawee General Computing 8 May 23rd, 2007 15:36
What's your first computer? Oldfatslob General Computing 34 March 20th, 2007 07:39


All times are GMT -8. The time now is 04:30.


Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
© HardwareLogic 2005 - 2008. All Rights Reserved


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52