Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251

Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
Downloader.Zlob.YQ
Downloader.Zlob.YQ

Downloader.Zlob.YQ

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Downloader.Zlob.YQ Rob 05-07-2006
---> Re: Downloader.Zlob.YQ cquirke (MVP Wi...05-07-2006
Posted by =?Utf-8?B?UGFuZGFfbWFu?= on May 7, 2006, 12:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
My reply is at the bottom of your message


"Rob" wrote:

> Hope someone can help!
>
> The other day my machine (XP Pro) started to behave strangely. Every time I
> launch IE I get page after page of security warnings designed to look like
> microsofrt warnings (Although they are clearly not Microsoft) telling me the
> machine is at risk and I need to download all sorts of software to sort out
> the problems, this I have not done. Also my home page has been redirected to
> www.systemuptodate.com, this I cannot change.
>
> I ran and AVG scan and it detected and removed Trojan Horse
> Downloader.Zlob.YQ and any subsequent scan says the machine is clear of all
> threats however the symptoms have not gone away.
>
> I have searched the interenet for information on this virus but have failed
> to come up with anything usefull.
>
> Can anyone help me with solutions/information?
>
> Thanks
> Rob
>
>


Hello Rob .
Goto my site http://pandaman.my.contact.bg
and perform the "Check for and eliminate malware" instructions to clean your
PC


Regards!

Panda_man
--
Bronze level Contributor
http://pandaman.my.contact.bg
http://www.eset.com
Please , rate posts

Posted by cquirke (MVP Windows shell/use on May 7, 2006, 4:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>The other day my machine (XP Pro) started to behave strangely. Every time I
>launch IE I get page after page of security warnings designed to look like
>microsofrt warnings (Although they are clearly not Microsoft) telling me the
>machine is at risk and I need to download all sorts of software to sort out
>the problems, this I have not done. Also my home page has been redirected to
>www.systemuptodate.com, this I cannot change.

>I ran and AVG scan and it detected and removed Trojan Horse
>Downloader.Zlob.YQ and any subsequent scan says the machine is clear of all
>threats however the symptoms have not gone away.

Sounds a bit like the SpyAxe, SpyFalcon etc. fake antispyware scam -
suspect this if you have new "security center"-type shortcuts in Start
Menu and Desktop, and frequent alerts from a fake yellow "Security"
shield in the SysTray.

In addition to the good general advice here (appropriate, as you may
have other malware activity), I'd try Ewido, as I've found that to be
the best easy-killer for that.



>---------- ----- ---- --- -- - - - -
Don't pay malware vendors - boycott Sony
>---------- ----- ---- --- -- - - - -

Posted by =?Utf-8?B?Um9i?= on May 8, 2006, 3:10 am
If you were  Registered and logged in, you could reply and use other advanced thread options


"cquirke (MVP Windows shell/user)" wrote:

>
> >The other day my machine (XP Pro) started to behave strangely. Every time I
> >launch IE I get page after page of security warnings designed to look like
> >microsofrt warnings (Although they are clearly not Microsoft) telling me the
> >machine is at risk and I need to download all sorts of software to sort out
> >the problems, this I have not done. Also my home page has been redirected to
> >www.systemuptodate.com, this I cannot change.
>
> >I ran and AVG scan and it detected and removed Trojan Horse
> >Downloader.Zlob.YQ and any subsequent scan says the machine is clear of all
> >threats however the symptoms have not gone away.
>
> Sounds a bit like the SpyAxe, SpyFalcon etc. fake antispyware scam -
> suspect this if you have new "security center"-type shortcuts in Start
> Menu and Desktop, and frequent alerts from a fake yellow "Security"
> shield in the SysTray.
>
> In addition to the good general advice here (appropriate, as you may
> have other malware activity), I'd try Ewido, as I've found that to be
> the best easy-killer for that.
>
>
>
> >---------- ----- ---- --- -- - - - -
> Don't pay malware vendors - boycott Sony
> >---------- ----- ---- --- -- - - - -

OK, Thanks for all your help. I will attempt to get rid of this nightmare
tonight! One question, the machine in question has 4 user profiles on it. Do
I have to go through these steps for each profile or do I log on as
administrator and do it once from there?

Thanks
Rob

>

Posted by David H. Lipman on May 8, 2006, 7:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options




| OK, Thanks for all your help. I will attempt to get rid of this nightmare
| tonight! One question, the machine in question has 4 user profiles on it. Do
| I have to go through these steps for each profile or do I log on as
| administrator and do it once from there?

| Thanks
| Rob


It will depend on teh extent of the infection. If it modified the User Registry
then yes,
it would be best to run the utilities under the user accounts.

After yopu run the utilities under administrator account, logon as the user and
see if
there are oddities that need correcting such as inabilities to change the
desktop or use
the Registry tools, etc.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by cquirke (MVP Windows shell/use on May 8, 2006, 4:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
>"cquirke (MVP Windows shell/user)" wrote:

>> Sounds a bit like the SpyAxe, SpyFalcon etc. fake antispyware scam -
>> suspect this if you have new "security center"-type shortcuts in Start
>> Menu and Desktop, and frequent alerts from a fake yellow "Security"
>> shield in the SysTray.

>> In addition to the good general advice here (appropriate, as you may
>> have other malware activity), I'd try Ewido, as I've found that to be
>> the best easy-killer for that.

>One question, the machine in question has 4 user profiles on it. Do
>I have to go through these steps for each profile or do I log on as
>administrator and do it once from there?

Each profile, as each user account can have its own integration
settings, and detection strategies that look for these rather than
file content will miss the malware if it's not integrated into the
account you are scanning from.

This is why I AVOID multiple user accounts; IMO, they are more hassle
than they are worth, as they are weak at malware protection, and
balloon the maintenance workload considerably.

Worse; every new account starts off with MS duhfault settings like
"dump incoming malware in the data set", "chew up hundreds of megs for
IE's web cache" and "hide filename extensions".

Some scanners (e.g. AdAware) purport to scan all user profiles at
once, and the RunScanner plugin for Bart PE can be set to redirect all
user registries for such tools.

But in practice, I often get positives when scanning from different
accounts after the system is "clean", as well as when scanning in
normal Windows after the system was "cleaned" from Safe Mode (which
may use the hidden administrator account instead of the one you use).

Until I can...
- set up prototype account so all new accounts start right
- control settings over multiple accounts at once
...I have no use for multiple user accounts, and if I have to do the
equivalent of 5 PCs work on one PC just so that Mary can have a
different wallpaper to Johnny, I bill accordingly.



>------------ ----- ---- --- -- - - - -
The most accurate diagnostic instrument
in medicine is the Retrospectoscope
>------------ ----- ---- --- -- - - - -

Similar ThreadsPosted
Downloader AQ December 7, 2006, 11:40 am
Trojan.Zlob.Gen September 5, 2006, 12:10 am
How do i get rid of Win32/zlob.zwc? August 3, 2007, 4:40 pm
Zlob.Trojan September 15, 2008, 3:42 am
Downloader-Awx Trojan June 20, 2006, 5:00 pm
High downloader October 12, 2007, 6:11 pm
Restored PC with Zlob Trojan July 23, 2006, 12:32 pm
New Zlob Rogue: VirusRay October 23, 2007, 3:18 pm
Trojon Downloader Will not delte help April 13, 2006, 9:40 am
How do I remove Downloader virus??? Help! July 13, 2006, 9:29 pm

The site map in XML format XML site map

Contact Us | Privacy Policy