UNSOLVED

ciwawa

updated

18 years ago

C

ciwawa

68 Posts

0

2352

June 15th, 2008 16:00

Trojan downloader - HELP

Dear sir/madam:

 

I was running my Ad-Aware 2007, it picked up this on my computer:

 

Win32.Trojandownloader.Zlob (Malware)

Registry Entry

Root:  HKU path: S-1-5-21-1715567821-492894223-725345543-1003\software\microsoft\windows\currentversion\ext\stats\{9034a523-d068-4be8-a284-9df278be776e}

 

I don't know where this came from.  I have AVG (free version, which I just updated to version 8 last week), Zone Alarm and I run Ad-Aware.

 

How serious is this problem? Can you help, plese?

 

Back in February, Bugbatter was able to help me with my trojan horse problem, I have been cleaned, I thought, all this time.  Could this from one of the updates that ran on my computer?  I also replaced my Verizon Modem because I was losing DSL connection last week.

 

Any help will be greatly appreciated.

 

Thanks a million.

 

Best Regards,

 

Dell Dimension 8250

Intel Pentium 4 CPU 2.4pGHz

2.39 GHz, 512 MB of RAM

Microsfot Windows XP Professional

Version 2002

Service Pack 2

 

 

  • melboy

    336 Posts

    128

    0

    Posted June 15th, 2008 17:00

    Hi, follow these instructions and i'm sure Bugbatter or one of the other helpers will come to your aid

    (dont forget to post the MBAM log and HJT log on the HiJackThis board)

     

    Please download Malwarebytes' Anti-Malware from Here or Here

    Make sure you are connected to the Internet.

    Double-click on Download_mbam-setup.exe to install the application.

    When the installation begins, follow the prompts and do not make any changes to default settings.

    When installation has finished, make sure you leave both of these checked:

    Update Malwarebytes' Anti-Malware

    Launch Malwarebytes' Anti-Malware

    Then click Finish. MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install. On the Scanner tab:

    Make sure the "Perform Quick Scan" option is selected. Then click on the Scan button.

    The next screen will ask you to select the drives to scan. Leave all the drives selected and click on the Start Scan button. The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient. When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found". Click OK to close the message box and continue with the removal process. Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found. Make sure that everything is checked, and click Remove Selected. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. :(see Note below) The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.

    Notes:

    **If you encounter this message:"c:\program files\malwarebytes' Anti-Malware\mbamext.dll Unable to register the dll/ocx: RegSvr32 failed with exit code 0x5" Click on ignore mbamext.dll

    **If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

     

    Copy&Paste the entire report into a New Message on the HijackThis board. Also include a fresh HijackThis log. Instructions for downloading HijackThis are at the top of that forum.
    By having a review there, we can be sure vulnerabilities have been addressed
    1. Just click the New Message button in the HijackThis forum here:
    http://www.dellcommunity.com/supportforums/board?board.id=si_hijack
    to start your own thread requesting assistance for a follow-up check to be sure the malware is gone.

     

    Message Edited by melboy on 06-15-2008 01:35 PM
  • Bugbatter

    4 Apprentice

    20487 Posts

    128

    0

    Posted June 15th, 2008 17:00

    A lot can happen in 4 months. That is not from the infection you had earlier, so it is something new.

     

    Edit: This is being handed on the HijackThis Board

    Message Edited by Bugbatter on 06-15-2008 10:42 PM