Help needed

Discussion in 'NOD32 version 2 Forum' started by fosius, Mar 19, 2006.

Thread Status:
Not open for further replies.
  1. fosius

    fosius Registered Member

    Joined:
    Oct 14, 2004
    Posts:
    479
    Location:
    Partizanske, Slovakia
    Hi all,
    I cant get rid of this stupid program. I scanned all computer with NOD32, it found Win32/TrojanDownloader.Zlob.II trojan. I deleted it. I am attaching a screenshot. I just cant find out which program shows me this baloon popup. I had a look at RUN keys in registry (HKLM and HKCU). Of course, I checked STARTUP folder, but there were no shortcuts.. I tried "msconfig" tool but I didnt find any suspicious entries. Even, I tried killing programs via Task Manager but it didnt help me. I leave only windows programs (SYSTEM and explorer.exe and so on) running but it still appears in taskbar.
    Could somebody help me? Is there anything else what should I check? I am attaching STARTUP list, if somebody experienced has a time to look at it.. thank you in advance..

    ---
    I scanned computer in SAFE MODE...
     

    Attached Files:

    Last edited: Mar 19, 2006
  2. fosius

    fosius Registered Member

    Joined:
    Oct 14, 2004
    Posts:
    479
    Location:
    Partizanske, Slovakia
    Here is that startup list..
     

    Attached Files:

  3. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    Last edited: Mar 19, 2006
  4. TradeMark

    TradeMark Registered Member

    Joined:
    Mar 19, 2006
    Posts:
    65
    Happend the same to me yesterday and i cleaned it with SpyBot it helped i think.
    :rolleyes:
     
  5. Albinoni

    Albinoni Registered Member

    Joined:
    Feb 17, 2005
    Posts:
    711
    Location:
    Perth, Western Australia
    Looks like your PC has been infected by a Trojan that has sort of disguised itself as some sort of Trojan warning you about infections etc.

    I just cant find out which program shows me this baloon popup.
    Does this baloon pop up everytime you power up the PC ?

    Even, I tried killing programs via Task Manager but it didnt help me.
    No it wont Task Manager will only close it down but it will re-appear next time you boot up your PC again, you need to physically delete it.

    I ams suggesting both these files are related, the one you deleted and this baloon one.

    Try the following:>

    C drive, Doc and settings, All Users, Start Menu, Progs and Startup. See if you see any thing suspicious in your startup menu and if so delete it.

    Also I would do a full scan using Ewido, Spybot S&D and also Adaware SE.

    Let me know how you go.
     
  6. fosius

    fosius Registered Member

    Joined:
    Oct 14, 2004
    Posts:
    479
    Location:
    Partizanske, Slovakia
    Thank you all! I ran scan with Spyware Doctor but since it was only trial version I couldn't remove it (there was SpyAXE, some other spyware programs and so on)... But it helped me because I found out which files are responsible for it. So I deleted them, removed registry entries from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run. Damn I didn't know that Windows runs files from this location.... THANK YOU once again.. I made copies of all that files and I am going to send them to ESET for further analyse and possible detection added...
     
  7. Albinoni

    Albinoni Registered Member

    Joined:
    Feb 17, 2005
    Posts:
    711
    Location:
    Perth, Western Australia
    Download a trial version of Ewido and do a scan with that.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.