Author Topic: Help with trojan...avast doesn't see?  (Read 3836 times)

0 Members and 1 Guest are viewing this topic.

YGH

  • Guest
Help with trojan...avast doesn't see?
« on: March 27, 2006, 02:40:45 AM »
So I have been having a few problems with my computer, and been trying to figure out if any were connected (including folders upon whose opening windows explorer crashes, regardless of how I try to open them, Internet explorer coming up with an exception error every time I try to boot it, and so on down the line)

The big issue I have is that I seem to have been afflicted with a trojan. Avast caught it coming in, but doesn't seem to have stopped it? I thought it had until I recently did an ad-aware sweep, and it caught it. Ok, no problem, just delete it, right?

Nope. First it crashed ad aware, then it froze the deletion process, then it deleted ok, and on subsequent avast searches and ad aware searched was not present...

Until I rebooted, and it's right back again. Avast doesn't seem to see it at all, no matter how thoroughly I scan, and my avast is completely updated.

The virus/trojan is listed by ad aware as a win32.trojan.downloader, and the object is listed as winnt\system32\zlbw.dll.

I admit I got as desperate as trying to delete the file manually, but it's always there on reboot. I have tried all these steps in safe mode as well.

1) why doesn't avast see it?
2) how do I get rid of this problem?

Thanks for any and all suggestions. I'm very concerned that there's a trojan on my system. I have loved avast until now, but I'm worried it might not stop what I need it to. Please help me love avast again;)

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Help with trojan...avast doesn't see?
« Reply #1 on: March 27, 2006, 05:30:35 AM »
Follow the instructions on my website

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Help with trojan...avast doesn't see?
« Reply #2 on: March 27, 2006, 02:48:13 PM »
Hi YGH,

zlbw.dll is "a harmless compression library" according to Symantec. It's "dropped" by several different Trojans, and win32.trojan.downloader is just a generic term, so you'd be better off with a dedicated Trojan scanner. The two bellow are both free:

Ewido (XP'Win2000 only) http://www.ewido.net/en/

     and/or a-Squared http://www.emsisoft.com/en/

Good luck!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Help with trojan...avast doesn't see?
« Reply #3 on: March 27, 2006, 08:54:43 PM »
Hi YGH,

Read this:
zlbw.dll
    Zlbw.dll is a Backdoor Trojan.Abwiz
    Zlbw.dll monitors user Internet activity and private information.
    It sends stolen data to a hacker site
    Related files:
    %System%\wisvccz.exe
    %System%\zlbw.dll
    Adds the value:
    "wupdate" = "%System%\wisvccz.exe"
    to the Windows startup registry keys.
    More info: http://securityresponse.symantec.com/avc...
    Removal:
    Remove zlbw.dll from Windows startup

Nore technical details, here:
http://www.sophos.com/virusinfo/analyses/trojorsed.html

polonus
« Last Edit: March 27, 2006, 10:16:23 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!