This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans found on the portable external drive

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Plz HELP me…. Hello… I've just done a fresh install of "Windows XP Home Edition". I had to back everything I had onto a portable external drive. Before putting anything back I scanned the external drive, and the avg free scan found a few infections. Obviously I haven't transfered anything back to my computer. After the avg free scan finished it showed only 3 infections. It also showed that the 3 infections were removed and healed. As I was not sure what to do next I took screen shots of everything and just let the program be, left all the windows minimized. But I woke up at 6 am all the minimized avg windows were gone. There was a new avg window up though. This was the "Resident Shield alert" "Multiple threat detection" In here I found a list: 1) "D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000117.com";"Trojan horse Downloader.Zlob.AKEB";"Infected" 2) "D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000117.com";"Trojan horse Downloader.Zlob.AKEB";"Infected" 3) "D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000117.com";"Trojan horse Downloader.Zlob.AKEB";"Infected" Took another screen shot and I went back to bed. When I came back to the computer 3 hours later I found the "Multiple threat detection list had doubled, there were now 6 listed, again all the same path names, just 6 of them. Aside from the "Multiple threat detection" window the avg free scan found the following. Under the "Infections" tab in the "Scan Results" of the avg free scan I found 3 trojans all with a little bit different path names: 1) D:RECYCLER\S-6-3-83-100023387-100005074-100021026-1650.com Trojan horse Downloader.Zlob.AKEB 2) D:RECYCLER\S-7-5-43-100009838-100019303-100002789-9980.com "Infection" Trojan horse Downloader.Zlob.AKEB 3) D:RECYCLER\S-8-9-53-100029173-100001901-100029399-6167.com "Infection" Trojan horse Downloader.Zlob.AKEB Under the "Information" tab of the AVG free scan I found 2 infections with different paths: 1) D:\TRANSFERED FROM F DRIVE\Kristi\Local Settings\Temp\wawtvjbd.dll "Infection" Runtime packed unpack 2) D:\TRANSFERED FROM F DRIVE\Kristi\Local Settings\Temp\ouhfqobx.dll "Infection" Runtime packed unpack Again under the "Information" tab each infection showed "Detailed object information" the additional details are as follows: 1) D:\TRANSFERED FROM F DRIVE\Kristi\Local Settings\Temp\wawtvjbd.dll "Infection" Runtime packed unpack "Object type" file "SDK Type" Core "Result" Result 2) D:\TRANSFERED FROM F DRIVE\Kristi\Local Settings\Temp\ouhfqobx.dll "Infection" Runtime packed unpack "Object type" file "SDK Type" Core "Result" Result Would someone please help me?? UPDATE: 5pm pst - A new trojan has popped up, and it appears to be multiplying!!! PLZ HELP!!??? "Infection";"Trojan horse Downloader.Zlob.AKDY";"D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000117.com";"";"3/31/2009, 4:33:45 PM" "Infection";"Trojan horse Downloader.Zlob.AKDY";"D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000118.com";"";"3/31/2009, 4:57:04 PM" UPDATE: 6:06 pm pst - this trojan apperas to be multiplying every 20-30 mins….PLZ HELP????? "Infection";"Trojan horse Downloader.Zlob.AKDY";"D:\System Volume Information\_restore{44DCCCDC-0856-45F2-B677-E6C3F52E9EB9}\RP3\A0000119.com";"";"3/31/2009, 6:00:04 PM"
Download a copy of HJTInstall.exe from here and save it to your Desktop
  • Double click HJTInstall.exe to begin installation.
  • Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse… button if you want to chose somewhere else and then click Install
  • Once HJT has installed, a shortcut will be created on your Desktop and HJT will run automatically.
  • You will need to accept the EULA, if it appears, to be able to use the tool.
  • When HJT opens, click on the Do a system scan and save a log file button.
  • When HJT has finished scanning, a window entitled "hijackthis.log" will open - when you close this window the log will be saved into the Hijackthis folder.
  • Copy and paste this into your next reply.
Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI