Thanks in advance for any help!DDS (Ver_10-03-17.01) - NTFSx86 Run by Niall at 11:31:19.48 on 03/10/2010Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_20Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1279.666 [GMT 1:00]AV: AVG Anti-Virus Free *On-access

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\{7a6e35d6-f3e2-82f2-bec6-6c816dc61dc2} (Trojan.ZbotR.Gen) -> Quarantined and deleted successfully. The data read from the domain is RSA-signed and validated through the public key store in the trojan's body.

Some variants make the following changes to the registry to ensure that they run each time you start your PC: In subkey: HKCU\Software\Microsoft\Windows\Currentversion\RunSets value: "{GUID of Windows volume}" (for example, "{449829B8-9322-5694-4C31-974E87EDDDA5}")

The trojan can generate up to 1020 pseudo-randomly named domains, and tries to connect with the generated list to download a configuration file.

Windows XP fully updated Using AVG 8 Free version 8.0.100 Database 269.23.7/1410 2 Mb Broadband connection via cable from virginmedia.com in UK Windows XP firewall off.

It also logs keystrokes and gets desktop and window snapshots of the infected PC. C:\Program Files\FunWebProducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Other versions of Win32/Zbot drops copies of itself as a randomly named file: %APPDATA% \\.exe %TEMP% \\.exe For example, C:\Documents and Settings\Administrator\Application Data\ecymy\huojq.exe. Files Infected: C:\Program Files\exe.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

Spam emails contain the following information, including a link to a phishing page disguised as a social networking, courier, or online banking site. check my blog O/S= OEM XP Home Edition + SP2 and updates as of 3May 08.

These families download Zbot as part of their criminal activity to steal information about your PC: TrojanDownloader:Win32/Bredolab TrojanDownloader:Win32/Upatre Win32/Cutwail Win32/Dofoil Win32/Gamarue Win32/Fareit Win32/Kelihos Win32/Kuluoz Win32/Vobfus Win32/Waledac Win32/Zbot might also be downloaded Steals sensitive information Win32/Zbot hooks APIs used by Internet Explorer and Mozilla Firefox; it does this to monitor your online activities.

These kits are bought and sold on the cyberworld black market.

The red color spreads throughout the disc to indicate whether a threat is moderate, high or severe.PreviousNextSummaryWhat to do nowTechnical informationSymptoms Symptoms The following could indicate that you have this threat Malware Response Instructor 34,443 posts OFFLINE Gender:Male Location:London, UK Local time:12:52 PM Posted 26 November 2010 - 09:05 PM Hi,I have not had a reply from you for 4 days. I have uninstalled Ashampoo Firewall and reloaded.

If you're using Windows XP, see our Windows XP end of support page.

Click 'Show Results' to display all objects found".Click OK to close the message box and continue with the removal process.Back at the main Scanner screen, click on the Show Results button Bleeping Computer is being sued by EnigmaSoft. Other programmes trigger Ashampoo for authorisation of programmes however AVG8 does not trigger Ashampoo Firewall permission box. If you accept cookies from this site, you will only be shown this dialog once!You can press escape or click on the X to close this box.

You can help protect your PC from ransomware by reading more about Win32/Crilock and our help topics about ransomware.