Just about every time I log on, avast finds the same trojan horse virus, Win32:Mebload-B. I always move it to a container or rename it.
Is this a false positive? What should I do here?
Thanks!
Which is the file name and path?
Maybe you can extract it to a safe place (never running/executing) it and uploading it to www.virustotal.com to check.
it’s related to Sinowal - google for this term and you’ll see ![]()
The file name is S0id.dll. The path is in German, but the English translation is something like:
\Documents and settings\HelpAssistant\Local settings\temp
I uploaded it to virustotal and e.g. Microsoft show it as the following: TrojanDownloader:Win32/Sinowal.A
So it apparently is a Sinowal variant.
Do I have to buy a antispyware to get rid of it???
googled a sinowal removal tool, don`t know if it will work ???
http://www.softpedia.com/get/Antivirus/Norman-Sinowal-Cleaner.shtml
Check your computer for Malware with
MBAM http://filehippo.com/download_malwarebytes_anti_malware/
update and run quick scan, click the button “remove selected” to quarantine anything found, and restart
SAS http://filehippo.com/download_superantispyware/
Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26
come back and tell us if it worked
If anything is found other than cookies you may post the scan logs here
No you don’t have to buy an anti-spyware, those suggested by Pondus have free on-demand versions.
If it keeps coming back (after you send it to the chest), there is likely to be an undetected or hidden element to the infection that restores or downloads the file again. So hopefully the tools suggested
will find that element.
What is your firewall ?
Hey folks! I think the Malwarebytes got it. I did a full check of the hard drive and it came up with a couple of things. When I rebooted avast didn’t find the trojan horse again. Keep your fingers crossed!
And thank you very much for your help!!!
Cheers,
Jim
Post your MBAM log contents, that gives a better idea what the problem is and if anything else may need to be done.
Also consider this info: http://vil.nai.com/vil/content/v_222251.htm
pol