Download, install, update and scan your System with Malwarebytes, and Spybot
Search & Destroy.
Do it in Safe mode if necessary, and do it with your Anti-virus as well,
while in Safe Mode..
All info below.
http://www.spybot.info/en/index.html
Spybot Search & Destroy 1.6 is a very good, FREE Anti-Spyware Program.
Download, install, update, and immunize your System with it.
Then SCAN with it.
Update it, and scan your System once a fortnight.
http://www.malwarebytes.org/mbam.php
Malwarebytes is as the name says, a Malware Remover!
For the Free version scroll down their page to either download from
Download.com, or Major Geeks.com
Download, install, and update.
Important re: Safe Mode
If you happen to find a problem that you can’t uninstall / delete, reboot
the computer, and go into Safe Mode.
To get into Safe mode, tap F8 right at Power On / Startup, and use UP arrow
key to get to Safe Mode from list of options, then hit ENTER.
RESCAN your computer with your Anti-Virus, Malwarebytes and Spybot S & D
while in Safe Mode.
--
Mad Mike
"E. T." wrote:
> On June 15th, my ZAP log mentions some:
> OSFW,2008/06/15,11:04:32 -7:00 GMT,UNKNOWN(0),Microsoft Windows Malicious
> Software Removal
> Tool,C:\WINDOWS\system32\MRT.exe,PROCESS,OPENPROCESS,DST,\SystemRoot\System32\smss.exe
> I realise it now, looking into my ZAP logs file.
>
> Later in the summer this line multiplied dozens of times in the log and I
> realize that too now, but before, I started having ZAP alerts, the violet
> ones saying
> Generic Host Program for win32 services is trying to act as a server
> and red alerts saying
> LSA Shell Export Version is trying to communicate with
> C:\Windows\system32\Zonelabs\UpdClient.exe by opening its process,
> application Isass.exe.
> among other things.
> I always denied them but did not find the time to check this problem.
> I have lots of problems in my p/c's function and today I tried to restore
> before this date (June 16th) basically in order to avoid those alerts and
> eventual trojan provoking them but I cannot restore before August (when I
> press the left arrow of restore system calendar being in August it does not
> function to lead me to July).
> Why is that?
> Tks for immediate response.
>