WD has been 'removing' for 28 hours two threats

G

Guest

For the past 28 hours Defender has been 'removing' two detected threats: Zlob
and Exploit:Win32/Wmfap.
This is recurrent WD execution; I've uninstalled and reinstalled from HS,
then deleted .exe and re-downloaded, installed and run. Same results.

Both files were detected inside Norton AV/Quarentine folder so I would
simply uninstall WD forever BUT.. WD detail indicates registry entries remain
for Zlob.
If correct then WD has merit ( regedit check verified entries ID'd in WD
detal).

2) Could Norton AV-Q prevent deletion?

3) What of the registry keys associated in WD detail ( same key for regkey
and runkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run ) ? Are they/it legit in WinXP-SP2?
Thanks
 
G

Guest

Hello CT3or4,

Download and Install
Ad-Aware - http://www.lavasoftusa.com
'Use custom scanning options' and leaving things checked nets a far more
comprehensive scan than the default 'Smart system scan' choice.
http://www.bleepingcomputer.com/forums/tutorial48.html

You can run Ewido in safe mode with network!ng, fwiw.
http://www.ewido.net/en

http://safety.live.com/site/en-US/default.htm
Look for the broom Clean up, also Tune Up.

For the benefit of the community reading this post, please rate the pºst.

I hope this post is helpful.

Let us know how it works ºut.

Еиçеl
 
G

Guest

Operator error. "pages" would have made the link a bit more useful. The
links in the sig. seem to work correctly. Sorry.
 
G

Guest

Let's try this again, shall we? Poor typing skills.

"Pages" might have eliminated the 404.

Click the link in the sig. They have been tested.
 
Top