Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: malware bytes detects termsrv.dll as trojan downloader  (Read 5779 times)

0 Members and 1 Guest are viewing this topic.

think

  • Guest
malware bytes detects termsrv.dll as trojan downloader
« on: November 21, 2010, 10:48:23 PM »
i did scan with malware bytes free version.
i got following.
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
c:\WINDOWS\system32\termsrv.dll (Trojan.Downloader) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\termservice (Trojan.Downloader) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\sri user\Application Data\Microsoft\svchost.exe (Backdoor.Gbot) -> No action taken.
C:\WINDOWS\system32\termsrv.dll (Trojan.Downloader) -> No action taken.
C:\Documents and Settings\sri user\Local Settings\Temp\0.9803419823262692.exe (Backdoor.Gbot) -> No action taken.
C:\Documents and Settings\sri user\Application Data\Microsoft\stor.cfg (Malware.Trace) -> No action taken.

i am scared to delete termsrv.dll.
and also any comments on the other malware results would be really helpful.
thank you

harry 48



    Egghead

  • lay back , relax and chill out
  • Thanked: 129
    • Yes
    • Yes
    • Yes
    • Dribbling Pensioner
  • Certifications: List
  • Experience: Familiar
  • OS: Windows 7
Re: malware bytes detects termsrv.dll as trojan downloader
« Reply #1 on: November 23, 2010, 07:50:59 AM »
re-run mbam and remove what ever it finds , also go to below and complete and post the other 2 logs ( hjt and sas ) a malware expert will help you

http://www.computerhope.com/forum/index.php/topic,46313.0.html