NoAdware Home | Blog Home | NoAdware Features | Support | NoAdware Download

December 05, 2007

How To Remove Trojan.Zlob-xa Right Now!

Here you will find manual removal instructions because software most often are not able to automatically remove this trojan.

Step by step instructions... follow each step. First read each step before applying what there is to do, since at the bottom there are instructions to help you complete each step.

Step ONE:

Kill Trojan.Zlob Running Process.

* isamini.exe,
* isamonitor.exe
* pmmon.exe

Note:

How to kill running process.

* Please go to 'Start' and then click on 'Run'
* Now in the Run command box, type 'taskmgr.exe', and then click on 'OK'

Then click on the Processes tab and in that list find each of the files. To kill them, click once on them and they are higlighted, then click on End Procces button.

(If you cannot find some files they do not exist, so skip them)

Step TWO:

Unregister Trojan.Zlob DLL file

* dfrep.dll
* ieffse32.dll

Note:

HOW TO UN-REGISTRY DLL FILE :

* Please go to 'Start' and then click on 'Run'
* Now in the Run command box, type 'cmd', and then click on 'OK'
* Type regsvr32 /u filename.dll where 'filename' is the name of the file that you like to Unregister.

(If you cannot find some files they do not exist, so skip them)

Step THREE:

Remove/Modify Trojan.Zlob Registry Entries

Click Start, then Run.
Type regedit
Then click OK

HKEY_CLASSES_ROOT\Interface\
{418985AE-4FE4-448D-83EE-
238C887D8FC2}

HKEY_CLASSES_ROOT\Interface\
{5F251303-F8C4-44C3-A7C2-9E8A
93C59322}

HKEY_CLASSES_ROOT\Interface\
{61840430-C7CF-43A0-9D49-3B3E
D563FED1}

HKEY_CLASSES_ROOT\Interface\
{64A8E3CA-AE17-4EB0-8C67-47D
1103A5B6F}

HKEY_CLASSES_ROOT\Interface\{
765A8F7D-F57B-4601-A038-3F463A
4D3193}

HKEY_CLASSES_ROOT\Interface\{
77E616D5-5DB4-4B6A-8BDA-2BE4
103A9921}

HKEY_CLASSES_ROOT\Interface\{8
742F319-C916-4930-B781-1C148134
C05C}

HKEY_CLASSES_ROOT\Interface\{8
97F5CB6-C1C1-494E-8F17-97278419
3442}

HKEY_CLASSES_ROOT\Interface\{A
2224C72-745E-4046-882F-1A48C9311D77}

HKEY_CLASSES_ROOT\Interface\{A
A500EFC-3C92-44C9-B1D6-7A70333
43A50}

HKEY_CLASSES_ROOT\Interface\{A
B5E9971-7086-4E6E-ADFA-BE9C68
5BE68B}

HKEY_CLASSES_ROOT\Interface\{
AD7CA0BC-693A-4AF9-B31A-6047
2248F761}

HKEY_CLASSES_ROOT\Interface\{
B2882CC2-0077-426B-916D-E0B9E
A23A1B5}

HKEY_CLASSES_ROOT\Interface\{
EE241504-6F15-49E4-847F-B4D7D
A9EA8F9}

HKEY_CLASSES_ROOT\Interface\{
F1666E4E-45C8-462A-97FF-BFD5A
103BFFA}

HKEY_CLASSES_ROOT\Interface\{
FD9A05E8-4A1E-45E6-B3B6-37CE2
0140278}

HKEY_CLASSES_ROOT\TypeLib\{
AF0C5CBA-52E1-4B29-A2DC-58D91
D599612}

Note:

Before you start deleting first backup your registry and here is step by step instructions... including a free software that does it automatically for you.

Then on my other blog post you find out how to delete registry entries step-by-step.

(If you cannot find some entries they do not exist, so skip them)

Step FOUR:

Search and delete these Trojan.Zlob Related Files

To search, click Start, then Search, then click on For files or folders...

* pmmon.exe
* pmsngr.exe
* isamonitor.exe
* iesplugin.dll
* iesuninst.exe
* Security Troubleshooting.lnk
* Online Security Guide.lnk
* Online Security Test.url
* isaddon.dll
* isamini.exe
* isamonitor.exe
* pmmon.exe
* pmsngr.exe
* dfrep.dll
* cfg.dat
* ieffse32.dll
* lbf.tme
* regmod.exe

(If you cannot find some files they do not exist, so skip them)

Leave comments.



Click to email this useful post to a friend:

2 Comments on this post. Post your comment :)



Attention: Do you want to get Your Name, Photo and Comment posted on the site? We want honest and sincere people. Do it NOW, click here to take survey!

2 Comments:

Great insightful advice, spware and adware can slow down your hardrive, hurt your business and you outlined in great detail how NOT to let that happen. Thanks for the informative post!

Take care
Jeff Casmer
Work at Home

By Blogger Jeff Casmer, at 8:52 PM  

I'm glad you found it useful Jeff!

Thanks,
Karl

By Blogger Karl Sultana, at 1:31 AM  

Post a Comment

Links to this post:

Create a Link