PDA

View Full Version : Malware



Max
19-05-2013, 03:42 PM
My Toshiba laptop running Windows 7 64 bit recently was infected with the ZBOT malware.I used Rootkiller,combofix ,hitman and rogue killer to remove it.Avira says its gone as does malware bytes and eset online scanner.However Microsot action centre still red flags and says harmful software detected.Also iexplorer says all exe downloads are viruses and deletes them.Chrome is fine.

wainuitech
19-05-2013, 10:33 PM
No Idea if this will work, but have a read of remove-win32-zbot (http://free.avg.com/us-en/remove-win32-zbot) Normally AVG is crap, but every so often they have a fix for a certain bug.

Sometimes if a system get to infected you cant ever guarantee it will ever be clean again. Sometimes when removing infections the whole system turns to custard.

Often its quicker and easier to save all your data, mails etc, wipe the drive clean, reinstall Windows from fresh and start again then putting all the programs / data back.

Read This article (http://searchsecurity.techtarget.com/definition/Zeus-Trojan-Zbot) :(

linw
20-05-2013, 09:23 AM
Ouch. Can see why you used the purple sad face. OTOH, zbot can't be such a super infection if scanners can identify it. Still don't want it, though!

Speedy Gonzales
20-05-2013, 10:00 AM
See if tdsskiller removes it

Max
20-05-2013, 10:40 AM
Tried that and also AVG one,all scans I now run say no virus however windows action centre still says it is present.

wainuitech
20-05-2013, 11:09 AM
What about IE exe downloads are they still saying infections ?

Are you also sure its the real action Center and not a fake one, as the fakes look very convincing.

Max
20-05-2013, 11:55 AM
Yes IE still saying downloads are viruses.How would I check if action centre is real or fake.

Speedy Gonzales
20-05-2013, 12:20 PM
Disable system restore too then try again

Max
20-05-2013, 05:05 PM
Thanks to all for suggestions however scannow won't work as well as system restore so decided to do full system restore.

Mirddes
22-05-2013, 12:26 PM
linux