Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan.Zbot Infection


  • Please log in to reply
5 replies to this topic

#1 Crossroad

Crossroad

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 01 November 2012 - 11:39 PM

Hi,

Malwarebytes Anti-malware picked up two Trojan.Zbot on Database version v2012.11.01.08. on my window 7 machine which also have Kaspersky Internet Security 2012 installed.

I was wondering if my computer is still infected.

Thanks

BC AdBot (Login to Remove)

 


#2 Quads

Quads

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:CHCH New Zealand
  • Local time:05:00 AM

Posted 01 November 2012 - 11:58 PM

May be a False Positive for the InstallShield Deleter appearing today

Quads

#3 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:00 PM

Posted 02 November 2012 - 05:40 AM

Did you get something similar to this?

C:\Users\<Username>\Music\Music Two\Photoshop\Photoshop\Adobe Photoshop 7.0 Retail\_ISDel.exe (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\System32\InstallShield\_isdel.exe (Trojan.Zbot) -> Quarantined and deleted successfully.
C:\WINDOWS\winsxs\wow64_microsoft-windows-i..llshield-wow64-main_31bf3856ad364e35_6.1.7600.16385_none_ca61f601a4548b8e\_isdel.exe (Trojan.Zbot) -> Quarantined and


Probably a false positive.

Edited by narenxp, 02 November 2012 - 05:45 AM.


#4 Crossroad

Crossroad
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:00 AM

Posted 02 November 2012 - 05:20 PM

I got the last two but not the first one. I guess it is a false/positive then

#5 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:12:00 PM

Posted 02 November 2012 - 05:37 PM

Yep :)

#6 Quads

Quads

  • Members
  • 86 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:CHCH New Zealand
  • Local time:05:00 AM

Posted 03 November 2012 - 12:34 AM

Malwarebytes has fixed the False Positive, Update the Definitions.

Quads




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users