Get your own customer support community
 

trojan-spy.win32.zbot.gen .. persistant after several cleanings/removals

This little beast and another one called trojan.crypt.morphene.gen just won't stay gone!

The first sign of it was vipre alerting that it had blocked the file "sysguard.exe" from running.

Clicked OK then saw the little red security shield load on the taskbar with the balloon tip that threats were found on the machine...but then it was gone. I figured vipre stopped it and we were ok..

Did several deep scans but it was always found again. Did a deep scan in safe mode and it still was there again after that, this includes several reboot scans as well.

I have over 9mb of logs to send in, I just need a ticket number to associate it with.

The logs themselves have a lot of Chinese characters in them, that can't be good either.

I've even booted to a live cd and went in to manually delete "sdra64.exe" and it's not there.
I can see in the logs where vipre reports it's not found...but the scan details point to this file being the source.

I'm going to see if Eset has anything that will kill this.

I think my wife got this from a facebook app. It's the only thing she uses the computer for.

-Gordon
 
sad
Inappropriate?
1 person has this question

User_default_medium