Wilders Security Forums  

Go Back   Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 25th, 2012, 09:55 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default explorer.exe infected with a variant of Win32/spy.zbot.ZR

Hi
On a customer's PC Eset NOD32 V4.2.71 is detecting this now and then in startupscanner (unable to clean).
A full scan often does not find/clean it. Is there a removal tool available that i can advise to use?

Greetings from Holland
  #2  
Old April 25th, 2012, 10:16 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

Just a suggestion,why not update to version 5 0.95 and go from there.Try to remove it in safe mode maybe your best bet.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.

Last edited by Dark Shadow : April 25th, 2012 at 10:27 AM.
  #3  
Old April 25th, 2012, 11:28 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

the reason i did not do is beacause it is a Business edition (there is no v5 available, only RC endpointsecurity)
  #4  
Old April 25th, 2012, 11:29 AM
Dark Shadow's Avatar
Dark Shadow Dark Shadow is offline
Massive Poster
 
Join Date: Oct 2007
Location: USA
Posts: 4,550
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

Quote:
Originally Posted by duijv023
the reason i did not do is beacause it is a Business edition (there is no v5 available, only RC endpointsecurity)
I see.
__________________
OS X 10.8.3 - 2.9 GHz Intel core i7 - 8 GB 1600 MHz DDR3 - 750 SATA HD - Intel HD 4000 Graphics 512 MB.
  #5  
Old April 25th, 2012, 01:06 PM
Rusty_Shackleford's Avatar
Rusty_Shackleford Rusty_Shackleford is offline
Infrequent Poster
 
Join Date: Nov 2011
Location: USA
Posts: 11
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

I would boot the computer into safe mode with networking and run an ESET On-demand Scan:

http://www.eset.com/us/online-scanner/

if that doesn't work then you may want to run TDS Killer from kaspersky:

http://support.kaspersky.com/faq/?qid=208283363
  #6  
Old April 25th, 2012, 04:51 PM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

Wasn't it detected during a memory scan? Please copy & paste the appropriate record from the Threat log here.
  #7  
Old May 1st, 2012, 07:20 AM
duijv023's Avatar
duijv023 duijv023 is offline
Frequent Poster
 
Join Date: Feb 2006
Location: Rijnsburg, Netherlands
Posts: 230
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

Unfortuately I only have access to ERAC at this moment.
There I see:

Column Name Value
Threat Id Threat 1103
Client Name ######
Computer Name ######
MAC Address 0019d1a990aa
Primary Server ######
Date Received 2012-04-22 16:25:26
Date Occurred 2012-04-22 16:21:21
Level Critical Warning
Scanner Startup scanner
Object file
Name Operating memory » explorer.exe(30
Threat a variant of Win32/Spy.Zbot.ZR trojan
Action unable to clean
User
Information
Details Ready


Column Name Value
Client Name ######
Computer Name ######
MAC Address 0019d1a990aa
Primary Server ######
Domain ###.###
IP 192.168.1.27
Product Name ESET NOD32 Antivirus BUSINESS EDITION
Product Version 4.2.71
Policy Name Default Primary Clients Policy
Last Connected 2012-05-01 13:10:38
Protection Status Text
Virus Signature DB 7100 (20120501)
Last Threat Alert a variant of Win32/Spy.Zbot.ZR trojan
Last Firewall Alert
Last Event Warning
Last Files Scanned
Last Files Infected
Last Files Cleaned
Last Scan Date
Restart Request
Restart Request Date
Product Last Started 2012-04-27 09:09:19
Product Install Date 2008-06-17 10:01:13
Roaming User
New Client Yes
OS Name Microsoft Windows XP 5.1.2600 Service Pack 3
OS Platform Microsoft Windows
HW Platform 32-bit
Configuration Ready (2 hours ago)
Protection Status Ready (3 days ago)
Protection Features Ready (14 months ago)
System Information Ready (2 hours ago)
SysInspector No Data
Custom Info
Comment


In a few days, I hope to be onsite again
  #8  
Old May 1st, 2012, 10:22 AM
Marcos Marcos is offline
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,185
Default Re: explorer.exe infected with a variant of Win32/spy.zbot.ZR

Try running a scan with sig. db 7104. If it's still detected only in memory, it will be necessary to create a SysInspector log and check it for suspicious files. Also a complete memory dump of explorer.exe (PID 308) and submitting it to the ESET viruslab along with the ESI log might help determine the malicious file.

Last edited by Marcos : May 2nd, 2012 at 10:11 AM.
 

Wilders Security Forums > Official ESET Support Forum > ESET Home Users Products Forum > ESET NOD32 Antivirus « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:06 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums