PDA

View Full Version : Win32.Agent.pz & Win32.Zbot + rootkit malicious code



TinaH
2010-01-13, 19:54
Spybot discovered Win32.agent.pz & Win32.Zbot on my PC. I have run combofix, which appears to have removed them.

However, combofix has also highlighted rootkit activity - "malicious code at sector 0x017BD141A."

And I'm still getting mysterious music playing / web page redirections when in Explorer 7 (a new iexplore.exe appears in task manager)

Currently running Kaspersky on-line scanner to see if it discovers anything.

Any advice on how to solve this very gratefully received.

tashi
2010-01-13, 20:22
Hello TinaH :welcome:

Please see this forum's FAQ which details how to produce a HJT log and copy paste it into a new topic.
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

If HJT won't run please start a new topic anyway, make note of the situation and and a volunteer analyst will advise you when available.

For future reference: Do NOT run 'FIXES' (ComboFix etc) without being asked (http://forums.spybot.info/showthread.php?t=16806)

Best regards.

http://forums.spybot.info/showthread.php?t=54787