PDA

View Full Version : Win32.ZBot infection



Husky_
2010-05-05, 10:38
Dear all,

When I last scanned with Spybot, it found a Win32.ZBot infection. More specifically, it found the following entries:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\\Windows NT\CurrentVersion\\Winlogon\Userinit=...C:\WINDOWS\system32\sdra64.exe...
- C:\WINDOWS\system32\sdra64.exe
- C:\WINDOWS\system32\lowsec\local.ds
- C:\WINDOWS\system32\lowsec\user.ds
- C:\WINDOWS\system32\lowsec

I read in some posts on this forum that the best way to get rid of this infection is by formatting and reinstalling the OS. However, I do not have time to do this at the moment, so any advice for removing this infection would be greatly appreciated.

Many thanks in advance.

Husky_

tashi
2010-05-05, 19:11
Hello Husky_,

Please see this forum's FAQ and follow the instructions to post a preliminary DDS log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) then start a new topic. :)

A volunteer analyst will advise you when available.

Best regards.