ZoneAlarm User Community
ZoneAlarm User Community
 

Go Back   ZoneAlarm User Community > ZoneAlarm Forums > Malware Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old March 7th, 2010, 07:14 PM
chuckgco chuckgco is offline
Junior Member
 
Join Date: Mar 2010
Posts: 1
Default Found Trojan-Spy.Win32.Agent.bdrd files -- frustrated with ZA Security Suite

Found Trojan-Spy.Win32.Agent.bdrd files -- frustrated with ZA Security Suite

I am running a paid and fully functional multi-P.C. ZoneAlarm Security Suite license.
(version 9.1.008, anti-virus/spyware engine version 8.0.2.42)

I have recently had a ZA scan pick Trojan-Spy.Win32.Agent.bdrd
in several locations on my C: drive. ZA says it has put the file in
quarantine. Unfortunately, every time I reboot my P.C., the damn
thing returns and within a short time ZA says it found it again.
I can't delete what is in quarantine. I cannot select or delete the items.

Not trusting ZA, I installed another reputable malware application.
It found Trojan entries in my registry that ZA missed. It found them
and deleted them.

After a reboot, I did another scan with ZA which came up clean.
Then WHAMO, about an hour later the Trojan alert was back, many of them:

C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056950.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056951.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056952.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056953.exe

etc ...

I am not one to travel to obviously risky websites. I update my
ZA database each day that I turn on my P.C.

So what now? I am losing trust and patience in my fully paid for ZA?
What good is it to have a security suite that can't protect you?
And is there really any live tech support available?

Besides having to reformat and restore my entire system, what can I do?
Any thoughts would be appreciated.
Reply With Quote
  #2  
Old March 10th, 2010, 06:26 AM
GeorgeV's Avatar
GeorgeV GeorgeV is offline

Guru

 
Join Date: Jun 2006
Location: The 3rd Coast - South Central Texas
Posts: 8,596
Smile Re: Found Trojan-Spy.Win32.Agent.bdrd files -- frustrated with ZA Security Suite

Welcome to the Zone Alarm User Forum..

This Forum exist to allow Volunteer experienced Zone Alarm Users to help the Few Users who encounter a problem with ZoneAlarm and need to be guided in the right direction..


You did say you only updated ZA once a day..?

In todays environment with 100's of new threats created evey day, no Security program can provide 100% protection against everything.
Zone Alarm AV, Suite and Extreme 9.1 can be configured to check for AV/AS updates every 30 minutes.. on my computers I have noticed as many a 16 updates in one day..

http://forums.zonealarm.com/showthread.php?t=72655


You asked if there was access to Live Tech Support?
With a Valid ZA Licence you can Contact ZA Tech Support Live Chat Free of charge..

Click on the Support link in my Signature..
__________________
Guru GeorgeV
ZoneAlarm® Extreme Security

Click here for ZA Technical Support Avail. 24x7 - Excl. Holiday

Click here for ZA Customer Support Avail. 24x7 xcept Holidays

Last edited by GeorgeV; March 10th, 2010 at 07:22 AM. Reason: typo
Reply With Quote
  #3  
Old March 10th, 2010, 07:16 AM
fax's Avatar
fax fax is online now

Guru

 
Join Date: Nov 2004
Location: localhost
Posts: 13,632
Default Re: Found Trojan-Spy.Win32.Agent.bdrd files -- frustrated with ZA Security Suite

Quote:
Originally Posted by chuckgco View Post
After a reboot, I did another scan with ZA which came up clean.
Then WHAMO, about an hour later the Trojan alert was back, many of them:

C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056950.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056951.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056952.exe
C:\System Volume Information\_restore{7F7BE6F8-OD6A-488B-ABDC-75393719A72D}\RP525\A0056953.exe
Follow ALL steps suggested here:
Malware Clean-up Guidance

One last step of the procedure includes the purge of restore points.
Exactly what you are probably missing judging from the above restore points lines

See here below how to setup yoru system and keep it clean!
xyz was not detected. What I should do?

Fax
__________________

Click here for ZA Technical Support
Avail. 24x7 hours - Excl. Holiday
Click here for ZA Customer Support
Avail. 24x7 hours - Excl. Holiday
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan-Spy.Win32.Agent.amec mclovin Malware Discussion 0 April 21st, 2009 05:07 PM
Help please re win32.trojan.spy.agent.dbk alert tedi Malware Discussion 0 July 31st, 2008 10:51 AM
Is Win32.Trojan.Spy.Agent.kb a false positive? skjhlkj Malware Discussion 2 May 28th, 2008 10:52 AM
Win32.Trojan.Spy.Agent.kb morey Malware Discussion 13 May 28th, 2008 07:19 AM
What the heck is Trojan-Spy.Win32.Agent.cad?? sandyo ZoneAlarm Antivirus/Anti-Spyware 9 May 21st, 2008 03:05 PM


All times are GMT -8. The time now is 01:54 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
©2003-2010 Check Point Software Technologies Ltd. All Rights Reserved.