ZoneAlarm User Community
ZoneAlarm User Community
 

Go Back   ZoneAlarm User Community > ZoneAlarm Forums > Malware Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old March 10th, 2010, 11:32 AM
ronusa_com ronusa_com is offline
Junior Member
 
Join Date: Aug 2005
Location: Lexington, KY.
Posts: 5
Red face Re: Removing Trojan-Spy.Win32.Agent.beaf

I receive the following message from ZA whenever my screen saver comes on. ZA automatically quarantines this virus. How is the best way to remove it.

Thanks!
Ron

Trojan-Spy.Win32.Agent.beaf was found in C:\System Volume Information\_restore{CABC4128-DB31-4141-8BF1-8874E0DA6F79}\RP630\A0131673.exe on 3/10/2010 15:24:46

ZoneAlarm Security Suite version:9.1.008.000
TrueVector version:9.1.008.000
Driver version:9.1.008.000
Anti-virus engine version:8.0.2.42
Anti-virus signature DAT file version:1013602816
AntiSpam version:6.0.0.2383
Reply With Quote
  #2  
Old March 10th, 2010, 11:34 AM
GeorgeV's Avatar
GeorgeV GeorgeV is offline

Guru

 
Join Date: Jun 2006
Location: The 3rd Coast - South Central Texas
Posts: 8,596
Smile Re: Removing Trojan-Spy.Win32.Agent.beaf

Quote:
Originally Posted by ronusa_com View Post
I receive the following message from ZA whenever my screen saver comes on. ZA automatically quarantines this virus. How is the best way to remove it.

Thanks!
Ron

Trojan-Spy.Win32.Agent.beaf was found in C:\System Volume Information\_restore{CABC4128-DB31-4141-8BF1-8874E0DA6F79}\RP630\A0131673.exe on 3/10/2010 15:24:46

ZoneAlarm Security Suite version:9.1.008.000
TrueVector version:9.1.008.000
Driver version:9.1.008.000
Anti-virus engine version:8.0.2.42
Anti-virus signature DAT file version:1013602816
AntiSpam version:6.0.0.2383

Malware Clean-up Guidance
NOTE: the steps below works only if you are on the latest versions of ZA (version 9). If you are not, please update.
Try to perform a full Antivirus/Antispyware scan but in SAFE MODE WITH NETWORKING.

1. Set ZA Antivirus/antispyware to "Ultra Deep Scan" under the advanced options of the ZA antivirus/antispyware tab (scan modes);
2. Reboot in SAFE MODE WITH NETWORKING;
3. Manual run ZA (ZA firewall will be OFF but Antivirus/Antispyware will be functional);
4. Run a full ZA AV/AS scan;
5. Reboot in Normal Mode
6. Set ZA Antivirus/Antispyware back to Normal

How to start in SAFE MODE WITH NETWORKING

If the above fails try to clean your system with:

A. Download update and scan with MBAM
WARNING: Some malware will block the download of this software, rename the installer to a random name before saving and running
B. Use the superantispyware online cleaning tool --> Here or download, update and scan with superantispyware FREE
WARNING: Some malware will block the download of this software, rename the installer to a random name before saving and running
C. Download update and scan with A2 free

Still Problems? Try the bootable CD fromDrWeb

For a final check that your PC is clean run Hitman Pro cloud scanning (the scanner is free not the cleaning)

if ALL the above fails please post your Hijackthis log to BleepingComputer or SpywareHammer

Once you have cleaned the system please remember to purge the windows system restore points. You may be reinfected otherwise.
- Disable system restore (How to disable windows SYSTEM RESTORE);
- Reboot the PC
- Re-ensable system restore
__________________
Guru GeorgeV
ZoneAlarm® Extreme Security

Click here for ZA Technical Support Avail. 24x7 - Excl. Holiday

Click here for ZA Customer Support Avail. 24x7 xcept Holidays
Reply With Quote
  #3  
Old March 13th, 2010, 06:14 AM
jorgie jorgie is offline
Junior Member
 
Join Date: Mar 2003
Posts: 15
Default Re: Removing Trojan-Spy.Win32.Agent.beaf

When virus scanning last night my ZoneAlarm Security Suite came up with 8 of these Trojans and one ending with bdzz.

All seemed to come from a program or programs starting with hp\recoverr\wizard.......

Could that be from Hewlett Packard?

jorgie
Reply With Quote
  #4  
Old March 14th, 2010, 02:45 PM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Default Re: Removing Trojan-Spy.Win32.Agent.beaf

Quote:
Originally Posted by jorgie View Post
When virus scanning last night my ZoneAlarm Security Suite came up with 8 of these Trojans and one ending with bdzz.

All seemed to come from a program or programs starting with hp\recoverr\wizard.......

Could that be from Hewlett Packard?

jorgie
jorgie,

Suggest that you get expert malware help at bleepingcomputer.com The malware expert will work with you one-on-one providing step-by-step detailed instructions to remove all malware from your computer. Please see Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help

Findley
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan-Spy.Win32.Agent.amec mclovin Malware Discussion 0 April 21st, 2009 05:07 PM
Help please re win32.trojan.spy.agent.dbk alert tedi Malware Discussion 0 July 31st, 2008 10:51 AM
Is Win32.Trojan.Spy.Agent.kb a false positive? skjhlkj Malware Discussion 2 May 28th, 2008 10:52 AM
Win32.Trojan.Spy.Agent.kb morey Malware Discussion 13 May 28th, 2008 07:19 AM
What the heck is Trojan-Spy.Win32.Agent.cad?? sandyo ZoneAlarm Antivirus/Anti-Spyware 9 May 21st, 2008 03:05 PM


All times are GMT -8. The time now is 02:38 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
©2003-2010 Check Point Software Technologies Ltd. All Rights Reserved.