Microsoft Security Essentials

  • Scanning, Detecting, and Removing Threats
  • Microsoft Security Essentials
  • All forums
Question

Chrome application and reinstall detected as PWS:Win32/Zbot

Just installed MSE on this system, initial scan returned chrome.exe as severe threat, password stealer. Deleted, reinstalled Chrome (from Google website), same thing. Should I just allow and ignore? This didn't happen on the laptop, where Chrome is also installed...
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation
78 People had
this question

Was this helpful?

2

Votes

Answer

See this link, wherein microsoft says "oops"
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=PWS:Win32/Zbot&threatid=2147598479




    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

1

Vote

Answer

Thanks for the link, Jocelyn!

 

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=PWS:Win32/Zbot&threatid=2147598479

 

On September 30th, 2011, an incorrect detection for PWS:Win32/Zbot was identified. On September 30th, 2011, Microsoft released an update that addresses the issue. Signature versions 1.113.672.0  and higher include this update.

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

MSE detected win32/zbot this morning, suggesting removal. This also removed Google Chrome, and prevents it from being reinstalled. Many other users are having this problem, all starting this morning. Genuine threat, or a false positive from an error in the MSE definitions updated yesterday?
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

I run chrome in sandboxie.  It was blown up when I had MSE remove the threat, and I et the same threat when I try to re-download from  Google home page.

 

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

MSE is flagging Google Chrome as having "PWS:Win32/Zbot"  virus.
Tried removing, quarantining, then reinstalling Chrome but again flagged as virus.
What gives? Seems like a false possitive.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

This happened today since update @ ~13.00

according to this thread over at google-support I'm not the only one
and it has to do with defenition version: 1.113.656.0

Any ideas? Fixes?

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

For more information:

http://www.google.co.uk/support/forum/p/Chrome/thread?hl=en&tid=42d6ba02d7eed070


Google Chrome running on Windows XP.  Microsoft Security Essentials alerted me of password stealing virus called PWS:Win32/Zbot and automatically removed it without my intervention; basically closed out of everything I was doing and gave me the option to restart which I did and to my surprise the Google Chrome exe program was removed from my computer only leaving behind unmapped chrome shortcuts. 

What MS Security Essentials Shows:

Category: Password Stealer

Description: This program is dangerous and captures user passwords.

Recommended action: Remove this software immediately.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:
file:C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
process:pid:1068
process:pid:1600
process:pid:2584
process:pid:2736
process:pid:4076
process:pid:452
process:pid:468
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

this thread:
http://www.google.com/support/forum/p/Chrome/thread?tid=13073ef7ed2ef001

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

http://answers.microsoft.com/en-us/protect/forum/protect_scanning/mse-detects-chrome-as-win32zbot/43435186-35be-4931-acbf-9f020b45ff66

 

Based on the above thread there may be a temporary problem with MSE and Chrome...I'm not familiar with it since I do not use Chrome but I'll be sure MSE Support is aware of your issue.

 

Thanks for reporting it.

 

 

    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

1

Vote

I think the active thread is actually this one: http://www.google.com/support/forum/p/Chrome/thread?hl=en&tid=42d6ba02d7eed070
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

2

Votes

Same thing with MS Forefront.
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation

Was this helpful?

This is a Microsoft problem.  MSE definition file 1.113.656.0 is the culprit.  Microsoft should issue a new definition file immediately with an apology.  Millions of users have been affected!
    • Child exploitation or abuse
    • Harassment or threats
    • Inappropriate/Adult content
    • Nudity
    • Profanity
    • Software piracy
    • SPAM/Advertising
    • Virus/Spyware/Malware danger
    • Other Term of Use or Code of Conduct violation
<< PreviousPage of 4 Next >>

Message marked as answers cannot be deleted

To delete this message, first unmark this message as an answer, then delete it.

Reason to remove escalation


Merge

Enter the thread ID of the thread you are merging into


Reply will be posted to a public thread

You are replying to a public portion of this thread. To reply privately, click Cancel, click the Private Messages tab, and Reply on that private message.

Don't show this message again

To report abuse, sign in or continue without signing in

Thank you.

Report abuse

Abuse type:

Details (optional):

Report abuse

Abuse type:

Details (required):
Enter the characters you see (required):
Type the numbers that you see in the picture.
Play audio and type the numbers that you hear.
Show a different picture.

Sign in

Hotmail, Xbox Live, Messenger, or msn accounts will also work.

Don't have one of the above accounts?

Signing in...
This page will automatically update after you are signed in.
If you are having problems, you can close this message and try to connect again.