Author Topic: WIN 32 KADRBOT  (Read 5069 times)

0 Members and 1 Guest are viewing this topic.

kelltic

  • Guest
WIN 32 KADRBOT
« on: November 13, 2011, 06:53:04 PM »
On November 8th my system was infected with the WIN 32 KADRBOT (so-called by AVAST!). Besides AVAST, I've run several of Kaspersky's fixes and Malwarebytes - which I think is the app that finally got it - in safe mode.  Finally, it seems I have my computer back. 

However, this morning I ran DeBank, an application that checks for banking trojans. This is the report I got:

W32/Zeus variant detectd in the process C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

Pieces of potentially malicious code were found in the memory. It is strongly advised that you run a proper AntiVirus scan on the machine. Below you can find some free online scanners.


I am wondering if this could be correct.   

I'm using WindowsXP.

Thanks.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89249
  • No support PMs thanks
Re: WIN 32 KADRBOT
« Reply #1 on: November 13, 2011, 06:56:12 PM »
Argh memory scans, this is no different to avast making detections on other security software that has virus signatures loaded into memory.

Memory scans cause more confusion than comfort, nit to mention, detecting it in memory would be somewhat late as it is loaded.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

iyogisolutions1

  • Guest
Re: WIN 32 KADRBOT
« Reply #2 on: November 14, 2011, 09:02:13 AM »

W32/Zeus variant detectd in the process C:\Program Files\Alwil Software\Avast5\AvastSvc.exe

Thanks for the information

As you know, the infection detected was a W32/Zeus variant.

So for this type of malicious Microsoft has Malicious Software Removal Tool updates

So please get this tool by doing windows update and be safe

I would suggest you please don't use any other security softwares, because it would conflict with Avast.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89249
  • No support PMs thanks
Re: WIN 32 KADRBOT
« Reply #3 on: November 14, 2011, 12:42:41 PM »
Did you even read my post, obviously not, this is detecting virus signatures in memory (not real viruses) loaded into memory by avastSvc.exe and why memory scans return weird results.

Why else wouldn't it find any associated files registry entries.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76034
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: WIN 32 KADRBOT
« Reply #4 on: November 14, 2011, 12:53:14 PM »
Did you even read my post...

Guess he didn't. :(
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

kelltic

  • Guest
Re: WIN 32 KADRBOT
« Reply #5 on: November 14, 2011, 03:01:05 PM »
The virus was detected by AVAST. It is now gone - 90% sure. No more problems online, no more Firewall going crazy, no more AVAST jumping up with warnings about programs I've had on my system for years, and no more thousands of cookies.

I posted because I wanted to know if the DeBank report could have an validity.

Thanks to all who answered me. I appreciate it.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89249
  • No support PMs thanks
Re: WIN 32 KADRBOT
« Reply #6 on: November 14, 2011, 03:14:06 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security