Author Topic: New alert, is this detected by avast...Trojan Zbot inside zip file  (Read 24114 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #15 on: October 20, 2013, 09:06:07 PM »
Whoop. It is quite easy to delete. Kill the Proccess in Task Manager, C:\Users\X\Roaming\IG(xxx).

Delete that and then run a scan with MBAM.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #16 on: October 20, 2013, 09:06:59 PM »
Steven. Suggestion. Use Windows 7 VM. Not Windows 8.1. I hate Windows 8
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #17 on: October 20, 2013, 09:10:29 PM »
I will use a Win7 VM. I am running Windows 8.1 at the moment, i had to reset the laptop to factory settings cause it was
crashing several times a day. I think svchost.exe was corrupted or damaged.

Maybe i will go over to Linux if Windows will stay that bad, many people switched to Linux due to Win8.
Most stayed at Windows 7. When Windows is staying at this stage and Windows 7 is outdated i think many will go over to a Mac
or Linux.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
« Last Edit: October 20, 2013, 09:19:29 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #19 on: October 21, 2013, 05:42:03 PM »
Some more info. It modifies the registry to run on boot-up.

HKEY_CURRENT_USER --> Software --> Microsoft --> Windows --> Current Version --> Run

The file is randomly named according to the C:\Users\X\Roaming\[filename]

I'll attach a picture with the virus folder name.

Please Note: The virus folders and executables files are randomly named each time and are not consistant!!

Additionally: Once the file has been run, it caps your CPU to max levels then drops. In order to delete the Roaming folder you need kill the proccess in Task Manager. Note again it will be randomly named and signed by Kemliz (Close, will modify that when I get home) MBAM works against this variant of Zbot.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #21 on: October 21, 2013, 09:06:44 PM »
Youch! I'll edit this post with the folders and the signed name and all that. Uno momento!
« Last Edit: October 21, 2013, 09:29:39 PM by alan1998 »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #22 on: October 21, 2013, 09:10:30 PM »
Now i have a Win 7 Home Premium 32 Bit VM.

Just set it up.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #23 on: October 21, 2013, 09:25:53 PM »
After running the file there is a Trojan sitting in AppData Roaming.

Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #24 on: October 21, 2013, 09:31:09 PM »

The file is randomly named according to the C:\Users\X\Roaming\[filename]


After running the file there is a Trojan sitting in AppData Roaming.

Also, opsted pics in my last post....
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #25 on: October 21, 2013, 09:37:49 PM »
For me the file tried to access Windows Mail, which was not working.

I am running this inside VMWarePlayer cause Virtualbox is not working for me at the moment, i cannot drag and drop files.
Even when its activated in the settings.

I also have Ubuntu and Linux Mint as VM.
« Last Edit: October 21, 2013, 09:40:23 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #26 on: October 21, 2013, 09:42:17 PM »
Have you sent a copy to Avast ?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #27 on: October 21, 2013, 09:42:47 PM »
Windows Mail? Was probably trying to mass email itself.... Hmm. it tried to connect to my network. Blocked by Windows Firewall.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #28 on: October 21, 2013, 09:43:21 PM »
Have you sent a copy to Avast ?

Avast! Detects the file and the site. No need to. We are messing with it at this point....
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #29 on: October 21, 2013, 09:44:54 PM »
Have fun :)

Could you run an OTL scan when it is installed so that I can have a look see