Author Topic: New alert, is this detected by avast...Trojan Zbot inside zip file  (Read 24115 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #30 on: October 21, 2013, 09:47:29 PM »
Mhm. Will post a log here in a seocnd for you. Will relaunch it. Should all be gone
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #31 on: October 21, 2013, 09:49:46 PM »
Will do.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #32 on: October 21, 2013, 09:57:00 PM »
Logs.
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #33 on: October 21, 2013, 09:59:23 PM »
beat me too it. Dang it!. Lol. It's tried to access the Firewall.

Edit: Just incase you want to see another view... I've attached my logs as well.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Secondmineboy

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3645
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #34 on: October 21, 2013, 10:05:41 PM »
Here i have some Screenshots.

My VM has no software on it, and no updates.

Just Windows 7 Home Premium from scratch.

I will change the VM when i have time, install Adobe Reader, Flash, Java, maybe Firefox and Chrome etc.
« Last Edit: October 21, 2013, 10:11:26 PM by Steven Winderlich »
Windows 10 1909, 4 GB DDR3 RAM, 500 GB 5400 RPM HDD, 1366 by 768 LCD Screen, Intel Core i3 5010U Dual Core, Intel HD Graphics 5500
HUAWEI P30 Pro. Android 10

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #35 on: October 21, 2013, 10:34:18 PM »
Steven your one shows one run key and the bad folder.  Randomly named but very easy to detect.  It doesn't come with ZA or any other nasty stuff :) 

O4 - HKU\S-1-5-21-790779079-295387617-2750372325-1000..\Run: [Hazyw] C:\Users\Steven Winderlich\AppData\Roaming\Onneco\hazyw.exe (Alamanez)
[2013.10.21 21:19:49 | 000,000,000 | ---D | C] -- C:\Users\Steven Winderlich\AppData\Roaming\Onneco


Alan you have that plus some adware rubbish as well

O2:64bit: - BHO: (Feven 1.7) - {11111111-1111-1111-1111-110411051194} - C:\Program Files (x86)\Feven 1.7\Feven 1.7-bho64.dll (Feven)
O4 - HKU\S-1-5-21-65408486-2122880362-1486629332-1001..\Run: [Hawa] C:\Users\Infected\AppData\Roaming\Varo\hawa.exe (Alamanez)
[2013/10/14 18:38:12 | 000,001,166 | ---- | M] () -- C:\END
C:\Users\Infected\AppData\Roaming\Varo

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #36 on: October 21, 2013, 10:38:27 PM »
I knew about the adware. It's been there for a while. Haven't cleaned it yet
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: New alert, is this detected by avast...Trojan Zbot inside zip file
« Reply #37 on: October 22, 2013, 02:29:24 AM »
yeah, the files are randomly named. I cleaned the adware rubbish off the PC. That dind't come from Zeus
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.