Author Topic: Dangerous site with Zeus malware...  (Read 31334 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Dangerous site with Zeus malware...
« on: July 19, 2010, 10:00:07 PM »
« Last Edit: July 19, 2010, 10:05:22 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Dangerous site with Zeus malware...
« Reply #2 on: July 20, 2010, 12:50:55 AM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Dangerous site with Zeus malware...
« Reply #3 on: July 20, 2010, 07:27:12 AM »
Dear Polonus,

Nice to share,

By the way, have you try to run it with avast antivirus protected?
Whether avast! can protect from this kind of Malware?

Because according to one of article that mentioned Zeus Malware is one of hardest financial malware to get detected.
The reference link is : hxxp://thepcsecurity.com/latest-security-software-cannot-detect-zeus-virus/
« Last Edit: July 20, 2010, 08:05:55 AM by Yanto.Chiang »
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Dangerous site with Zeus malware...
« Reply #4 on: July 20, 2010, 02:04:42 PM »
Hi Yanto.Chiang,

This was not detected here: http://www.virustotal.com/analisis/e47a7e823f05eacb49bbc026094f4f0246999f35ee754f4813d1f29df6cf0082-1279623641

Anubis report: http://anubis.iseclab.org/?action=result&task_id=1bf73ff18d51b7eb4252fb6f2e61b9f78

But let us wait for our good friend, Pondus, he will check for the latest detection: MD5 hash =
9a04271668a0ce4beb9514226cd08835

Further checks: http://www.malwaregroup.com/Virustotals

Well the main line of infected computers is Windows XP2 and the bot has to my knowledge not yet arrived at Windows7, so people/firms are strongly advised to upgrade from Windows XP2....Some 3.6 million PCs are said to be infected in the U.S. alone!
but it remains unclear if modern antivirus software is effective at preventing all of its variants from taking root.
So to fully patch and to use in-browser-security like blocking woth RP and NS are the best measures one can take,
avast also has the shields to prevent an infection to take place...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Dangerous site with Zeus malware...
« Reply #5 on: July 20, 2010, 02:15:59 PM »
The VT result you posted seems to be the latest, only PCtools and Symantec/Norton detect....

ThreatExpert
http://www.threatexpert.com/report.aspx?md5=9a04271668a0ce4beb9514226cd08835

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Yanto.Chiang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1371
  • Soli Deo Gloria
    • PT Garuda Sinatriya Globalindo
Re: Dangerous site with Zeus malware...
« Reply #7 on: July 21, 2010, 05:18:15 AM »
Dear Pondus and Polonus,

Thanks for your up to date,

by the way, yesterday i was found one of article at website that mentioned avast! is the one of few antivirus can detect this attacks.

You may visit to : http://www.malwarehelp.org/find-and-remove-zeus-zbot-banking-trojan-2009.html

Anyway, i also found at avast! history database that provided to protect from Zeus attacks.
Yanto Chiang | IT Security Consultants | AVAST Premium Security | GarudaSinatriya

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Dangerous site with Zeus malware...
« Reply #8 on: July 24, 2010, 01:09:32 PM »
Hello all guys,i am new here,i went to this site but my avast didnt warn me,i got infected?please tell me i am avast fan :)
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Dangerous site with Zeus malware...
« Reply #9 on: July 24, 2010, 01:29:20 PM »
plzz tell me
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Dangerous site with Zeus malware...
« Reply #10 on: July 24, 2010, 03:56:19 PM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Dangerous site with Zeus malware...
« Reply #11 on: July 24, 2010, 07:19:33 PM »
Hello Polonus
I runned a full scan with avast 5,it didnt detect any zeusbin virus etc.i just want to know if it is hiden somewhere i only went to this site nothing more,my avast detected win32:malware-GEN i chosed "move to chest" and run a full "scan" with CCleaner,2Questions:
i have been detected by zeus?
WIN32:Malware-GEN will back in pc?or it deleted for ever

waiting for your reply,thanks a lot

AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Dangerous site with Zeus malware...
« Reply #12 on: July 24, 2010, 09:36:28 PM »
Hello Polonus
I runned a full scan with avast 5,it didnt detect any zeusbin virus etc.i just want to know if it is hiden somewhere i only went to this site nothing more,my avast detected win32:malware-GEN i chosed "move to chest" and run a full "scan" with CCleaner,2Questions:
i have been detected by zeus?
WIN32:Malware-GEN will back in pc?or it deleted for ever

1. Run a boot time scan with avast..! (32bit only)
2. Run free Mbam: http://www.malwarebytes.org/mbam.php
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Dangerous site with Zeus malware...
« Reply #13 on: July 24, 2010, 11:29:58 PM »
2 QUESTIONS,JUST ANSWER PLEASE DONT GIVE ME LINKS FOR MB

i have been detected by zeus?
WIN32:Malware-GEN will back in pc?or it deleted for ever

just answer THANKS A lot
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Dangerous site with Zeus malware...
« Reply #14 on: July 25, 2010, 10:50:27 AM »
give me an answer please
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus