Author Topic: Is Avast finding Zeus3  (Read 9763 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Is Avast finding Zeus3
« Reply #15 on: August 17, 2010, 09:27:29 AM »
Virustotal results here

Is VT down..??
Can't reach it...
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89201
  • No support PMs thanks
Re: Is Avast finding Zeus3
« Reply #16 on: August 17, 2010, 03:41:59 PM »
Whilst this is a long time after your post, VT isn't down but it is very slow in loading right now, but the delay seems to be in ajax.googleapis.com, see image.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wompa

  • Guest
Re: Is Avast finding Zeus3
« Reply #17 on: August 17, 2010, 05:43:53 PM »
How widespread is Zeus3?

iRonzel

  • Guest
Re: Is Avast finding Zeus3
« Reply #18 on: August 18, 2010, 03:18:14 AM »
Virustotal results here

Is VT down..??
Can't reach it...
asyn


New upload and link:

http://www.virustotal.com/file-scan/report.html?id=543d5d279e1c24f0f89e4e7a3d8411b0a58a6c3d95ef66f9c540a52f1082aa34-1282095086

Edit: The results from the first time that I uploaded the file was 2/41

Edit: One day diferrence; 19 AV detecting it
« Last Edit: August 18, 2010, 03:25:05 AM by iRanzel »

iRonzel

  • Guest

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: Is Avast finding Zeus3
« Reply #20 on: August 18, 2010, 11:32:10 PM »
Hi iRanzel,

This is a proactive Heuristic Detection, which may be triggered by a file that behaves in a suspicious manner indicative of malware infection.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Is Avast finding Zeus3
« Reply #21 on: August 19, 2010, 12:57:34 AM »
Additional detalis on F-secure's Suspicious: Gemini

Quote
Suspicious:W32/Malware!Gemini is a proactive Heuristic Detection, which may be triggered by a file that behaves in a suspicious manner indicative of malware infection.

http://www.f-secure.com/v-descs/suspicious_w32_malware!gemini.shtml

Summary -    Suspicious:W32/Malware!Gemini
Quote
The file appears to be performing suspicious or potentially undesirable actions on the system. This may potentially indicate the presence of a malware infection, or that the suspect file is malicious.
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Is Avast finding Zeus3
« Reply #22 on: August 19, 2010, 01:29:39 AM »
In the Ikarus detection the identification zbot has no further qualifier

such as with zbot.ikh  http://www.securelist.com/en/descriptions/Trojan-Spy.Win32.Zbot.ikh
or with zbot.PI    http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS:Win32/Zbot.PI

so probably look to the generic grouping which are banker trojans   http://www.f-secure.com/v-descs/trojan-spy_w32_zbot.shtml
and for good measure   http://www.symantec.com/security_response/writeup.jsp?docid=2010-011016-3514-99

So careful
But Ikarus give no indication of where the zbot ID has come from and their info center offers no further insight. Considering the zbot DNA has been out for a while now, I think you would expect a few more AVs to make detections, if not provide more specific data on the zbot ID.

But as I say be careful. What gives you the idea that is Zeus v2
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.