Today we will be discussing a new form of malware that was released 5/16/2013 and that is the
Trojan.Zbot!gen41 this particular variation of trojan has very specific directions on what to target but at the same time it was poorly written and it is easy to detect. So lets dive into this new malware sample, and by the end of this you will know how to avoid the trojan and remove the program the program from your computer.
Effects
This malware was designed to specifically go after important bank information and goes through a number of ways to get it. The trojan will even try going through your saved files and passwords on internet explorer to retrieve important passwords. The Zeus trojan also goes through any programs such as Thunderbird which it will try to gather any passwords for the email accounts that are being used. So as you can tell the point of this program is to gather any and all passwords that it can get it's hands on. Now after the malware has gotten onto the computer it will try to download a worm which was identified by Symantec as the W32.Waledac. After the computer gets these malicious items on it the creator can feed the trojan commands and tell it to do various commands such as: shutdown the computer, reboot the computer, delete files, and delete important system files which requires you to reinstall the operating system.Signs Of Infection
The computer will be running slower however this is commonly shared with all forms of malware. There are other main signs such as the computer randomly shutting down or rebooting which should not be happening but this is generally a clear cut sign of malware, or some form of a driver issue. Which might also lead to random shutdowns, but you want to check all possibilities before trying to fix the issue. So please go down to the secondary scanners and run any combination of them to see if your computer is infected.Removal
You can remove the malware by using the secondary scanners below, and they will detect the malware. However you need to realize that if one of them says that your computer is safe there is still a chance that the computer is infected with some sort of malware. So make sure to use two or three of the scanners below. I recommend that you use Malwarebytes and HitmanPro because they are the most powerful secondary scanners on the market.
Protection
If you want to protect against the malware you will want an up to date antivirus and firewall. I recommend that you use Ad Aware Antivirus or Avast Free Antivirus because these two have always found malware that someone else has missed. But make sure that you only use one of the above antivirus products because we want to avoid confliction between them. For your firewall I recommend that you use Comodo free firewall which offers the best HIPS protection in the industry, and it contains a ton of extra features like the Sandbox and the Comodo Kiosk.Secondary Malware Scanners
- HitmanPro- http://www.surfright.nl/en/hitmanpro/
- Panda Active Scan- http://www.pandasecurity.com/homeusers/solutions/activescan/
- Malwarebytes- http://www.malwarebytes.org/
- Super AntiSpyware- http://www.superantispyware.com/
- Bitdefender Quick Scan- http://quickscan.bitdefender.com/
- Norton Power Eraser- http://security.symantec.com/nbrt/npe.aspx
- Kaspersky TDSSKiller- http://kaspersky-tdsskiller.en.softonic.com/
- McAfee Stinger- http://www.mcafee.com/us/downloads/free-tools/stinger.aspx
- Trend Micro House Call- http://housecall.trendmicro.com/
- Eset Onlne Scanner- http://www.eset.com/us/online-scanner/
- Dr.Web CureIt! - http://www.freedrweb.com/cureit/

0 comments:
Post a Comment