How to detect the ever changing Zeus bot infection?

Hi malware fighters,

There has been seen quite an increase in Zeusbot infections lately. How to detect the various everchanging variants has been described here:
http://blogs.technet.com/mmpc/archive/2010/03/11/got-zbot.aspx

polonus


Nice information … thanks for the link, Polonus :slight_smile:

One reason I like to see HJT logs is that userinit shows up and can be checked whether or not what is listed is good or not.


Hi CharleyO,

The latest version of Zeusbot now comes with a MS installation protection against pirated versions:
http://www.secureworks.com/research/threats/zeus/?threat=zeus
Link: http://www.theregister.co.uk/2010/03/12/new_zeus_features/

polonus


Thanks for the additional links, Polonus, as it is interesting reading. :slight_smile: