Copper-zinc exploration in the Flin Flon-Snow Lake VMS Belt
Recent Results Include 6.69% Copper Over 71.69 Metres and 3.74% Copper Over 21.77 Metres
  • Demo Video
  • Private Messages
  • Edit My Profile
  • View/Edit Portfolio

Email Updates

Search

AGORACOM News Flash

AGORACOM Wire - Wednesday February 15th, 2012

Breaking News ....

Lomiko (LMR: TSX-V) to Complete 43-101 Report on Previous Drilling at the Quatre Milles Graphite Property *CLIENT* Read More

Top Sector Stories ....

Strike Graphite Corp. (TSXV:SRK) Acquires Wagon Graphite Project in Quebec in Vicinity of Timcal's Lac des Iles Graphite Mine *CLIENT* Read More  |  Profile

Strike Graphite goes "Beyond the Press Release"

McLaren Resources (CNSX:MCL) Drills 7.0 Grams Gold Over 7.4 Metres at the TimGinn Property Located Adjacent to the Hollinger Mine *CLIENT* Read More | Watch Beyond the Press Release

DONNER METALS INTERVIEW: David Patterson Discusses the Bracemac-McLeod Mine Development Beyond the Press Release

 AGORACOM Launches GraphiteStocksBlog.com

We're proud to announce the launch of GraphiteStocksBlog.com a website dedicated to the needs of investors and companies in the fast growing Graphite industry.

INAUGURAL GRAPHITE SPONSORS

Message: Zeus Trojan, detection and removal.

Noord aa
Rank: [?]
President
Points: [?]
11750
Rating: [?]
Votes: 129 Score: 3.7
  • Currently 3.7/5 Stars.
Did you know? You can earn activity points by filling your profile with information about yourself (what city you live in, your favorite team, blogs etc.

Zeus Trojan, detection and removal.

posted on Sep 20, 09 06:13AM
Sep 18th

Detecting and Removing the ZEUS Banking Trojan

Posted by: Mel Morris

Bookmark Now

ZEUS has been around in various generations for a few years now. Here is link to an article from 2007 when a ZEUS Trojan infiltrated serveral prominent us organizations ZEUS infects US organizations.

ZEUS is easily and commonly dropped by an exploit and is also carried via social engineering techniques exploiting job sites and the like. The ZEUS Trojan, or the ZEUS Banking Trojan can also be referred to by security firms as WSNPOEM and Gorhax.

Outwardly, a ZEUS infected PC will show no obvious signs of infection. The ZEUS Banking trojan is capable of rifling your Internet cache for stored login and password credentials, it can also eavesdrop on keystrokes and screen contents and can even modify a web page with form injection to capture additional fields - just in case what the criminals want to steal isn't already on the page.

As a recent hyped article claimed ZEUS frequently bypasses popular antivirus and internet security suites. The criminals are careful to infect just a few PCs with each copy of the Trojan, thereby avoiding detection by honepots/nets and subsequent researcher attention in security labs. By the time each copy of a ZEUS Trojan is identified by security researchers it's job is done and a new fresh version will be dispatched to takeover its role.

No one has an accurate account of the real numbers of ZEUS infections, but it must run to millions of PCs worldwide. We uncovered a cache of stolen information captured by a ZEUS trojan earlier this year. This data came from 160,000 PCs infected by ZEUS Trojans. During the six weeks of tracking this crop of infections it reached a peak of 20,000 new PC infections per day.

Now for some tell tale signs of ZEUS. Using this information you will be able to check your PC for signs of infection by ZEUS. You may also use this information to help you remove the ZEUS Trojan, or at least disable it.

The ZEUS trojan will commonly use names like NTOS.EXE, LD08.EXE, LD12.EXE, PP06.EXE, PP08.EXE, LDnn.EXE and PPnn.EXE etc, so search your PCs for files with names like this. The ZEUS Trojan will typically be between 40KBytes and 150Kbytes in size.

Also look for a folder with the name WSNPOEM, this is also a common sign of infection for the ZEUS Trojan.

Finally, check the Registry lloking for RUN keys referencing any of these names.

Do not assume because your antivirus or internet security suite does not show any signs of infection that your PC does not have the ZEUS Trojan infection.

New Message

Please login to post a reply

AGORACOM Quick Tips

Alaskan Junior Gold Co. with Bonanza Grades ... Learn More!

President's D.D.

New feature: Hub Presidents can add important links here.