PDA

View Full Version : Does spybot detect Zeus and its varients?



spynot
2010-11-04, 04:29
Hi....I have read that some anti-virus programs cannot detect what I think is called Zeus in some of it's varients. News items on the web state that this potentially undetectable malware is widespread and can steal personal data. Can spybot detect known Zeus varients? can it detect unknown varients? which anti virus scanners can?
Aforementioned news items do not spell out which-if any-antivirus programs are effective. This appears to make a mockery of on-line security....if there is a reliable means of detecting zeus surely the methods should be shared with all antivirus /antimalware distributers.
It would be interesting to know what the estimated percentage of infected computers is, so at least one could guess the chances of ones own pc being infected.
Thanks for reading this.
I have spent some time online looking for the answers.

Yodama
2010-11-04, 11:24
Current variants of Zeus also known as ZBot use Rootkit functions to hide and protect itself, this makes it very hard to counter it on an active system.

The best way to find and remove ZBot variants is to use an offline scanner, i.e. boot with another Operating System for instance a BootCD since these cannot be affected by the rootkit functions. Spybot S&D is also available on a BootCD (http://www.safer-networking.ie/en/paragraphs/home_bootable_cds.html).

Spybot S&D does have signatures for detection of ZBot, but we cannot guarantee that all variants are covered since ZBot is very active and its developers and deployers constantly try to enhance ZBot with new variants.
So depending on the actual infection it may be necessary to gather information on the infected system and release custom detection rules.

Basically no vendor of security software can claim to remove all variants of ZBot, anyone claiming this would be lying.

spynot
2010-11-04, 15:25
Thanks Yodama for your reply it has been very informative. I will try offline scanning. Cheers!