Trojan-Banker.Win32.Qbot.gen found -> recover system? Win10

Configure and optimize you computer for Audio.
RELATED
PRODUCTS

Post

hi guys, strange thing, i got no warez and ran today only youtube in firefox + outlook where no mail with attachment was received + in firefox i didnt download anything. suddenly kaspersky warned me 5 VST3 files are infected, strange, so i deleted them then 20 mins later 5 vst dlls... i shut down my pc and switched of my 2 external hdds + switched off my internetconnection (i downloaded and installed malwarebytes before shutting down). turned my pc on and scanned, nothing found with malwarebytes and kaspersky too first but then again 5 files found VST3 again... i dunno i mean does the virus spread 20-30 mins to 5 new files or is this some kaspersky false positives?

im not sure yet what to do, i did sadly my last image backup with acronis about 2 months ago, i didnt change much i think cause i work mostly with the 2 external hdds. so i thought maybe to recover this image or do you have any ideas? i had false positives in the past too but not like this behaviour
DAW FL Studio Audio Interface Focusrite Scarlett 1st Gen 2i2 CPU Intel i7-7700K 4.20 GHz, RAM 32 GB Dual-Channel DDR4 @2400MHz Corsair Vengeance. MB Asus Prime Z270-K, GPU Gainward 1070 GTX GS 8GB NT Be Quiet DP 550W OS Win10 64Bit

Post

Is your machine connected to a network, either by WiFi or ethernet? If so disconnect then run the cleaners again and see if it comes back.
If it doesn't then there maybe another machine/device on the network that is infected and maybe trying to propagate itself to other devices.
If it does come back while disconnected then it implies you have something hooky on your device.

https://www.f-secure.com/v-descs/trojan ... nker.shtml

Post

You could try uploading one of the suspicious DLLs to a service like VirusTotal. It'll run your file through all the major virus/malware scanners and report back what they all found. It's not going to tell you definitively if something is or isn't infected, but knowing how widespread detection is can be helpful. A completely or near-unanimous result is obviously cause for worry, but if only 1 or 2 scanners detect an issue that could be grounds to suspect a false positive.

Post

I'd try an offline scanner via USB and Rufus.
10 Free Bootable Antivirus Rescue Disks
https://www.thepcinsider.com/best-boota ... ks-windows

Post

look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.

Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
I don't make audio products anymore. I sell furniture & smart products.

Post

Might just have been a false positive in the scanner, those happen.
Note I do not run any antiviruses on the machine anymore, only online scan few times a year.
Soft Knees - Live 12, Diva, Omnisphere, Slate Digital VSX, TDR, Kush Audio, U-He, PA, Valhalla, Fuse, Pulsar AUDIO, NI, OekSound etc. on Win11Pro R7950X & RME AiO Pro
https://www.youtube.com/@softknees/videos Music & Demoscene

Post

Sounds like an afx track - try opening it with foobar

Post

kingozrecords wrote: Mon Sep 11, 2023 9:12 pm look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.

Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
What makes you think this is actually the culprit here? Wouldn't his anti-virus software have found that when present?

Throwing out random advice imho does not help anyone.
We are the KVR collective. Resistance is futile. You will be assimilated. Image
My MusicCalc is served over https!!

Post

Use another PC(non infected) to create a bootable USB with some AV.


7 Free Bootable Antivirus Disks to Clean Malware From Your PC
https://www.makeuseof.com/tag/free-boot ... are-disks/

Post

This page should contain creditable info (from Kaspersky) about qbot/QakBot:
https://securelist.com/qakbot-technical ... is/103931/

Virus scanning is a slow background process. So it does not surprise me it finds infected dlls at intervals.

These could be false positives but it could be real as well. The infection itself could have happened quite a while ago and remained dormant and well hidden up until now.

Too bad you deleted the infected .dlls already. Otherwise you could compare them with known uninfected originals. If found completely equal, then either it is a false positive (perhaps a popular component of the Juce framework triggers it) or the virus is extremely good at hiding itself.
We are the KVR collective. Resistance is futile. You will be assimilated. Image
My MusicCalc is served over https!!

Post

BertKoor wrote: Tue Sep 12, 2023 10:04 am
kingozrecords wrote: Mon Sep 11, 2023 9:12 pm look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.

Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
What makes you think this is actually the culprit here? Wouldn't his anti-virus software have found that when present?

Throwing out random advice imho does not help anyone.
Exploitable windows components for data bankers that are un-necessary. I do my research. You're random Bert, lol. Go find Ernie or something. Powershell 2.0 is the old version and is not restricted by security. Linux subsystem can do most things without any detection, because it's a foreign process, not relating to any windows feature; regardless of operation.
I don't make audio products anymore. I sell furniture & smart products.

Post

@kingoz: You have disqualified yourself right here with a logical fallacy: argumentum ad hominem.

I could counter most of your arguments, but I'm not so sure it's worth the trouble.


The question here is whether this is a known false positive of Kaspersky. Then other users here might have had the same issue. So far none came forward.

Maybe the best action for OP is to contact Kaspersky. It's their scanner that found it after all. A scanner that cannot remove the malware it found is not worth paying for.

It might also be worth the trouble to search in the detailed logfiles of the virus scanner: has the checksum of so-called infected files changed over the years?
We are the KVR collective. Resistance is futile. You will be assimilated. Image
My MusicCalc is served over https!!

Post

BertKoor wrote: Tue Sep 12, 2023 5:41 pm @kingoz: You have disqualified yourself right here with a logical fallacy: argumentum ad hominem.

I could counter most of your arguments, but I'm not so sure it's worth the trouble.


The question here is whether this is a known false positive of Kaspersky. Then other users here might have had the same issue. So far none came forward.

Maybe the best action for OP is to contact Kaspersky. It's their scanner that found it after all. A scanner that cannot remove the malware it found is not worth paying for.

It might also be worth the trouble to search in the detailed logfiles of the virus scanner: has the checksum of so-called infected files changed over the years?
*nods
I don't make audio products anymore. I sell furniture & smart products.

Post

thx a lot guys, so i created live bootable isos from avira, avast, kaspersky and eset
eset found 2 files but i photographed it wrong... it was 2 files in windows folder but very different files. looked not important maybe false positive because before this avast didnt find anything. kaspersky also didnt find anything. only avira found something more, 1 java file, from bitwig installation, i think this is definitely false positive.

still i did remove these 3 files, then i restarted to windows 10 normally and updated kaspersky asap and disconnected my pc from the net. i let kaspersky fully rescan in win10 my pc, nothing found, this time over 1 hour nothing popped up as well. so maybe really a false positive after updating the database 1-2 days later.

still i felt unsure and i backed my drive up with acronis. then i recovered my old image (sadly from end of june i thought i had a newer one but i checked what i installed so far, only a few vsts + outlook via imap) so there shouldnt be a lot to update + my new bookmarks i saved.

on this recovered drive i started live cds - eset found no infected files (maybe these 2 windows files these were some temp or something files, nothing in system etc. ), avast didnt find anything too and kaspersky too only avira again the bitwig file. so i deleted it and will reinstall the newest version from bitwig.
then i also scanned with kaspersky in win 10 nothing found. so i think this partition is safe.

either these were false positives or it was really something fishy, so far since a day nothing happened from my june recovered disk. i dunno if i shall extend kaspersky or take a new scanner cause my license will be inactive in 5 days.

oh btw. malwarebytes didnt find anything before either, i didnt install it on my recovered disk as i am not very convinced of this app.
DAW FL Studio Audio Interface Focusrite Scarlett 1st Gen 2i2 CPU Intel i7-7700K 4.20 GHz, RAM 32 GB Dual-Channel DDR4 @2400MHz Corsair Vengeance. MB Asus Prime Z270-K, GPU Gainward 1070 GTX GS 8GB NT Be Quiet DP 550W OS Win10 64Bit

Post

:tu: :party:
We are the KVR collective. Resistance is futile. You will be assimilated. Image
My MusicCalc is served over https!!

Post Reply

Return to “Computer Setup and System Configuration”