Trojan-Banker.Win32.Qbot.gen found -> recover system? Win10
-
- KVRAF
- 9693 posts since 5 Aug, 2009
hi guys, strange thing, i got no warez and ran today only youtube in firefox + outlook where no mail with attachment was received + in firefox i didnt download anything. suddenly kaspersky warned me 5 VST3 files are infected, strange, so i deleted them then 20 mins later 5 vst dlls... i shut down my pc and switched of my 2 external hdds + switched off my internetconnection (i downloaded and installed malwarebytes before shutting down). turned my pc on and scanned, nothing found with malwarebytes and kaspersky too first but then again 5 files found VST3 again... i dunno i mean does the virus spread 20-30 mins to 5 new files or is this some kaspersky false positives?
im not sure yet what to do, i did sadly my last image backup with acronis about 2 months ago, i didnt change much i think cause i work mostly with the 2 external hdds. so i thought maybe to recover this image or do you have any ideas? i had false positives in the past too but not like this behaviour
im not sure yet what to do, i did sadly my last image backup with acronis about 2 months ago, i didnt change much i think cause i work mostly with the 2 external hdds. so i thought maybe to recover this image or do you have any ideas? i had false positives in the past too but not like this behaviour
DAW FL Studio Audio Interface Focusrite Scarlett 1st Gen 2i2 CPU Intel i7-7700K 4.20 GHz, RAM 32 GB Dual-Channel DDR4 @2400MHz Corsair Vengeance. MB Asus Prime Z270-K, GPU Gainward 1070 GTX GS 8GB NT Be Quiet DP 550W OS Win10 64Bit
-
- KVRist
- 39 posts since 28 Jul, 2023
Is your machine connected to a network, either by WiFi or ethernet? If so disconnect then run the cleaners again and see if it comes back.
If it doesn't then there maybe another machine/device on the network that is infected and maybe trying to propagate itself to other devices.
If it does come back while disconnected then it implies you have something hooky on your device.
https://www.f-secure.com/v-descs/trojan ... nker.shtml
If it doesn't then there maybe another machine/device on the network that is infected and maybe trying to propagate itself to other devices.
If it does come back while disconnected then it implies you have something hooky on your device.
https://www.f-secure.com/v-descs/trojan ... nker.shtml
-
- KVRAF
- 3511 posts since 27 Dec, 2002 from North East England
You could try uploading one of the suspicious DLLs to a service like VirusTotal. It'll run your file through all the major virus/malware scanners and report back what they all found. It's not going to tell you definitively if something is or isn't infected, but knowing how widespread detection is can be helpful. A completely or near-unanimous result is obviously cause for worry, but if only 1 or 2 scanners detect an issue that could be grounds to suspect a false positive.
- KVRAF
- 7023 posts since 16 Aug, 2017 from UK
I'd try an offline scanner via USB and Rufus.
10 Free Bootable Antivirus Rescue Disks
https://www.thepcinsider.com/best-boota ... ks-windows
10 Free Bootable Antivirus Rescue Disks
https://www.thepcinsider.com/best-boota ... ks-windows
- KVRian
- 1314 posts since 7 Apr, 2019 from Canada
look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.
Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
find a file deleter program that can delete it.
Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
I don't make audio products anymore. I sell furniture & smart products.
- KVRAF
- 2376 posts since 23 Sep, 2004 from Kocmoc
Might just have been a false positive in the scanner, those happen.
Note I do not run any antiviruses on the machine anymore, only online scan few times a year.
Note I do not run any antiviruses on the machine anymore, only online scan few times a year.
Soft Knees - Live 12, Diva, Omnisphere, Slate Digital VSX, TDR, Kush Audio, U-He, PA, Valhalla, Fuse, Pulsar AUDIO, NI, OekSound etc. on Win11Pro R7950X & RME AiO Pro
https://www.youtube.com/@softknees/videos Music & Demoscene
https://www.youtube.com/@softknees/videos Music & Demoscene
- KVRAF
- 16873 posts since 8 Mar, 2005 from Utrecht, Holland
What makes you think this is actually the culprit here? Wouldn't his anti-virus software have found that when present?kingozrecords wrote: Mon Sep 11, 2023 9:12 pm look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.
Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
Throwing out random advice imho does not help anyone.
We are the KVR collective. Resistance is futile. You will be assimilated. 
My MusicCalc is served over https!!
My MusicCalc is served over https!!
- KVRian
- 1188 posts since 21 Aug, 2017 from Brasil
Use another PC(non infected) to create a bootable USB with some AV.
7 Free Bootable Antivirus Disks to Clean Malware From Your PC
https://www.makeuseof.com/tag/free-boot ... are-disks/
7 Free Bootable Antivirus Disks to Clean Malware From Your PC
https://www.makeuseof.com/tag/free-boot ... are-disks/
- KVRAF
- 16873 posts since 8 Mar, 2005 from Utrecht, Holland
This page should contain creditable info (from Kaspersky) about qbot/QakBot:
https://securelist.com/qakbot-technical ... is/103931/
Virus scanning is a slow background process. So it does not surprise me it finds infected dlls at intervals.
These could be false positives but it could be real as well. The infection itself could have happened quite a while ago and remained dormant and well hidden up until now.
Too bad you deleted the infected .dlls already. Otherwise you could compare them with known uninfected originals. If found completely equal, then either it is a false positive (perhaps a popular component of the Juce framework triggers it) or the virus is extremely good at hiding itself.
https://securelist.com/qakbot-technical ... is/103931/
Virus scanning is a slow background process. So it does not surprise me it finds infected dlls at intervals.
These could be false positives but it could be real as well. The infection itself could have happened quite a while ago and remained dormant and well hidden up until now.
Too bad you deleted the infected .dlls already. Otherwise you could compare them with known uninfected originals. If found completely equal, then either it is a false positive (perhaps a popular component of the Juce framework triggers it) or the virus is extremely good at hiding itself.
We are the KVR collective. Resistance is futile. You will be assimilated. 
My MusicCalc is served over https!!
My MusicCalc is served over https!!
- KVRian
- 1314 posts since 7 Apr, 2019 from Canada
Exploitable windows components for data bankers that are un-necessary. I do my research. You're random Bert, lol. Go find Ernie or something. Powershell 2.0 is the old version and is not restricted by security. Linux subsystem can do most things without any detection, because it's a foreign process, not relating to any windows feature; regardless of operation.BertKoor wrote: Tue Sep 12, 2023 10:04 amWhat makes you think this is actually the culprit here? Wouldn't his anti-virus software have found that when present?kingozrecords wrote: Mon Sep 11, 2023 9:12 pm look for winzip.exe C:\Program Files (x86)\MSBuild
find a file deleter program that can delete it.
Next in programs and features, go to windows components, make sure linux subsystem kernel, and powershell 2.0 are turned off; serious threats to your system. stick with 7-zip
Throwing out random advice imho does not help anyone.
I don't make audio products anymore. I sell furniture & smart products.
- KVRAF
- 16873 posts since 8 Mar, 2005 from Utrecht, Holland
@kingoz: You have disqualified yourself right here with a logical fallacy: argumentum ad hominem.
I could counter most of your arguments, but I'm not so sure it's worth the trouble.
The question here is whether this is a known false positive of Kaspersky. Then other users here might have had the same issue. So far none came forward.
Maybe the best action for OP is to contact Kaspersky. It's their scanner that found it after all. A scanner that cannot remove the malware it found is not worth paying for.
It might also be worth the trouble to search in the detailed logfiles of the virus scanner: has the checksum of so-called infected files changed over the years?
I could counter most of your arguments, but I'm not so sure it's worth the trouble.
The question here is whether this is a known false positive of Kaspersky. Then other users here might have had the same issue. So far none came forward.
Maybe the best action for OP is to contact Kaspersky. It's their scanner that found it after all. A scanner that cannot remove the malware it found is not worth paying for.
It might also be worth the trouble to search in the detailed logfiles of the virus scanner: has the checksum of so-called infected files changed over the years?
We are the KVR collective. Resistance is futile. You will be assimilated. 
My MusicCalc is served over https!!
My MusicCalc is served over https!!
- KVRian
- 1314 posts since 7 Apr, 2019 from Canada
*nodsBertKoor wrote: Tue Sep 12, 2023 5:41 pm @kingoz: You have disqualified yourself right here with a logical fallacy: argumentum ad hominem.
I could counter most of your arguments, but I'm not so sure it's worth the trouble.
The question here is whether this is a known false positive of Kaspersky. Then other users here might have had the same issue. So far none came forward.
Maybe the best action for OP is to contact Kaspersky. It's their scanner that found it after all. A scanner that cannot remove the malware it found is not worth paying for.
It might also be worth the trouble to search in the detailed logfiles of the virus scanner: has the checksum of so-called infected files changed over the years?
I don't make audio products anymore. I sell furniture & smart products.
-
- KVRAF
- Topic Starter
- 9693 posts since 5 Aug, 2009
thx a lot guys, so i created live bootable isos from avira, avast, kaspersky and eset
eset found 2 files but i photographed it wrong... it was 2 files in windows folder but very different files. looked not important maybe false positive because before this avast didnt find anything. kaspersky also didnt find anything. only avira found something more, 1 java file, from bitwig installation, i think this is definitely false positive.
still i did remove these 3 files, then i restarted to windows 10 normally and updated kaspersky asap and disconnected my pc from the net. i let kaspersky fully rescan in win10 my pc, nothing found, this time over 1 hour nothing popped up as well. so maybe really a false positive after updating the database 1-2 days later.
still i felt unsure and i backed my drive up with acronis. then i recovered my old image (sadly from end of june i thought i had a newer one but i checked what i installed so far, only a few vsts + outlook via imap) so there shouldnt be a lot to update + my new bookmarks i saved.
on this recovered drive i started live cds - eset found no infected files (maybe these 2 windows files these were some temp or something files, nothing in system etc. ), avast didnt find anything too and kaspersky too only avira again the bitwig file. so i deleted it and will reinstall the newest version from bitwig.
then i also scanned with kaspersky in win 10 nothing found. so i think this partition is safe.
either these were false positives or it was really something fishy, so far since a day nothing happened from my june recovered disk. i dunno if i shall extend kaspersky or take a new scanner cause my license will be inactive in 5 days.
oh btw. malwarebytes didnt find anything before either, i didnt install it on my recovered disk as i am not very convinced of this app.
eset found 2 files but i photographed it wrong... it was 2 files in windows folder but very different files. looked not important maybe false positive because before this avast didnt find anything. kaspersky also didnt find anything. only avira found something more, 1 java file, from bitwig installation, i think this is definitely false positive.
still i did remove these 3 files, then i restarted to windows 10 normally and updated kaspersky asap and disconnected my pc from the net. i let kaspersky fully rescan in win10 my pc, nothing found, this time over 1 hour nothing popped up as well. so maybe really a false positive after updating the database 1-2 days later.
still i felt unsure and i backed my drive up with acronis. then i recovered my old image (sadly from end of june i thought i had a newer one but i checked what i installed so far, only a few vsts + outlook via imap) so there shouldnt be a lot to update + my new bookmarks i saved.
on this recovered drive i started live cds - eset found no infected files (maybe these 2 windows files these were some temp or something files, nothing in system etc. ), avast didnt find anything too and kaspersky too only avira again the bitwig file. so i deleted it and will reinstall the newest version from bitwig.
then i also scanned with kaspersky in win 10 nothing found. so i think this partition is safe.
either these were false positives or it was really something fishy, so far since a day nothing happened from my june recovered disk. i dunno if i shall extend kaspersky or take a new scanner cause my license will be inactive in 5 days.
oh btw. malwarebytes didnt find anything before either, i didnt install it on my recovered disk as i am not very convinced of this app.
DAW FL Studio Audio Interface Focusrite Scarlett 1st Gen 2i2 CPU Intel i7-7700K 4.20 GHz, RAM 32 GB Dual-Channel DDR4 @2400MHz Corsair Vengeance. MB Asus Prime Z270-K, GPU Gainward 1070 GTX GS 8GB NT Be Quiet DP 550W OS Win10 64Bit
