The attack worked, the password is cmF0dGEK
This was obtained by generating 32 possible plaintexts for the first 10 bytes of system.zip (based on the different values in the headers of ~300 zip files on my system), plus three null bytes for the high bytes of compressed size, file name length and extra field length.
You can also run VirtualBox with KVM as a backend.