View Single Post
  #12  
Old October 6th, 2011, 11:01 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
Hi EraserHW,
I'll try to get infected in my VM, then I'll see if I can run the tool.
My experience with zero access malware is varied. With some you have a little control, they can be neutralized. Others cannot, even in safe mode they manage to block all access to your PC.
The only solution is to use a bootable CD or restore the snapshot.

That said, I haven't read any documentation on this removal tool, which I will do now.
It was more or less, a question to myself "how is it possible"?

Thanks Eraser for your offer of help, I'll have a look at it sometime today and post my experience.

You're welcome

You'll find a lot of documentation about ZeroAccess rootkit in our blog:

http://www.prevxresearch.com/zeroaccess_analysis.pdf (which is going to be updated with last technical details as well)

http://blog.webroot.com/2011/08/08/t...e-of-the-same/

http://blog.webroot.com/2011/07/19/z...nother-update/

http://www.prevx.com/blog/171/ZeroAc...e-rootkit.html
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute