Wilders Security Forums  

Go Back   Wilders Security Forums > Official Prevx Support Forum > Prevx Betas
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old October 3rd, 2011, 07:51 PM
Victek123's Avatar
Victek123 Victek123 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Location: USA
Posts: 2,722
Default WSA beta and zeroaccess rootkit

I've been hearing a lot recently about the zeroaccess rootkit and it's ability to disable security software in real-time. Has anyone tested WSA against zeroacces? Can it effectively prevent the rootkit from installing or remove it after the fact?
__________________
ut quod ego verus est maioribus quam ut quod est sanctus
  #2  
Old October 4th, 2011, 07:11 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by Victek123
I've been hearing a lot recently about the zeroaccess rootkit and it's ability to disable security software in real-time. Has anyone tested WSA against zeroacces? Can it effectively prevent the rootkit from installing or remove it after the fact?
No, it does no better than the other AV's.
Only today, WSA was crippled by Zero Access in my VM.
Once infected, you're history. It doesn't remove it after the fact.
  #3  
Old October 4th, 2011, 07:30 PM
hawki's Avatar
hawki hawki is offline
Frequent Poster
 
Join Date: Dec 2008
Posts: 468
Default Re: WSA beta and zeroaccess rootkit

http://blog.webroot.com/2011/08/03/n...ccess-goodbye/
  #4  
Old October 4th, 2011, 08:07 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by hawki
Good to see.
Only question I would have is how to use it if I have ZERO access
  #5  
Old October 4th, 2011, 10:44 PM
Victek123's Avatar
Victek123 Victek123 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Location: USA
Posts: 2,722
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
Good to see.
Only question I would have is how to use it if I have ZERO access

I haven't tried it myself, but I observed it being used in a video and apparently it will run in an infected system. Generally, if a removal tool will not run from the normal desktop you try SAFE mode, and if that doesn't work you boot from a "rescue disk" (CD/DVD) and run the tool from there. Many security venders offer a rescue disk as part of a complete security solution. For instance Symantec has the Norton Bootable Recovery Tool.
__________________
ut quod ego verus est maioribus quam ut quod est sanctus
  #6  
Old October 5th, 2011, 04:27 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
No, it does no better than the other AV's.
Only today, WSA was crippled by Zero Access in my VM.
Once infected, you're history. It doesn't remove it after the fact.

Could you send me the dropper you've used? We should protect against ZeroAccess without a problem but there are indeed many versions out so it's hard to say which you'd have seen.

Thanks!
  #7  
Old October 5th, 2011, 06:54 AM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by PrevxHelp
Could you send me the dropper you've used? We should protect against ZeroAccess without a problem but there are indeed many versions out so it's hard to say which you'd have seen.

Thanks!
I'll try to locate it for you Joe
Can you please let me know if I can submit a suspect file, via system tools to support.
I believe that this was not available during the Beta test phase.
  #8  
Old October 5th, 2011, 07:09 AM
PrevxHelp's Avatar
PrevxHelp PrevxHelp is offline
Prevx Moderator
 
Join Date: Sep 2008
Location: USA/UK
Posts: 7,584
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
I'll try to locate it for you Joe
Can you please let me know if I can submit a suspect file, via system tools to support.
I believe that this was not available during the Beta test phase.

It's probably worth sending it to me directly to report@prevxresearch.com so that I get it in hand.
  #9  
Old October 5th, 2011, 08:06 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
Good to see.
Only question I would have is how to use it if I have ZERO access

It's enough to run the tool and follow the instructions listed on the screen.

Do you need any help about how to use it?
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
  #10  
Old October 5th, 2011, 09:02 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by PrevxHelp
Could you send me the dropper you've used? We should protect against ZeroAccess without a problem but there are indeed many versions out so it's hard to say which you'd have seen.

Thanks!
I'm sorry Joe, I was unable to locate the file in question.
If/when I come across another I will send it to you.
  #11  
Old October 5th, 2011, 09:18 PM
overangry's Avatar
overangry overangry is offline
Frequent Poster
 
Join Date: Apr 2009
Posts: 309
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by EraserHW
It's enough to run the tool and follow the instructions listed on the screen.

Do you need any help about how to use it?
Hi EraserHW,
I'll try to get infected in my VM, then I'll see if I can run the tool.
My experience with zero access malware is varied. With some you have a little control, they can be neutralized. Others cannot, even in safe mode they manage to block all access to your PC.
The only solution is to use a bootable CD or restore the snapshot.

That said, I haven't read any documentation on this removal tool, which I will do now.
It was more or less, a question to myself "how is it possible"?

Thanks Eraser for your offer of help, I'll have a look at it sometime today and post my experience.
  #12  
Old October 6th, 2011, 11:01 AM
EraserHW's Avatar
EraserHW EraserHW is offline
Prevx Moderator
 
Join Date: Oct 2005
Location: Italy / UK
Posts: 584
Default Re: WSA beta and zeroaccess rootkit

Quote:
Originally Posted by overangry
Hi EraserHW,
I'll try to get infected in my VM, then I'll see if I can run the tool.
My experience with zero access malware is varied. With some you have a little control, they can be neutralized. Others cannot, even in safe mode they manage to block all access to your PC.
The only solution is to use a bootable CD or restore the snapshot.

That said, I haven't read any documentation on this removal tool, which I will do now.
It was more or less, a question to myself "how is it possible"?

Thanks Eraser for your offer of help, I'll have a look at it sometime today and post my experience.

You're welcome

You'll find a lot of documentation about ZeroAccess rootkit in our blog:

http://www.prevxresearch.com/zeroaccess_analysis.pdf (which is going to be updated with last technical details as well)

http://blog.webroot.com/2011/08/08/t...e-of-the-same/

http://blog.webroot.com/2011/07/19/z...nother-update/

http://www.prevx.com/blog/171/ZeroAc...e-rootkit.html
__________________
Before you criticize someone, you should walk a mile in their shoes. That way when you criticize them, you are a mile away from them and you have their shoes
Check your PC in about a minute
 

Wilders Security Forums > Official Prevx Support Forum > Prevx Betas « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:22 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums