05-20-2012 06:49 PM
Just a Note,
Some variants of Zeroaccess can or will shut down Norton and other security products or Stop scans from occuring /won't start.
Quads
05-20-2012 07:18 PM
Quads wrote:Just a Note,
Some variants of Zeroaccess can or will shut down Norton and other security products or Stop scans from occuring /won't start.
Quads
Sure hope you can dig us out of this one - I'd be totally lost
05-20-2012 07:32 PM
Zeroaccess is not that hard you just have to track down which variant, and where the objects are, also is there anything else that came along with it.
It's harder id it's a Combo infection, say zeroaccess + Pihar + FakeAV's + other malware, you just have to figure out which to break first as tools to scan looking for the rootkit / bootkit may not work or work properly as the FakeAV or other malware over the top may be trying to block it.
Have these tools malfunction during their scans may cause a bigger hole to deal with.
Quads
05-20-2012 08:12 PM
Quads wrote:Zeroaccess is not that hard you just have to track down which variant, and where the objects are, also is there anything else that came along with it.
It's harder id it's a Combo infection, say zeroaccess + Pihar + FakeAV's + other malware, you just have to figure out which to break first as tools to scan looking for the rootkit / bootkit may not work or work properly as the FakeAV or other malware over the top may be trying to block it.
Have these tools malfunction during their scans may cause a bigger hole to deal with.
Quads
Thanks for the short lesson.
When I get in trouble I'll come calling. You have convinced me with your posts that I'd be way out of my knowledge zone trying to play with any of this stuff.
Thank you for being here and even more so thank you for all of your time and expertise helping all of us.
If there's anything I can do for you, ask, I'll try
06-10-2012 07:41 PM
The services.exe I directly sent SSR (Symantec) is now detected as Trojan.Patchep!sys, Dormant state at least, although now the Writeup is out of date haha.
Quads
06-11-2012 05:00 AM
Quads wrote:The services.exe I directly sent SSR (Symantec) is now detected as Trojan.Patchep!sys, Dormant state at least, although now the Writeup is out of date haha.
Quads
Quads,
Isn't that about normal? About the time you get it written/published it's out of date. Got to love the speed at which things change these days - not!![]()
The older I get and the harder I try the behinder I get. Makes life interesting.![]()
Again, thanks for all of your hard work and dedication to helping others. ![]()
06-11-2012 08:33 PM - edited 06-11-2012 08:36 PM
I will not use NPE on the new mods and variants from MaxSS, pihar, Zeroaccess as it can't handle it + the subsystems.
New variants are CLSID's 2 locations with desktop.ini and services.exe
NPE with the ever changing zeroaccess sucks it can't handle it and causes with the other family mods Windows to not boot after, freeze, NPE freezes / locks let alone you have to do a system restart first before even scanning.
I have had to get around NPE on my own system from the screw ups or lock ups.
No way will I ask a user to use it if a rootkit is suspected.
Do a proper job and log and target what is found, Malware removalists do.
Another zeroaccess services.exe MD5 I have https://www.virustotal.com/file/e647717985bf0a1c6b
Quads
06-12-2012 05:15 AM
Quads,
Again, thank you for keeping us informed but even moreso for helping us out of the holes we dig for ourselves.
06-12-2012 06:18 PM
I gave Symantec over 2MB (compressed) of the CLSID variant zeroaccess, They asked me. The payload is now started being detected as Trojan.Zeroaccess instead of Trojan.Gen.2
Quads
06-14-2012 10:51 PM
hahaha the log attached shows I give my system kittens on what I do to it
Quads
