Security-X
Forum Security-X => News => Discussion démarrée par: chantal11 le juin 25, 2012, 12:23:04
-
ZeroAccess – From Rootkit to Nasty Infection
One year ago we’ve blogged about ZeroAccess striking back at antivirus products by means of malicious payload injection causing the antivirus products to terminate. ZeroAccess is known for causing browser redirects causing additional malware infections.
ZeroAccess (also known as Sirefef, Maxplus or Smiscer) changed its way of working a few times and recently it evolved from a rootkit into a user mode virus. This makes sense because it used to use different strategies on 32-bit and 64-bit computers. On 32-bit Windows ZeroAccess infected a random kernel driver and on 64-bit it used an altered Session Manager\SubSystems registry key to survive reboots.
Merging both 32 and 64-bit versions the authors now have a common code base for both architectures which is easier to maintain and improve.
Services.exe infection
http://hitmanpro.wordpress.com/2012/06/25/zeroaccess-from-rootkit-to-nasty-infection/