TDL3 and ZeroAccess: More of the Same?Description : We have also noted how the ZeroAccess rootkit acts very similar to the TDL3 rootkit, either by infecting a random system driver, using its own file system to store its plugins or by filtering the disk I/O by analysing the SCSI packets – though in a pretty different way.
Lien : http://blog.webroot.com/2011/08/08/tdl3-and-zeroaccess-more-of-the-same/