15.11.2011, 23:30
Tutaj opisałem jak sprawuje się nowa wersja vs ZeroAccess:
Dodano: 15 lis 2011, 23:30
Dla tych, którzy nie posiadają konta.
[Aby zobaczyć linki, zarejestruj się tutaj]
Dodano: 15 lis 2011, 23:30
Cytat: Ok, I have just tested CCE vs ZeroAccess.
I grabbed a sample and run it. Then i tried to run KillSwitch but ZeroAccess prevented it from running and made it unable to run permanently.
I run CCE - it went just fine - it did a scan - it detected malicious process of rootkit.
See picture:
[img width=640 height=312][Aby zobaczyć linki, zarejestruj się tutaj]
[/img]
Applause for CCE for not being terminated and destroyed by ZeroAccess during scanning. 0l
I hit Clean and restarted the system.
After restart I didn''t see any trace of ZeroAccess anymore: :-TU :-TU
See image
[img width=640 height=426][Aby zobaczyć linki, zarejestruj się tutaj]
[/img]
But there are few problems:
1. KillSwitch is still vulnerable.
2. After restart I checked the folder andCCE.exe get modified as well(fortunately it deleted the rootkit and then dead )
[img width=601 height=480][Aby zobaczyć linki, zarejestruj się tutaj]
[/img]
Another problem : Aggressive mode cannot still terminate some FakeAVs - I guess it''s because they don;t terminate running processes - they stop them from running.
I know that command prompt can run just fine under these fakeAVs, mabye that is the key (somehow use that method).
I have this sample of Rootkit and FakeAV as well, so if you want them just tell me.
Dla tych, którzy nie posiadają konta.
[Aby zobaczyć linki, zarejestruj się tutaj]