|
In the past few days we have seen an increase of customer being infected by a new virus on Windows machines.
Symptoms of this new virus are,
- slower PC
- google searches not going to the intended web sites
- virus scanners finding viruses but not removing them
- virus scanner no longer working
- in some cases the Internet not working at all
The virus is part of the ZeroAccess is a family of Rootkits, capable of infecting the Windows Operating System. On infection, it replaces Windows System Files and installs Kernel Hooks in an attempt to remain stealthy. Once the hooks are installed, the target operating system falls under control of the rootkit, which is then able to hide processes, files, networks connections, as well as to kill any security tools trying to access its files or processes. This rootkit is known to infect both 32 and 64 bit Windows operating systems. ZeroAccess also patches system files to load its malicious code. The original file name is then kept inside an encrypted virtual file system the rootkit creates. The virtual file system is stored in a file on disk.
Aliases Microsoft: TrojanDropper:Win32/Sirefef.B Kaspersky: Trojan-Dropper.Win32.ZAccess, Backdoor.Win32.ZAccess Norman: W32/ZAccess.F, W32/Zbot.WTG Symantec: Trojan.Zeroaccess Sophos: Troj/ZAccess-F, Mal/Zbot-CX F-Secure: Gen:Variant.Kazy.28752, Trojan.Generic.KD.348130
Infection Methods ZeroAccess is usually installed by a dropper component that may come to the machine from different sources. Email attachments (EXE, ZIP, RAR) Flash exploits Downloading crack files
Please also be aware these people that make these viruses, will hide their viruses in fake music and tv show files. These would normally be down on P2P software programs like Bearshare. We strongly recommend avoiding these programs.
Removal of Infection Unfortunately there is no easy way to remove this virus. Once infected it takes over serveral important files on your system and prevents it's self from being removed. The hard drive needs to be removed from your computer and scanned with another computer. Then the virus need to be manual removed to prevent reinfection.
If you do find you have this virus. Please give us a call. We are able to remove this virus without needing to do a clean load over your computer. Keeping all your files and program safe.
Phone 1300 87 23 28
|