- Local time
- 11:54 AM
- Messages
- 156
For those lurking, or anyone who is interested in the details about Sirefef/ZeroAccess: http://www.kindsight.net/sites/default/files/Kindsight_Malware_Analysis-ZeroAcess-Botnet-final.pdf
http://www.2-viruses.com/remove-zeroaccess-rootkit
I believe that I had the older variant of Sirefef-- .Y, .W, .B
There are new variants out by now-- .AG, .I, .P (which I believe is also called the CLSID variant) Major shift in strategy for ZeroAccess rootkit malware, as it shifts to user-mode | Naked Security
Since I'm really interested in hacking and viruses, I'm actually having some fun trying to fight it. I'm not ready to reinstall Windows just yet. It's important that I learn what this is and what it does. I want to do everything I can before I wipe the whole thing. It's a learning process. Some of my most important files are already backed up here on my laptop, such as novels I'm writing.
I also hope the information will aid others in learning about the virus. I'll keep reporting back here with updates on how far I've gotten. Right now, I have to focus on fixing Services.exe. ESET has a ServicesRepair tool that I'm going to see if I can quickly use in safe mode before the system shuts down. If not that, then I'm going to try to get my AHCI drivers onto a flash drive so that I can access my OS when repairing my computer so I can do an SFC scannow.
I'm not giving up just yet.
This is a guide I was going to follow: http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
Here's a video about it as well, and from what I can see, the virus can impact a system far worse than how it hit mine. I can at least boot into Windows. http://www.youtube.com/watch?v=xVtGvtlDPwo&feature=related
(This reminds me a lot of the Conficker scare back in, I think 2010?)
http://www.2-viruses.com/remove-zeroaccess-rootkit
I believe that I had the older variant of Sirefef-- .Y, .W, .B
There are new variants out by now-- .AG, .I, .P (which I believe is also called the CLSID variant) Major shift in strategy for ZeroAccess rootkit malware, as it shifts to user-mode | Naked Security
Since I'm really interested in hacking and viruses, I'm actually having some fun trying to fight it. I'm not ready to reinstall Windows just yet. It's important that I learn what this is and what it does. I want to do everything I can before I wipe the whole thing. It's a learning process. Some of my most important files are already backed up here on my laptop, such as novels I'm writing.
I also hope the information will aid others in learning about the virus. I'll keep reporting back here with updates on how far I've gotten. Right now, I have to focus on fixing Services.exe. ESET has a ServicesRepair tool that I'm going to see if I can quickly use in safe mode before the system shuts down. If not that, then I'm going to try to get my AHCI drivers onto a flash drive so that I can access my OS when repairing my computer so I can do an SFC scannow.
I'm not giving up just yet.
This is a guide I was going to follow: http://malwaretips.com/Thread-How-to-completely-remove-ZeroAccess-Sirefef-rootkit-Removal-Guide
Here's a video about it as well, and from what I can see, the virus can impact a system far worse than how it hit mine. I can at least boot into Windows. http://www.youtube.com/watch?v=xVtGvtlDPwo&feature=related
(This reminds me a lot of the Conficker scare back in, I think 2010?)
Last edited:
My Computer
At a glance
Windows 7 64-Bit Home Premium Service Pack 1AMD Phenom II Black x4G. Skill Ripjaws Gaming series DDR3 2 x2GBSapphire ATI Radeon HD 5770 PCIe
- OS
- Windows 7 64-Bit Home Premium Service Pack 1
- CPU
- AMD Phenom II Black x4
- Motherboard
- Asus M4A89TD Pro USB3
- Memory
- G. Skill Ripjaws Gaming series DDR3 2 x2GB
- Graphics Card(s)
- Sapphire ATI Radeon HD 5770 PCIe
- Hard Drives
- Western Digital Caviar Blue 500gb SATA 6.0
- PSU
- Corsair HX 650w
- Case
- Cooler Master CM690 II Advanced