Many systems with security features disabled

I just took this variant of ZeroAccess off a laptop yesterday. Combofix handled the final clean-up nicely.
 
I just took this variant of ZeroAccess off a laptop yesterday. Combofix handled the final clean-up nicely.

Which variant? Are you saying you used Combofix to cleanup after you removed the meat of the infection? I'll agree to that, Combofix is great albeit as slow as watching grass grow... but it also can't run when Windows is shutting down :P
 
Just updated D7 and my latest removal tool for this variant to tackle the systems with an infected SERVICES.EXE file (which, if active A/V on the system detects this will attempt to remove it and subsequently windows will get stuck in a reboot loop.)
 
Last edited:
Back
Top