ZeroAccess Rootkit Launched by Signed Installers
http://blogs.mcafee.com/mcafee-labs/zer ... installers
http://blogs.mcafee.com/mcafee-labs/zer ... installers
A forum for reverse engineering, OS internals and malware analysis
rkhunter wrote:ZeroAccess Rootkit Launched by Signed InstallersAnybody got a sample? I would like to investigate the certificate. Thanks.
http://blogs.mcafee.com/mcafee-labs/zer ... installers
markusg wrote:are you sure the exe file is a malware, when i delete dll file from folder the exe file is in it only starts flash player so i think the adobe installer is clean or im wrong?It is msimg32.dll that gets loaded by the genuine official Flash Player Installer. The whole certificate thing, as McAfee wrote, plays NO ROLE.