<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: ZeroAccess Rootkit Guards Itself with a Tripwire</title>
	<atom:link href="http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/</link>
	<description>WEBROOT - INSIGHTS INTO THREATS AND TRENDS FROM OUR INTERNET SECURITY EXPERTS</description>
	<lastBuildDate>Fri, 17 May 2013 20:44:03 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: charly</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-58917</link>
		<dc:creator><![CDATA[charly]]></dc:creator>
		<pubDate>Wed, 04 Jul 2012 17:06:52 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-58917</guid>
		<description><![CDATA[is there a way to decode the @-files to know which domains are in those?]]></description>
		<content:encoded><![CDATA[<p>is there a way to decode the @-files to know which domains are in those?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-45631</link>
		<dc:creator><![CDATA[James]]></dc:creator>
		<pubDate>Sun, 15 Apr 2012 13:16:14 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-45631</guid>
		<description><![CDATA[the removal tool that you have found the item but also became more agressive when I used it to remove and reboot the computer. I may need an update the removal program]]></description>
		<content:encoded><![CDATA[<p>the removal tool that you have found the item but also became more agressive when I used it to remove and reboot the computer. I may need an update the removal program</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Windows rootkit developer battle proves there&#8217;s no honor among thieves &#124; MyCE &#8211; My Consumer Electronics</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-16155</link>
		<dc:creator><![CDATA[Windows rootkit developer battle proves there&#8217;s no honor among thieves &#124; MyCE &#8211; My Consumer Electronics]]></dc:creator>
		<pubDate>Thu, 11 Aug 2011 16:36:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-16155</guid>
		<description><![CDATA[[...] Blog has previously covered the pitfalls of ZeroAccess. One variant of the rootkit can effectively render anti-virus software useless via a &#8220;virtual tripwire.&#8221; While deleting TDL is a pleasant side effect, it&#8217;s [...]]]></description>
		<content:encoded><![CDATA[<p>[...] Blog has previously covered the pitfalls of ZeroAccess. One variant of the rootkit can effectively render anti-virus software useless via a &#8220;virtual tripwire.&#8221; While deleting TDL is a pleasant side effect, it&#8217;s [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: quartzie</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-16098</link>
		<dc:creator><![CDATA[quartzie]]></dc:creator>
		<pubDate>Wed, 10 Aug 2011 12:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-16098</guid>
		<description><![CDATA[Gerald, you can check whether your antivirus software is running - if it closes the moment you run a process scan, bingo.

(You can also check the permissions of the AV executable, they will be set to deny execution)]]></description>
		<content:encoded><![CDATA[<p>Gerald, you can check whether your antivirus software is running &#8211; if it closes the moment you run a process scan, bingo.</p>
<p>(You can also check the permissions of the AV executable, they will be set to deny execution)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brooke</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-16069</link>
		<dc:creator><![CDATA[Brooke]]></dc:creator>
		<pubDate>Tue, 09 Aug 2011 23:26:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-16069</guid>
		<description><![CDATA[Gerald, from experience (I&#039;m dealing with it now!), I can tell you that you&#039;ll see the following symptoms if you&#039;re infected:  (a) every link you click in Google search results will take you to some stupid, junky ad site; and (b) you won&#039;t be able to run any anti-virus software (MalwareBytes Anti-Malware, SuperAntiSpyware, Spybot Search &amp; Destroy, Webroot, etc.).

Actually, my Webroot user interface is up and running, but I can&#039;t run a manual scan and I can&#039;t configure any settings -- everything is greyed out.  ARGH!!!  A volunteer from the bleepingcomputer.com forum is helping me, but it has taken several days so far...

One of Marco Giuliani&#039;s more recent posts mentions a ZeroAccess detection and removal kit; I need to look into that:  &quot;...you can download our ZeroAccess removal tool and check if your system is already infected by the ZeroAccess rootkit. Our free removal tool will be able to detect whether the system is infected and, if so, it’ll clean the system for you.&quot;  http://anywhere.webrootcloudav.com/antizeroaccess.exe]]></description>
		<content:encoded><![CDATA[<p>Gerald, from experience (I&#8217;m dealing with it now!), I can tell you that you&#8217;ll see the following symptoms if you&#8217;re infected:  (a) every link you click in Google search results will take you to some stupid, junky ad site; and (b) you won&#8217;t be able to run any anti-virus software (MalwareBytes Anti-Malware, SuperAntiSpyware, Spybot Search &amp; Destroy, Webroot, etc.).</p>
<p>Actually, my Webroot user interface is up and running, but I can&#8217;t run a manual scan and I can&#8217;t configure any settings &#8212; everything is greyed out.  ARGH!!!  A volunteer from the bleepingcomputer.com forum is helping me, but it has taken several days so far&#8230;</p>
<p>One of Marco Giuliani&#8217;s more recent posts mentions a ZeroAccess detection and removal kit; I need to look into that:  &#8220;&#8230;you can download our ZeroAccess removal tool and check if your system is already infected by the ZeroAccess rootkit. Our free removal tool will be able to detect whether the system is infected and, if so, it’ll clean the system for you.&#8221;  <a href="http://anywhere.webrootcloudav.com/antizeroaccess.exe" rel="nofollow">http://anywhere.webrootcloudav.com/antizeroaccess.exe</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gerald D Cranford</title>
		<link>http://blog.webroot.com/2011/07/08/zeroaccess-rootkit-guards-itself-with-a-tripwire/#comment-14642</link>
		<dc:creator><![CDATA[Gerald D Cranford]]></dc:creator>
		<pubDate>Sat, 09 Jul 2011 03:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.webroot.com/?p=4657#comment-14642</guid>
		<description><![CDATA[how do I know if my computer is infected. Thanks you guys do a great job!]]></description>
		<content:encoded><![CDATA[<p>how do I know if my computer is infected. Thanks you guys do a great job!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
