ZeroAccess rootkit found by ShadowServer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Kimkama, Sep 26, 2013.

  1. Kimkama

    Kimkama Private E-2

    I got an email from the campus administrator that ShadowServer found ZeroAccess rootkit on my laptop.
    This is the message: (i've cut out the ip addresses)

    "timestamp","ip","port","asn","geo","region","city","hostname","type","infection","url","agent","cc","cc_port","cc_asn","cc_geo","cc_dns","count","proxy","application","p0f_genre","p0f_detail"
    > "2013-09-15
    > 20:00:09","(IP)",52001,1103,"NL","(city)","(city)",,"udp",
    > "ZeroAccess",,,"(ip cut out)",16465,22773,"US","ip(ip)",1,,,,,
    >
    > ---- end complaint ----

    I've ran all the required softwares but no rootkit was found. Is it possible that ShadowServer gave false alarm? Or is the virus hiding so well?

    I've attached all the logfiles required, except TDSSKiller, it didn't find any infected files.

    Thanks!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're getting a false positive.
     
  3. Kimkama

    Kimkama Private E-2

    Ok thanks.
    How did you know if I may ask?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It wasn't found in any of your logs. RogueKiller would have picked it up. Or it would have been found in the MGLogs.zip.

    And you are most welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds