ZeroAccess, a kernel-mode rootkit, recently shifted its infection technique from kernel mode to user mode. (For more on ZeroAccess, which turns infected systems into a peer-to-peer botnet, read these posts from my colleagues Peter Szor and Aditya Kapoor.) Even in user mode, ZeroAccess can maintain its presence on an infected system. ZeroAccess implements what I Read more…
Tags: botnet, kernel mode, rootkit, user mode, ZeroAccess
Posts tagged under kernel mode