KillZA is a ZeroAccess Malware Removal/Repair Tool
Current Version: 2.0.1
NEWS: KillZA is dated and does not work on the latest variants. There are other tools out there like Bitdefender’s tool and another I’m not thinking of right now, and they seem to do a good job at both removal and repair. No reason to reinvent the wheel until the next time we have a new ZeroAccess variant and no tool to remove it easily.
NEWS: KillZA v2.x now performs Windows repairs after the removal is complete!!!
KillZA is a quick and dirty tool I wrote to remove the newer ZeroAccess (Sirefef) user mode variants, those that hide in a subdir of Windows, and some of the Recycle Bin variants.
Currently this is the Sirefef.P dropper with .X – .Z and other misc. payload, but may work for others. NOTE on 5/2013 that KillZA does not handle complete cleanup of the most current revisions of Zero Access, so your mileage may vary depending on the particular variant.. The actual repair process performed by KillZA still proves effective at the time of this writing.
The removal procedure takes care of the hidden files in your %temp% directory, anything found in %windir%Installer, anything found in a hidden dir within the Recycle Bin, as well as replacing a potentially infected services.exe file, and repairing infected registry entries.
SIDE EFFECT NOTE: On Vista/7, this utility will remove the current user’s Windows logon password, if set – don’t ask why it’s not important… Also when Windows has multiple user accounts, you must log in to the same user account where you first started KillZA from on all subsequent reboots, until the utility is finished.
This tool is NOT for earlier versions of ZA (the old rootkit versions that used an NTFS junction point to mask its files.)
These Youtube videos demonstrate the latest infection techniques and showcases removal with KillZA, and repair with D7. NOTE: These videos showcase v1.x of KillZA – where repair with D7 was required after removal – this is no longer the case as KillZA v2.x now performs the repairs!
Latest News
-
CryptoPrevent v23.5.5.0 just released! v23.5.3.0 Fixed an issue sending email with Office 365 SMTP...
Read More -
d7x v23.1.12 Release Notes Resolved an issue where DataGrab would backup everything except your...
Read More -
d7x v22.8.10 Release Notes Resolved an issue with the “Reset Networking” and “Repair Winsock”...
Read More -
d7x v22.8.9 Release Notes Resolved an issue with the “Set Time Zone” feature on...
Read More -
d7x and Tweaky – Set Time Zone issue with Windows 11 (UPDATED Aug 9th 2022) UPDATE: this issue has been resolved in d7x v22.8.9 and...
Read More -
d7x v22.2.23 Release Notes It appears that d7x was not applying hidden file and...
Read More -
d7x v22.1.16 and v22.1.17 Release Notes Added Microsoft OneDrive integration for d7x Reports storage (see the...
Read More -
d7x v22.1.15 Release Notes Added a user requested option to change the Info Report...
Read More -
d7x v22.1.14 Release Notes A new ‘d7x Release Notes (RSS)‘ window will display the...
Read More -
d7x v22.1.7 Release Notes Added new d7x feature to show system info on the...
Read More