The ZeroAccess malware family has pushed out another update to ensure reboot persistence. The new ZeroAccess dropper copies itself to two locations: in the %Program Files% folder, and in the users local AppData area. Each copy is placed in a folder that looks as though it is part of a Google product, using non-printable Unicode characters that make it hard to spot on some versions of Windows. The malware connects to the same peer-peeer network as described in this technical paper, and is currently downloading that that is currently downloaded that fraud fraud fraud is under way.”]

