[RP]: Extracting ZeroAccess from NTFS Extended Attributes gebhard 2012-12-12 Uncategorized Forensics, Malware Analysis just a quick link: Extracting ZeroAccess from NTFS Extended Attributes