n – Rootkit ZeroAccess

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Download UnHackMe
Fully Functional 30-day Trial. No credit card is required. Reviews. EULA. Privacy Policy.

n – Rootkit ZeroAccess removal

File Virus Alias
n Rootkit ZeroAccess
n Trojan Crypt

Created files:

C:\RECYCLER\S-1-5-21-515967899-854245398-1708537768-1003\$ae229ccd6a28e4e88a473737ee4e0fed\@ – Rootkit ZeroAccess
C:\RECYCLER\S-1-5-21-515967899-854245398-1708537768-1003\$ae229ccd6a28e4e88a473737ee4e0fed\n – Rootkit ZeroAccess

Autostart registry keys:

HKCU\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32\ThreadingModel: Both
HKCU\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 : C:\RECYCLER\S-1-5-21-515967899-854245398-1708537768-1003\$ae229ccd6a28e4e88a473737ee4e0fed\n.

Detected by UnHackMe:

n
Default location: C:\RECYCLER\S-1-5-21-515967899-854245398-1708537768-1003\$ae229ccd6a28e4e88a473737ee4e0fed\n

Dropper information:
SHA256: 2990294ca803e6a4287ae47872a632af83c71938db2a6c5ccf2c9f46c2b452ec
SHA1: 58e87db23f4600d2de4de71142ab9c825e1e09ee
MD5: 2f0235ca06ea0393bdca296f6c246167
File size: 160768 bytes

Leave a Reply