Rootkit ZeroAccess – mdmdes.dll – 465fbdbcb88656bf2d1751015656e884

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Rootkit ZeroAccess
Also known as: Trojan Generic, Trojan Barys
SHA256: ff9445611fb89659edca59e74c0d54a2099e0b385fac1b70fe99d598fd362378
SHA1: 509a4482f8aa5e7604f57531bafb5e4f6c3d8a28
MD5: 465fbdbcb88656bf2d1751015656e884
File size: 413184 bytes

Created files:

%AppData%\mdmdes.dll – Rootkit ZeroAccess
%Temp%\IXP000.TMP\C32938~1.EXE – Rootkit ZeroAccess
%Temp%\IXP000.TMP\THETA.exe – Rootkit ZeroAccess

Rootkit ZeroAccess created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0: rundll32.exe %WinDir%\System32\advpack.dll,DelNodeRunDLL32 “%Temp%\IXP000.TMP\”

Leave a Reply