Rootkit ZeroAccess – b2c471ad35c2a906d1a62e68b419c672

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

Rootkit ZeroAccess
Also known as: Trojan Jorik
SHA256: 197cbb7a3c033afa7f4a98e5d60cfc0ab0e0221dc55737054baf514daa380ce3
SHA1: 2aeb8a81bde6fb81ea840c64aef9c9f13173c44c
MD5: b2c471ad35c2a906d1a62e68b419c672
File size: 414208 bytes

Created files:

%AppData%\wehupr.dll – Rootkit ZeroAccess
%Temp%\IXP000.TMP\C32938~1.EXE – Rootkit ZeroAccess
%Temp%\IXP000.TMP\youtube.exe – Rootkit ZeroAccess

Rootkit ZeroAccess created autostart registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\wehupr: rundll32.exe “%AppData%\wehupr.dll”,ReplaceCharsW

Leave a Reply