800000C0.@ is Trojan Small.32768.AZK

Rootkit 800000C0.@ is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of 800000C0.@ may be a very difficult process.
You should use anti-rootkit software to fix the 800000C0.@ problem.

Malware Analysis of 800000C0.@
Full path on a computer: %Local Appdata%3308c706U800000c0.@

Detected by RegRun Warrior:

800000C0.@
Default location: %Local Appdata%3308c706U800000c0.@

Removal Results: Success
Number of reboot: 1

800000C0.@ is known as:

Trojan.Small.32768.AZK, Trojan.zaccess.AA5, ZeroAccess, Trojan.PMax.x, RootKit, Rootkit.PMax.WoGLq6ObhwY, Win32.Sirefef.EN, W32.Trojan2.NQCO, W32.ZAccess.G, Win32:Sirefef-PL [Rtk], Rootkit.PMax.x, Trojan.Sirefef.CR, Trojan.Agent.Gen-Sirefef, TR.Offend.kdv.488489, Sus.Dropper-A, Win32.ZAccess.BI, Rootkit.PMax.o, TrojanDropper.Sirefef.N, Win-Trojan.Sirefef.32768, W32.PMax.X.tr.rkit, Bck.Cycbot.F

800000C0.@ hash:

  • MD5: 273a41f7c65a03f5309defbdf760d71c
How to quickly detect 800000C0.@ presence?

Registry:
  • HKLMSystemCurrentControlSetServicesse59nd5ParametersServiceDll: “%systemroot%system32CTSBLFX.DLL.dll”
Folders:
  • %WinDir%$NtUninstallKB3057$
Files:
  • %Local Appdata%3308c706@
  • %Local Appdata%3308c706U0000001.@
  • %Local Appdata%3308c706U00000c0.@
  • %Local Appdata%3308c706U00000cb.@
  • %Local Appdata%3308c706U00000cf.@
  • %Local Appdata%3308c706U80000000.@
  • %Local Appdata%3308c706U800000c0.@
  • %Local Appdata%3308c706U800000cb.@
  • %Local Appdata%3308c706U800000cf.@
  • %Local Appdata%3308c706X
  • %WinDir%assemblyGAC_MSILDesktop.ini
  • %SysDir%CTSBLFX.DLL.dll
  • %SysDir%dds_log_ad13.cmd

Fix it immediately!

Free Download

UnHackMe removes malware invisible for your antivirus!

Leave a Reply