C:\RECYCLER\S-1-5-18\$…\n is Rootkit ZeroAccess

Dmitry Sokolov recommends his nice removal tool: UnHackMe

UnHackMe quickly removes rootkits/malware/adware/browser hijack issues!

: Solved!
5 Stars (5 / 5)

Rootkit C:\RECYCLER\S-1-5-18\$…\n is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of C:\RECYCLER\S-1-5-18\$…\n may be a very difficult process.
You should use anti-rootkit software to fix the C:\RECYCLER\S-1-5-18\$…\n problem.

Malware Analysis of N
Full path on a computer: C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\n

Detected by UnHackMe:

Item Name: Rootkit: ZeroAccess 32/64.8
Author: Unknown
Related File:
Type: Devices in Memory

Item Name: Rootkit: ZeroAccess 32/64.7
Author: Unknown
Related File:
Type: Devices in Memory

Detected by RegRun Warrior:

Default location: C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\n

Removal Results: Success
Number of reboot: 1

N is known as:

ZeroAccess.gu, W32.PornoAsset.H, Trojan-Ransom.PornoAsset, Mal.Katusha-J, Trojan.Sirefef.BC, Win32:Sirefef-AJR , Win32.Sirefef.EV, W32.Birele.VEJ.tr, Cryptic.EGJ

N hash:

  • MD5: 2d992155600a72606af182512cee52c0
The file tries to connect to the dangerous web site.
How to quickly detect N presence? 

  • HKLM\Software\Classes\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InprocServer32\: “C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\n.”
  • C:\RECYCLER\S-1-5-21-1659004503-1708537768-1801674531-500\$b191330c415d588357c79de300728739
  • C:\RECYCLER\S-1-5-18
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\L
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\L\00000004.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\L\00000008.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\n
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U\00000004.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U\00000008.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U\000000cb.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U\80000000.@
  • C:\RECYCLER\S-1-5-18\$b191330c415d588357c79de300728739\U\80000032.@
  • %WinDir%\assembly\GAC\Desktop.ini

UnHackMe removes malware invisible for your antivirus!

Free Download

UnHackMe is compatible with most antivirus software.
UnHackMe is 100% CLEAN, which means it does not contain any form of malware, including adware, spyware, viruses, trojans and backdoors. VirusTotal (0/56).
System Requirements: Windows 2000-Windows 8.1. UnHackMe uses minimum of computer resources.


UnHackMe is a success where others have failed. We have used the software for sometime. Thank you for a great product, which actually works and we believe in the developers.

The UnHackMe is a real program, no spyware or phish and works great and is easy to use. Enjoy!

Leave a Reply