000000CB.@ is Rootkit.ZeroAccess

June 1, 2012 by NightWatcher
Filed under: Rootkit 
: Solved!

Fix it immediately:

Rootkit 000000CB.@ is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of 000000CB.@ may be a very difficult process.
You should use anti-rootkit software to fix the 000000CB.@ problem.

Malware Analysis of 000000CB.@
Full path on a computer: %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\000000cb.@

Detected by RegRun Warrior:

000000CB.@
Default location: %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\000000cb.@

Removal Results: Success
Number of reboot: 1

000000CB.@ is known as:

Rootkit.ZeroAccess, Trojan.Sirefef

000000CB.@ hash:

  • MD5: f2b2477ca78d7fb19e7491220f3a7981
How to quickly detect 000000CB.@ presence?

Registry:
  • HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\: “\\.\globalroot\systemroot\Installer\{b191330c-415d-5883-57c7-9de300728739}\n.”
Files:
  • %Local Appdata%\{b191330c-415d-5883-57c7-9de300728739}\@
  • %Local Appdata%\{b191330c-415d-5883-57c7-9de300728739}\n
  • %WinDir%\assembly\GAC\Desktop.ini
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\L\00000004.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\n
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\00000004.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\00000008.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\000000cb.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000000.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000032.@


Recommended: UnHackMe anti-rootkit and anti-malware

Premium software: RegRun Security Suite (Good choice for removal and protection)

Written by

Malware Hunter.

Comments

Tell me what you're thinking...
and oh, if you want a pic to show with your comment, go get a gravatar!

You must be logged in to post a comment.