80000000.@ is Rootkit ZeroAccess

Rootkit 80000000.@ is software that enables continued privileged access to a computer while actively hiding its presence.
Detection and removal of 80000000.@ may be a very difficult process.
You should use anti-rootkit software to fix the 80000000.@ problem.

Malware Analysis of 80000000.@
Full path on a computer: %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000000.@

Detected by RegRun Warrior:

80000000.@
Default location: %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000000.@

Removal Results: Success
Number of reboot: 1

80000000.@ is known as:

Rootkit.ZeroAccess, Trojan.Sirefef

80000000.@ hash:

  • MD5: 2ddce8374ef6f99a987acf620ed5c1d1
How to quickly detect 80000000.@ presence?

Registry:
  • HKLM\Software\Classes\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\: “\\.\globalroot\systemroot\Installer\{b191330c-415d-5883-57c7-9de300728739}\n.”
Files:
  • %Local Appdata%\{b191330c-415d-5883-57c7-9de300728739}\@
  • %Local Appdata%\{b191330c-415d-5883-57c7-9de300728739}\n
  • %WinDir%\assembly\GAC\Desktop.ini
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\L\00000004.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\n
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\00000004.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\00000008.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\000000cb.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000000.@
  • %WinDir%\Installer\{b191330c-415d-5883-57c7-9de300728739}\U\80000032.@

Fix it immediately!

Free Download

UnHackMe removes malware invisible for your antivirus!

Leave a Reply