Registry: HKLM\System\CurrentControlSet\Services\se59nd5\Parameters\ServiceDll: "%systemroot%\system32\CTSBLFX.DLL.dll" >
Folders:
%WinDir%\$NtUninstallKB3057$ >
Files:
%Local Appdata%\3308c706\@ %Local Appdata%\3308c706\U\00000001.@ %Local Appdata%\3308c706\U\000000c0.@ %Local Appdata%\3308c706\U\000000cb.@ %Local Appdata%\3308c706\U\000000cf.@ %Local Appdata%\3308c706\U\80000000.@ %Local Appdata%\3308c706\U\800000c0.@ %Local Appdata%\3308c706\U\800000cb.@ %Local Appdata%\3308c706\U\800000cf.@ %Local Appdata%\3308c706\X %WinDir%\assembly\GAC_MSIL\Desktop.ini %SysDir%\CTSBLFX.DLL.dll %SysDir%\dds_log_ad13.cmd > v> end --> ">

000000C0.@ - Dangerous

%LOCAL APPDATA%\3308C706\U\000000C0.@

Manual removal instructions:

Antivirus Report of %LOCAL APPDATA%\3308C706\U\000000C0.@:
%LOCAL APPDATA%\3308C706\U\000000C0.@ Trojan.Small.45968, Trojan.Sirefef.PS4, W32.Sirefef.f, Trojan.Sirefef.cr, EmailWorm, a variant of Win32.Sirefef.CR, Trojan.Zeroaccess, W32.ZAccess.G, Win32:Alureon-AJI [Rtk], TRSirefef.P, Trojan.Rootkit-3105, Backdoor.ZAccess.aqo, Backdoor.Smadow, Trojan.Sirefef.AN, Trojan.Inject.53003, Trojan.Sirefef.cr (v), Troj.Luiha-T, Win32.Smadow.P, Rootkit.ZAccess.cj, Trojan.Sirefef.P, Trojan.ZAccess.45968, Trojan.ZAccess, W32.TDSSPack.A.tr, Dropper.Agent.ARQJ.
%LOCAL APPDATA%\3308C706\U\000000C0.@Dangerous
%LOCAL APPDATA%\3308C706\U\000000C0.@High Risk
%local appdata%\3308c706\u\000000c0.@
We suggest you to remove 00000001.@ from your computer as soon as possible.
00000001.@ is known as: Trojan.Small.45968, Trojan.Sirefef.PS4, W32.Sirefef.f, Trojan.Sirefef.cr, EmailWorm, a variant of Win32.Sirefef.CR, Trojan.Zeroaccess, W32.ZAccess.G, Win32:Alureon-AJI [Rtk], TRSirefef.P, Trojan.Rootkit-3105, Backdoor.ZAccess.aqo, Backdoor.Smadow, Trojan.Sirefef.AN, Trojan.Inject.53003, Trojan.Sirefef.cr (v), Troj.Luiha-T, Win32.Smadow.P, Rootkit.ZAccess.cj, Trojan.Sirefef.P, Trojan.ZAccess.45968, Trojan.ZAccess, W32.TDSSPack.A.tr, Dropper.Agent.ARQJ.
MD5 of 00000001.@ = 59cc0151f048eff85b5f67824916567e
00000001.@ size is 45968 bytes.
Full path on a computer: %LOCAL APPDATA%\3308C706\U\000000C0.@
Related Files:
Registry:


HKLM\System\CurrentControlSet\Services\se59nd5\Parameters\ServiceDll: "%systemroot%\system32\CTSBLFX.DLL.dll"
>
Folders:


%WinDir%\$NtUninstallKB3057$
>
Files:


%Local Appdata%\3308c706\@
%Local Appdata%\3308c706\U\00000001.@
%Local Appdata%\3308c706\U\000000c0.@
%Local Appdata%\3308c706\U\000000cb.@
%Local Appdata%\3308c706\U\000000cf.@
%Local Appdata%\3308c706\U\80000000.@
%Local Appdata%\3308c706\U\800000c0.@
%Local Appdata%\3308c706\U\800000cb.@
%Local Appdata%\3308c706\U\800000cf.@
%Local Appdata%\3308c706\X
%WinDir%\assembly\GAC_MSIL\Desktop.ini
%SysDir%\CTSBLFX.DLL.dll
%SysDir%\dds_log_ad13.cmd
>
v>
end -->

Remove 000000C0.@ now!

Dmitry Sokolov:

I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.

Since that time I work every day to fix the issues that antiviruses cannot.

If your antivirus have not helped you solve the problem, you should try UnHackMe.

We are a small company and you can ask me directly, if you have any questions.

Testimonials

You can read UnHackMe testimonials here.