000000C0.@ - Dangerous
%LOCAL APPDATA%\3308C706\U\000000C0.@
Manual removal instructions:
Antivirus Report of %LOCAL APPDATA%\3308C706\U\000000C0.@:
%local appdata%\3308c706\u\000000c0.@
We suggest you to remove 00000001.@ from your computer as soon as possible.
00000001.@ is known as: Trojan.Small.45968, Trojan.Sirefef.PS4, W32.Sirefef.f, Trojan.Sirefef.cr, EmailWorm, a variant of Win32.Sirefef.CR, Trojan.Zeroaccess, W32.ZAccess.G, Win32:Alureon-AJI [Rtk], TRSirefef.P, Trojan.Rootkit-3105, Backdoor.ZAccess.aqo, Backdoor.Smadow, Trojan.Sirefef.AN, Trojan.Inject.53003, Trojan.Sirefef.cr (v), Troj.Luiha-T, Win32.Smadow.P, Rootkit.ZAccess.cj, Trojan.Sirefef.P, Trojan.ZAccess.45968, Trojan.ZAccess, W32.TDSSPack.A.tr, Dropper.Agent.ARQJ.
MD5 of 00000001.@ = 59cc0151f048eff85b5f67824916567e
00000001.@ size is 45968 bytes.
Full path on a computer: %LOCAL APPDATA%\3308C706\U\000000C0.@
Related Files:
HKLM\System\CurrentControlSet\Services\se59nd5\Parameters\ServiceDll: "%systemroot%\system32\CTSBLFX.DLL.dll"
>
%WinDir%\$NtUninstallKB3057$
>
%Local Appdata%\3308c706\@
%Local Appdata%\3308c706\U\00000001.@
%Local Appdata%\3308c706\U\000000c0.@
%Local Appdata%\3308c706\U\000000cb.@
%Local Appdata%\3308c706\U\000000cf.@
%Local Appdata%\3308c706\U\80000000.@
%Local Appdata%\3308c706\U\800000c0.@
%Local Appdata%\3308c706\U\800000cb.@
%Local Appdata%\3308c706\U\800000cf.@
%Local Appdata%\3308c706\X
%WinDir%\assembly\GAC_MSIL\Desktop.ini
%SysDir%\CTSBLFX.DLL.dll
%SysDir%\dds_log_ad13.cmd
>
v>
end -->
%LOCAL APPDATA%\3308C706\U\000000C0.@ | Trojan.Small.45968, Trojan.Sirefef.PS4, W32.Sirefef.f, Trojan.Sirefef.cr, EmailWorm, a variant of Win32.Sirefef.CR, Trojan.Zeroaccess, W32.ZAccess.G, Win32:Alureon-AJI [Rtk], TRSirefef.P, Trojan.Rootkit-3105, Backdoor.ZAccess.aqo, Backdoor.Smadow, Trojan.Sirefef.AN, Trojan.Inject.53003, Trojan.Sirefef.cr (v), Troj.Luiha-T, Win32.Smadow.P, Rootkit.ZAccess.cj, Trojan.Sirefef.P, Trojan.ZAccess.45968, Trojan.ZAccess, W32.TDSSPack.A.tr, Dropper.Agent.ARQJ. |
%LOCAL APPDATA%\3308C706\U\000000C0.@ | Dangerous |
%LOCAL APPDATA%\3308C706\U\000000C0.@ | High Risk |
00000001.@ is known as: Trojan.Small.45968, Trojan.Sirefef.PS4, W32.Sirefef.f, Trojan.Sirefef.cr, EmailWorm, a variant of Win32.Sirefef.CR, Trojan.Zeroaccess, W32.ZAccess.G, Win32:Alureon-AJI [Rtk], TRSirefef.P, Trojan.Rootkit-3105, Backdoor.ZAccess.aqo, Backdoor.Smadow, Trojan.Sirefef.AN, Trojan.Inject.53003, Trojan.Sirefef.cr (v), Troj.Luiha-T, Win32.Smadow.P, Rootkit.ZAccess.cj, Trojan.Sirefef.P, Trojan.ZAccess.45968, Trojan.ZAccess, W32.TDSSPack.A.tr, Dropper.Agent.ARQJ.
MD5 of 00000001.@ = 59cc0151f048eff85b5f67824916567e
00000001.@ size is 45968 bytes.
Full path on a computer: %LOCAL APPDATA%\3308C706\U\000000C0.@
Related Files:
Registry:
HKLM\System\CurrentControlSet\Services\se59nd5\Parameters\ServiceDll: "%systemroot%\system32\CTSBLFX.DLL.dll"
>
Folders:
%WinDir%\$NtUninstallKB3057$
>
Files:
%Local Appdata%\3308c706\@
%Local Appdata%\3308c706\U\00000001.@
%Local Appdata%\3308c706\U\000000c0.@
%Local Appdata%\3308c706\U\000000cb.@
%Local Appdata%\3308c706\U\000000cf.@
%Local Appdata%\3308c706\U\80000000.@
%Local Appdata%\3308c706\U\800000c0.@
%Local Appdata%\3308c706\U\800000cb.@
%Local Appdata%\3308c706\U\800000cf.@
%Local Appdata%\3308c706\X
%WinDir%\assembly\GAC_MSIL\Desktop.ini
%SysDir%\CTSBLFX.DLL.dll
%SysDir%\dds_log_ad13.cmd
>
v>
end -->
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.