Threat Database Trojans Rootkit.win32.zero

Rootkit.win32.zero

By GoldSparrow in Trojans

Threat Scorecard

Ranking: 6,029
Threat Level: 10 % (Normal)
Infected Computers: 641
First Seen: September 9, 2011
Last Seen: September 16, 2023
OS(es) Affected: Windows

Rootkit.win32.zero is a dangerous Trojan that comes bundled together with other malware infections. Rootkit.win32.zero can hide itself on the targeted computer system by avoiding genuine anti-spyware applications. Rootkit.win32.zero may also open ports on the infected PC system which potentially results in further attacks on the corrupted machine. Rootkit.win32.zero can also download some malicious files from its external servers. It is recommended to remove Rootkit.win32.zero immediately after detection.

File System Details

Rootkit.win32.zero may create the following file(s):
# File Name Detections
1. c:\windows\PEV.exe
2. c:\windows\system32\drivers\mbamswissarmy.sys
3. c:\windows\SWREG.exe
4. c:\windows\junction.exe
5. c:\windows\system32\dllcache\ndistapi.sys
6. c:\windows\sed.exe
7. c:\windows\MBR.exe
8. c:\windows\system32\drivers\mbam.sys
9. c:\windows\system32\c_11426.nl_
10. C:\ComboFixReal
11. c:\ComboFixReal3437C
12. C:\cmdcons

Registry Details

Rootkit.win32.zero may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run lsass = "%System%\DETER177\lsass.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\scrfile (Default) =

Trending

Most Viewed

Loading...