Threat Database Trojans Trojan.Zeroaccess.C

Trojan.Zeroaccess.C

By ZulaZuza in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 48
First Seen: August 16, 2012
OS(es) Affected: Windows

Trojan.Zeroaccess.C is a Trojan that may distribute other malware infections to the affected PC. Trojan.Zeroaccess.C can steal confidential data from the infected computer system. While being run, Trojan.Zeroaccess.C determines if the affected computer is 32- or 64-bit and chooses the particular payload. Trojan.Zeroaccess.C adds and runs infected files, creates folders and registry entries. Trojan.Zeroaccess.C then contacts a peer-to-peer network and downloads other threat modules.

Aliases

12 security vendors flagged this file as malicious.

Anti-Virus Software Detection
AntiVir TR/Crypt.XPACK.Gen
Sophos Troj/ZAccess-KY
Kaspersky Backdoor.Win32.ZAccess.cdsd
Panda Suspicious file
AVG Generic30.CAC
Fortinet W32/ZeroAccess.B!tr
GData Win32:Rootkit-gen
Comodo Heur.Packed.Unknown
Sophos Troj/ZAccess-EG
Kaspersky Trojan-Ransom.Win32.PornoAsset.aqbx
Avast Win32:Rootkit-gen [Rtk]
Symantec Trojan.Zeroaccess.C

SpyHunter Detects & Remove Trojan.Zeroaccess.C

File System Details

Trojan.Zeroaccess.C may create the following file(s):
# File Name MD5 Detections
1. n. 8d247eef3d376c16e489cd6ed46c9ac3 44
2. n. 4a8843f21767e135133d3c310a8ce1c3 4
3. %UserProfile%\AppData\Local\[UUID]\@
4. %Windir%\Installer\[UUID]\n
5. %UserProfile%\Local Settings\Application Data\[UUID]\n
6. %Windir%\Installer\[UUID]\@
7. %UserProfile%\Local Settings\Application Data\[UUID]\@
8. %UserProfile%\AppData\Local\[UUID]\n
9. decry.tmp bffc3e2b7382d093fb7440cabbd7b1ba 0
10. strikezIR1CF.dll 2f80f51188dc9aea697868864d88925d 0
11. malware.dll 21ffd24b8074d7cffdf4cc339d1fa8fe 0

Registry Details

Trojan.Zeroaccess.C may create the following registry entry or registry entries:
HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32\"@" = "%UserProfile%\Local Settings\Application Data\[UUID]\n."
HKEY_CLASSES_ROOT\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InprocServer32\"@" = "%UserProfile%\AppData\Local\[UUID]\n."
HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32\"@" = "%Windir%\Installer\[UUID]\n."

Trending

Most Viewed

Loading...