Home Malware Programs Rootkits Rootkit.win32.zero

Rootkit.win32.zero

Posted: September 9, 2011

Threat Metric

Ranking: 6,783
Threat Level: 1/10
Infected PCs: 1,525
First Seen: September 9, 2011
Last Seen: October 16, 2023
OS(es) Affected: Windows

Rootkit.win32.zero is a rootkit that disables legitimate anti-virus software, blocks Windows programs from running and shows security warning messages. Once installed, Rootkit.win32.zero may slow down your PC performance and reduce network speed. Rootkit.win32.zero can install its startup entry on the corrupted PC to run itself each time you start your computer. To protect your machine from damage, download a dependable anti-malware program with rootkit removal capabilities to remove Rootkit.win32.zero.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



c:\windows\sed.exe File name: c:\windows\sed.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\windows\SWREG.exe File name: c:\windows\SWREG.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\windows\PEV.exe File name: c:\windows\PEV.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\windows\MBR.exe File name: c:\windows\MBR.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\ComboFixReal3437C File name: c:\ComboFixReal3437C
Group: Malware file
c:\windows\junction.exe File name: c:\windows\junction.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
c:\windows\system32\drivers\mbamswissarmy.sys File name: c:\windows\system32\drivers\mbamswissarmy.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
c:\windows\system32\drivers\mbam.sys File name: c:\windows\system32\drivers\mbam.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
c:\ComboFixReal File name: c:\ComboFixReal
Group: Malware file
c:\windows\system32\dllcache\ndistapi.sys File name: c:\windows\system32\dllcache\ndistapi.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
c:\windows\system32\c_11426.nl_ File name: c:\windows\system32\c_11426.nl_
Mime Type: unknown/nl_
Group: Malware file
c:\cmdcons File name: c:\cmdcons
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Classes\scrfile (Default) =HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon Shell =HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run lsass = "%System%\DETER177\lsass.exe"
Loading...