Rootkit

What is “Rootkit.0Access”?

Malware Removal

The Rootkit.0Access is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.0Access virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Rootkit.0Access?


File Info:

name: DA25C5DCE34DEDBA3626.mlw
path: /opt/CAPEv2/storage/binaries/dec57f9efbd55431a73647dddf475fa2ef8f1ada7da98bf51c90548efedd895a
crc32: 2F3EFD84
md5: da25c5dce34dedba3626925009936851
sha1: 06a5458ef7abb9252d05ed30d7add6619fd60e2a
sha256: dec57f9efbd55431a73647dddf475fa2ef8f1ada7da98bf51c90548efedd895a
sha512: 12970ce19911b44f603659c31a47ed303b50506da326c0964d2978d1d7e6b216dbd315b7a66846be384ebe9a36039a7927627d716c2a1b3584c11794c9daf44a
ssdeep: 3072:n+zZNRqqAaveKlLBm1K873fuMmn0VVhTK6jKlKDjdtPs2L6+CLi5CpLL1X:+zPNFBmQ87Pmmhe6Ol67s2L6325AL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCF312D17267F1FBF61AD3F916F87125AE2869086982D80B54E05FF4AF83236C1CD280
sha3_384: f681efd098083518d58e6f7ed30c30f7945c71806d6c709a5faeab193cd31532431c7e813de19b65f05213a8c0609c10
ep_bytes: babf080000558bec83ec0c810de1ab42
timestamp: 2011-04-23 12:39:17

Version Info:

0: [No Data]

Rootkit.0Access also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Heur.Conjar.9
CAT-QuickHealTrojan.Generic.20872
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0039ece11 )
K7GWTrojan ( 0039ece11 )
Cybereasonmalicious.ce34de
CyrenW32/Zbot.EU.gen!Eldorado
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.9
NANO-AntivirusTrojan.Win32.Andromeda.rlifh
AvastWin32:Crypt-MRR [Trj]
Ad-AwareGen:Heur.Conjar.9
EmsisoftGen:Heur.Conjar.9 (B)
ComodoTrojWare.Win32.Kryptik.AFFO@4oh8if
DrWebBackDoor.Andromeda.22
ZillyaTrojan.Zbot.Win32.76224
TrendMicroTSPY_ZBOT.SMEM
McAfee-GW-EditionPWS-Zbot.gen.azq
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.da25c5dce34dedba
SophosML/PE-A + Mal/Katusha-J
IkarusVirus.Win32.Obfuscator
GDataGen:Heur.Conjar.9
JiangminTrojan/Generic.abnua
WebrootW32.InfoStealer.Zeus
AviraTR/Dldr.Matsnu.C
ArcabitTrojan.Conjar.9
MicrosoftPWS:Win32/Zbot!CI
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Small.R26389
McAfeePWS-Zbot.gen.azq
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Androm
MalwarebytesRootkit.0Access
TrendMicro-HouseCallTSPY_ZBOT.SMEM
RisingTrojan.Generic@AI.90 (RDML:m6dmegQNA7wQef6Uwet7+g)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZeroAccess.B!tr
BitDefenderThetaGen:NN.ZexaF.34742.kiW@aSxsTyi
AVGWin32:Crypt-MRR [Trj]
PandaTrj/Xpacked.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Rootkit.0Access?

Rootkit.0Access removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment