Crack

KernelDrUtil.Hacktool.Utility.DDS removal guide

Malware Removal

The KernelDrUtil.Hacktool.Utility.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What KernelDrUtil.Hacktool.Utility.DDS virus can do?

  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine KernelDrUtil.Hacktool.Utility.DDS?


File Info:

name: 5B33E484D97328EDAA01.mlw
path: /opt/CAPEv2/storage/binaries/c7ebf0b975802641b9a61f732e48dbdb8e66db446c05d12af02bf7c2aed7762d
crc32: A7DAC84D
md5: 5b33e484d97328edaa012bfc3a680609
sha1: 99dbc91adf83783e65b10b0c6f6a51714322f861
sha256: c7ebf0b975802641b9a61f732e48dbdb8e66db446c05d12af02bf7c2aed7762d
sha512: 6b779be4ed5b9dc5f4e6e68c30b6c33f356cd16f3a1caab9ebdb3f75645d7dd650ee8e39af3a6a9364c36be8c21821bf2980ec20aebf8cdab40a4681ec1c82d6
ssdeep: 12288:DZ6grCrkcHcmZB3y0W71oTY+PZE9O2bJIC0fDNN:DTrCrBZB3y0WZf+O93l0fZ
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T123C4AE16B3A524F9E877813CC8524506E772BC260765DBAF1390676A2F336D0AD3FB21
sha3_384: e1f752835d13b0425907405d9ddf4975da88e17309d3051638c39db005455bbfda769588ed7a8522b5d8a7bf869caf09
ep_bytes: 4883ec28e8e70700004883c428e972fe
timestamp: 2023-01-29 18:51:18

Version Info:

0: [No Data]

KernelDrUtil.Hacktool.Utility.DDS also known as:

LionicTrojan.Win64.Injects.tsbs
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Lazy.138240
McAfeeArtemis!5B33E484D973
MalwarebytesKernelDrUtil.Hacktool.Utility.DDS
VIPREGen:Variant.Application.Lazy.138240
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0057aacd1 )
AlibabaTrojanDropper:Win64/Genric.6cd91610
K7GWTrojan ( 0057aacd1 )
CyrenW64/KernelDrUtil.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win64/TrojanDropper.Agent.DO
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.xatkjv
BitDefenderGen:Variant.Application.Lazy.138240
NANO-AntivirusTrojan.Win64.Drop.junblf
AvastWin64:DropperX-gen [Drp]
TencentHackTool.Win64.KernelDrUtil.16000463
EmsisoftGen:Variant.Application.Lazy.138240 (B)
DrWebTrojan.MulDrop21.34663
McAfee-GW-EditionBehavesLike.Win64.Dropper.hh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.5b33e484d97328ed
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Application.Lazy.138240
JiangminTrojan.Agent.ejvo
GoogleDetected
AviraTR/Drop.Agent.ivkve
MAXmalware (ai score=74)
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Application.Lazy.D21C00
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R445388
ALYacGen:Variant.Application.Lazy.138240
TrendMicro-HouseCallTROJ_GEN.R002H0CAT23
RisingDropper.Agent!8.2F (CLOUD)
IkarusTrojan-Dropper.Win64.Agent
MaxSecureTrojan.Malware.198937900.susgen
FortinetW64/Agent.DO!tr
AVGWin64:DropperX-gen [Drp]

How to remove KernelDrUtil.Hacktool.Utility.DDS?

KernelDrUtil.Hacktool.Utility.DDS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment