Rootkit

How to remove “Rootkit.48427”?

Malware Removal

The Rootkit.48427 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.48427 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Rootkit.48427?


File Info:

crc32: 60B4E7E0
md5: 3e3fa042aada756367233d6d4b39562c
name: 3E3FA042AADA756367233D6D4B39562C.mlw
sha1: 733e95bb1d4b7effd5f2c3c8ca406566a188dd26
sha256: 417d014a622f3f0aef25ccf77ac7f9a0e487c0e62f95b7d8eddd84f0e6ce1ab2
sha512: e9d4fc853ca5d3056b471a367b4d1240fe2663b74c25ca032059e4ea7d853bbfb986311bd79dd4868a43c4d4e7c566da18ca7d6210efc898fbdb9f9c7f16fb47
ssdeep: 6144:LwrfkA04eb5aK1HM/hxX1UhIPOXKKpkJsHViz:L8kA04e9lG/bX1Uh/Srz
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright xa9 Nfnlqra Qsxojg 1995-2009
InternalName: Nfnlqra
FileVersion: 37, 99, 88, 4
CompanyName: Nfnlqra Qsxojg
ProductName: Nfnlqra Hkdfltlmi Pfgvdvg
ProductVersion: 37, 99, 88, 4
FileDescription: Nfnlqra Hkdfltlmi Pfgvdvg
OriginalFilename: Nfnlqra.exe
Translation: 0x0409 0x04e4

Rootkit.48427 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( f1000f011 )
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen.28527
CynetMalicious (score: 100)
ALYacRootkit.48427
CylanceUnsafe
ZillyaTrojan.PornoBlocker.Win32.2064
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Obfuscator.a80b7b5a
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.2aada7
CyrenW32/Zbot.DA.gen!Eldorado
ESET-NOD32a variant of Win32/Kryptik.MWZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderRootkit.48427
NANO-AntivirusTrojan.Win32.ULPM.bkwmwk
ViRobotTrojan.Win32.A.PornoBlocker.240924[UPX]
MicroWorld-eScanRootkit.48427
TencentWin32.Trojan.Generic.Llhv
Ad-AwareRootkit.48427
SophosMal/Generic-R + Mal/Zbot-CX
ComodoMalware@#3a4167xk7zx4r
BitDefenderThetaGen:NN.ZexaF.34628.omLfa80YSPii
VIPREPacked.Win32.PWSZbot.gen (v)
TrendMicroTROJ_RANSOM.JBU
McAfee-GW-EditionW32/Pinkslipbot.gen.af
FireEyeGeneric.mg.3e3fa042aada7563
EmsisoftRootkit.48427 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/PornoBlocker.dfb
WebrootWorm:Autoit/Helompy.A
AviraTR/Crypt.ULPM.Gen
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitRootkit.DBD2B
AegisLabTrojan.Win32.PornoBlocker.j!c
GDataRootkit.48427
McAfeeW32/Pinkslipbot.gen.af
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
PandaGeneric Malware
TrendMicro-HouseCallTROJ_RANSOM.JBU
RisingTrojan.Tofumanics!8.2DCF (CLOUD)
YandexTrojan.GenAsa!QioUnNZOfck
IkarusTrojan.Win32.Yakes
FortinetW32/Krap.A!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Rootkit.Generic.HwsBEpsA

How to remove Rootkit.48427?

Rootkit.48427 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment