Categories: Rootkit

How to remove “Rootkit.50912 (B)”?

The Rootkit.50912 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.50912 (B) virus can do?

  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Rootkit.50912 (B)?


File Info:

name: 66F25A53520423E6DEED.mlwpath: /opt/CAPEv2/storage/binaries/66946428379578427a243435c2f1159d641023c29a701d7c8d55abdbb31096cccrc32: F6B5FB93md5: 66f25a53520423e6deed7fe282579f2dsha1: 0a20d7f4a3a594e428293555bb32bd2b50d88b98sha256: 66946428379578427a243435c2f1159d641023c29a701d7c8d55abdbb31096ccsha512: d3f3a09233fcb2271416eb41b74a122cdff3cedfe753da0caa4156a4302f5ab7b392b9a2fc6e85248d84c09096ea2b81e6a7f887429f3db83ef9f0f3a18a8110ssdeep: 768:ZGBKzFj0NbVANwqKfXyLhgkPn2vEDC52CjaXLL6:Ug0NbVAzKfA//CebL6type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T1A5334A0EB694C072D87206705875B6619F3B7C625F78529B3B8812BD6FB26C08B3C357sha3_384: e7dc352e380c04ba28210c55156e71206ef93d90a4bd4e1155f14343aa38d270ebe721a804b0f8cb0fd526031bab2975ep_bytes: e83c250000e989feffffc70170824000timestamp: 2011-09-17 16:25:04

Version Info:

0: [No Data]

Rootkit.50912 (B) also known as:

Lionic Trojan.Win32.Reconyc.4!c
FireEye Generic.mg.66f25a53520423e6
ALYac Rootkit.50912
Cylance Unsafe
CrowdStrike win/malicious_confidence_70% (W)
Alibaba Trojan:Win32/Reconyc.1faf4511
BitDefenderTheta Gen:NN.ZexaF.34592.duW@aiZLpbci
Cyren W32/NewMalware-Rootkit-I-based!
Symantec ML.Attribute.HighConfidence
Paloalto generic.ml
Kaspersky Trojan.Win32.Reconyc.efkk
NANO-Antivirus Trojan.Win32.TrjGen.edgisr
Avast Win32:Malware-gen
Tencent Win32.Exploit.50912.bmzq
Emsisoft Rootkit.50912 (B)
Comodo Malware@#2ix009hq8yr9v
VIPRE Rootkit.50912
TrendMicro TROJ_GEN.R002C0RHD22
McAfee-GW-Edition BehavesLike.Win32.NetLoader.qm
Sophos Mal/Emogen-Y
SentinelOne Static AI – Suspicious PE
Jiangmin Trojan/Genome.bhib
Google Detected
Avira RKIT/50912.A.1
Antiy-AVL Trojan/Generic.ASMalwS.35E5
Microsoft Trojan:Win32/Wacatac.B!ml
GData Rootkit.50912
Cynet Malicious (score: 99)
McAfee Artemis!66F25A535204
MAX malware (ai score=84)
VBA32 BScope.Trojan.Reconyc
TrendMicro-HouseCall TROJ_GEN.R002C0RHD22
Rising Trojan.Reconyc!8.153 (CLOUD)
Ikarus Rootkit
Fortinet W32/Emogen.Y
AVG Win32:Malware-gen
Cybereason malicious.352042
Panda Generic Malware

How to remove Rootkit.50912 (B)?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Trojan.PWS.OnlineGames.KDXA information

The Trojan.PWS.OnlineGames.KDXA is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

Trojan:Win32/Koutodoor!pz removal tips

The Trojan:Win32/Koutodoor!pz is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

About “Trojan:Win32/Regrun!pz” infection

The Trojan:Win32/Regrun!pz is considered dangerous by lots of security experts. When this infection is active,…

27 mins ago

What is “Malware.AI.3739112771”?

The Malware.AI.3739112771 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

Generic.MSIL.Bladabindi.574A3861 (file analysis)

The Generic.MSIL.Bladabindi.574A3861 is considered dangerous by lots of security experts. When this infection is active,…

36 mins ago

Ransom.Cryfile.16952 information

The Ransom.Cryfile.16952 is considered dangerous by lots of security experts. When this infection is active,…

51 mins ago