Rootkit

Rootkit.51935 (file analysis)

Malware Removal

The Rootkit.51935 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.51935 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Rootkit.51935?


File Info:

crc32: 3C638B4C
md5: 45dcb73d680fa842462ac0bb3cc77aae
name: 45DCB73D680FA842462AC0BB3CC77AAE.mlw
sha1: 52cc36f54b799972535bc393ba3306611a01c044
sha256: 625cc0e5cb1941ae6be7b7ed590855cd27116ba68b0f8d892c8617b95d8c7c23
sha512: 7d33c6d65a7cda41580bd02401dfe60053aed2c4f2b16c7bc24f5f3e5aea61a440b7c5f019e0232b681b40f326a921084e7ba02744bfd2c831804dd4108166ee
ssdeep: 1536:mWHzsJAucXDJLHaUmYt0vXZ8HCI0+3V76UMy5wgfd8/JXZoSIo5:9sJ8DJNmO0vLItVuy5wgl8/JXZz
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Dying xa9 Conch Sect 1998-2010
InternalName: Coop Zing
FileVersion: 2.1
CompanyName: Lenovo Corporation
ProductName: Maud
ProductVersion: 2.1
FileDescription: Wet Swam Darts Virgil
OriginalFilename: Win.exe
Translation: 0x0409 0x04b0

Rootkit.51935 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0023d7211 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacRootkit.51935
CylanceUnsafe
ZillyaTrojan.Delf.Win32.76564
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/EncPk.fc28500a
K7GWTrojan ( 0023d7211 )
Cybereasonmalicious.d680fa
CyrenW32/SuspPack.EC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.QBH
APEXMalicious
AvastWin32:MalOb-IJ [Cryp]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderRootkit.51935
MicroWorld-eScanRootkit.51935
TencentWin32.Trojan.Crypt.Peqe
Ad-AwareRootkit.51935
ComodoMalware@#236b3cw5ee7fq
BitDefenderThetaGen:NN.ZexaF.34050.hO0@a0zTeDii
VIPRETrojan.Win32.EncPk.acl (v)
FireEyeGeneric.mg.45dcb73d680fa842
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Qhost.dtx
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1894CF6
MicrosoftTrojan:Win32/Dynamer!ac
GDataRootkit.51935
Acronissuspicious
McAfeeArtemis!45DCB73D680F
MAXmalware (ai score=100)
VBA32Trojan.Qhost
PandaGeneric Malware
RisingTrojan.Generic@ML.90 (RDML:2s/bJL0i6l3GiUxebQXmBg)
YandexTrojan.GenAsa!tkfifwRJX7E
IkarusTrojan.Win32.Ransom
FortinetW32/Yakes.LS!tr
AVGWin32:MalOb-IJ [Cryp]
Paloaltogeneric.ml
Qihoo-360Win32/Rootkit.Generic.HgIASOoA

How to remove Rootkit.51935?

Rootkit.51935 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment