Rootkit

Rootkit.72920 removal tips

Malware Removal

The Rootkit.72920 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.72920 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Rootkit.72920?


File Info:

name: 7A3DD55DE95BF4BEB19E.mlw
path: /opt/CAPEv2/storage/binaries/00980030a44b81d6adb33aac860cb7ad9a29162fdab350b7d257d3bbcf712ac7
crc32: F7E341C3
md5: 7a3dd55de95bf4beb19eab0e3c8273a4
sha1: 3953896c77ad7c9823a0929e16dd868aabf7e988
sha256: 00980030a44b81d6adb33aac860cb7ad9a29162fdab350b7d257d3bbcf712ac7
sha512: d1bfa6c3e7e0b2162999121416ace5725f71868b8fe2fa4d1d89ed93982b3bb7190b8d6936c95e2aa215b6340707b92ce56faf155e6f0fd169d1d5e3e0d19e19
ssdeep: 24:ev1GSHop/vbirjH2hRLLgT9Nw9pugofxquPXv8jvlF6K8JzFY6qveTVidfN8imz:qHoRvbZLLgTwndwXFJRYNaVid1Dmz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3418262CA689E74D05B82F57E1E9F5988F43011760CE1174AEC4C522EA1116AF87E4C
sha3_384: 1fa1127d2d0a5325ac1944d4179f31c8e100a9a211b80335a7b58c01edaee5fc24b7f271b225cbea727b78382e99fb42
ep_bytes: 558bec51538b4508c740349104400033
timestamp: 2009-04-21 16:49:00

Version Info:

0: [No Data]

Rootkit.72920 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanRootkit.72920
FireEyeGeneric.mg.7a3dd55de95bf4be
McAfeeArtemis!7A3DD55DE95B
CylanceUnsafe
VIPRERootkit.72920
SangforTrojan.Win32.Agent.2176
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaRootkit:Win32/Generic.58275da3
K7GWTrojan ( 00509d1f1 )
K7AntiVirusTrojan ( 00509d1f1 )
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderRootkit.72920
AvastWin32:Malware-gen
Ad-AwareRootkit.72920
SophosMal/Generic-R + Mal/Rootkit-Q
TrendMicroTROJ_GEN.R002C0RDQ22
McAfee-GW-EditionArtemis!Trojan
EmsisoftRootkit.72920 (B)
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1240115
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.6C82
KingsoftWin32.Malware.Heur_Generic.B.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataRootkit.72920
CynetMalicious (score: 99)
ALYacRootkit.72920
TACHYONTrojan/W32.Agent.2176.P
TrendMicro-HouseCallTROJ_GEN.R002C0RDQ22
RisingTrojan.Generic@AI.98 (RDML:IUFtD5Ir6MOx6T4IDzI/XQ)
YandexRootkit.Agent!pt2hDZlivjA
IkarusRootkit
MaxSecureTrojan.Malware.8948555.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.de95bf
PandaTrj/GdSda.A

How to remove Rootkit.72920?

Rootkit.72920 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment