Rootkit

Should I remove “Rootkit.82302”?

Malware Removal

The Rootkit.82302 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.82302 virus can do?

  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Rootkit.82302?


File Info:

crc32: 689B6ACC
md5: aec34aa3f88b2a269ba80de37328a238
name: AEC34AA3F88B2A269BA80DE37328A238.mlw
sha1: f5bfba4a31cd57a3fe764dc9fa9059869f2ea73b
sha256: 9a7066852006775cdfbb3a5d7e44452f8d3c76dddd218e40ef4c2dca6228fe1d
sha512: 56ba063eadf95e1c6ce29bbebdd340e86c063034ef7b306e27ca20a5a082d013431553f5bc61bdd81e2e2aa1ca19985c179422a391419e0429a6d7d3f99c4a45
ssdeep: 49152:tel9hxU/TRw90x9vbJRWZowN6/UyqqLu1mdPt8Qa:8hOf3Cb6/FqqLldPt8Qa
type: PE32+ executable (native) x86-64, for MS Windows

Version Info:

LegalCopyright: Microsoft Windows Operating System
InternalName: MSFS.SYS
FileVersion: 6.1.7600.16385
CompanyName: Microsoft Corporation
ProductName: Microsoft Windows Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Mailslot driver
OriginalFilename: MSFS.SYS
Translation: 0x0804 0x04b0

Rootkit.82302 also known as:

MicroWorld-eScanRootkit.82302
CAT-QuickHealRootkit.Win64
ALYacRootkit.82302
ZillyaRootkit.Rimic.Win64.1
AlibabaRootkit:Win64/Rimic.a7f07dee
Cybereasonmalicious.3f88b2
TrendMicroTROJ_GEN.R002C0WIQ19
AvastWin64:Malware-gen
GDataRootkit.82302
KasperskyRootkit.Win64.Rimic.a
BitDefenderRootkit.82302
TencentWin32.Rootkit.Obfuscator.Kzvh
Ad-AwareRootkit.82302
SophosMal/Generic-S
F-SecureTrojan.RKIT/Rimic.gtuzy
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
FireEyeRootkit.82302
EmsisoftRootkit.82302 (B)
Endgamemalicious (high confidence)
MicrosoftTrojan:Win32/Bitrep.B
ArcabitRootkit.D1417E
ZoneAlarmRootkit.Win64.Rimic.a
McAfeeArtemis!AEC34AA3F88B
MAXmalware (ai score=81)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0WIQ19
YandexRootkit.Rimic!
IkarusRootkit.Rimic
FortinetW64/Rimic.A!tr.rkit
AVGWin64:Malware-gen
Qihoo-360Trojan.Generic

How to remove Rootkit.82302?

Rootkit.82302 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment