Rootkit

What is “Rootkit.BlackEnergy.A”?

Malware Removal

The Rootkit.BlackEnergy.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.BlackEnergy.A virus can do?

  • At least one process apparently crashed during execution
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Unusual version info supplied for binary

How to determine Rootkit.BlackEnergy.A?


File Info:

name: 3B2AC4AE457618EEDBE5.mlw
path: /opt/CAPEv2/storage/binaries/80fa3c0ab284c2027d7aaafdeba35d17e4a9e38dc7a91f72462491873878c98a
crc32: FC296BC5
md5: 3b2ac4ae457618eedbe5a69a4237f951
sha1: 6dff938fc3b14c355871731efb566e877e3660c5
sha256: 80fa3c0ab284c2027d7aaafdeba35d17e4a9e38dc7a91f72462491873878c98a
sha512: bf6a16f9fc904a9e8efd39d608db85c2f35ce318cf56ccbb855b581db4dcfcedd7ae61372642234d4ec065af486e07fbde466a42c9d95d3dcf7ccc5230e3f9d7
ssdeep: 3072:QpdBvPIUtCpzlS21mErA3uou8OGywi6mHmUJIzGX2O/SE7hUa4HFo+pLf6HlH0Dp:An4UtTUmIAU8OOibHmUJC8H7hUa0LCHS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A0402902A286C46D4A75F344516B2476E38B6434308C66076EDFA6F2F5BBC79D0E33E
sha3_384: 773de321c33a63fb4f61e795d301030eafc4a5c8bae8e5b09c87ba9249c70b0094dee1582c908701e93cd4a483c749fb
ep_bytes: c745f80000000089f8b85cc4bd51f7d0
timestamp: 1970-01-01 00:00:00

Version Info:

CompanyName: Micro
FileDescription: Windows®SysUtility
FileVersion: 5.0.7601.17514 (win7sp1_rtm.101119-1850)
InternalName: msiexec
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: msiexec.exe
ProductName: WindowsSysUtility - Unicode
ProductVersio: 5.0.7601.17514
Translation: 0x0409 0x04b0

Rootkit.BlackEnergy.A also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanRootkit.BlackEnergy.A
CylanceUnsafe
ZillyaBackdoor.Blakken.Win32.182
K7AntiVirusRootKit ( 004ecaf41 )
K7GWRootKit ( 004ecaf41 )
Cybereasonmalicious.e45761
VirITBackdoor.Win32.Generic.AUTV
CyrenW32/Trojan.ZUGE-8593
tehtrisGeneric.Malware
ESET-NOD32Win32/Rootkit.BlackEnergy.BB
APEXMalicious
ClamAVWin.Trojan.BlackEnergy2-1
KasperskyHEUR:Backdoor.Win32.Blakken.gen
BitDefenderRootkit.BlackEnergy.A
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Malware-gen
Ad-AwareRootkit.BlackEnergy.A
EmsisoftRootkit.BlackEnergy.A (B)
DrWebBackDoor.BlackEnergy.75
VIPRERootkit.BlackEnergy.A
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.3b2ac4ae457618ee
SophosTroj/Blakken-A
GDataRootkit.BlackEnergy.A
JiangminTrojan.Generic.acbcv
AviraTR/Kazy.438154.2
Antiy-AVLTrojan/Generic.ASMalwS.3E79
ArcabitRootkit.BlackEnergy.A
ZoneAlarmHEUR:Backdoor.Win32.Blakken.gen
MicrosoftPWS:Win32/Zbot!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.Blacken.R124316
VBA32Malware-Cryptor.General.3
ALYacRootkit.BlackEnergy.A
MAXmalware (ai score=81)
RisingBackdoor.Win32.Phdet.c (CLASSIC)
YandexRootkit.BlackEnergy!bwYcWeeRFH0
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZexaF.34806.lq2@aeUVJCii
AVGWin32:Malware-gen

How to remove Rootkit.BlackEnergy.A?

Rootkit.BlackEnergy.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment