Rootkit

Rootkit.Ressdt removal instruction

Malware Removal

The Rootkit.Ressdt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Ressdt virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Rootkit.Ressdt?


File Info:

name: C5F1140E378C86D11284.mlw
path: /opt/CAPEv2/storage/binaries/28e1dfe09a5fbae16c6d8c77762654e2b099c6acbc737f82e64ae13ab48206fe
crc32: 7074F064
md5: c5f1140e378c86d11284f7ef61895bcd
sha1: 5852d011f4c04f23d80ed4a6abc2ee0dbcda60da
sha256: 28e1dfe09a5fbae16c6d8c77762654e2b099c6acbc737f82e64ae13ab48206fe
sha512: 11db9ff711006daf02db48d744fa5f3cac7c84fde065d1c84c537951ab6822538269e1d0a4bcbd68bed86a1fcb1ed0ae36b734af5a94b377b2850aa4d881f3e3
ssdeep: 98304:lelU0Ndo3e6356Umq02322+tCA4dfBpZSzsHu5RYdcVG:GPdke635E1C2Bd4df9AYT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137363348EAC9C1B7DF6F057148D0337FC21DE58AF495C22BAB98AD8E1511EF4A04D1AE
sha3_384: d619e98224b80d7a212f016772aecc90515f0bd7643dd5a94dd870718aaa9ca3cfcd34eced589ec466c531c481561b90
ep_bytes: e8f32a000050e83b3301000000000090
timestamp: 2007-09-20 12:34:46

Version Info:

0: [No Data]

Rootkit.Ressdt also known as:

Cybereasonmalicious.1f4c04
VBA32Rootkit.Ressdt
APEXMalicious

How to remove Rootkit.Ressdt?

Rootkit.Ressdt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment