Rootkit

What is “Rootkit.Win32.Small.kr”?

Malware Removal

The Rootkit.Win32.Small.kr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Rootkit.Win32.Small.kr virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Rootkit.Win32.Small.kr?


File Info:

name: E7519A4E5EFA4A6BA130.mlw
path: /opt/CAPEv2/storage/binaries/9fcb4e19da7e4d739d19124ac99d0f29683fcea70a49acedafea9417245ac585
crc32: 61531BF9
md5: e7519a4e5efa4a6ba130e8857be03f9b
sha1: ac9a9c2369da5cfbc43ac1df19b4773356e20325
sha256: 9fcb4e19da7e4d739d19124ac99d0f29683fcea70a49acedafea9417245ac585
sha512: 01c0507a15480a15262a4a087881f966ee6299b2f5dd94691b2ba5111bcdb2d90fe703636e2176e6d898810169de6f2bbfe94d581f81ed08bc393c8e2e08abb1
ssdeep: 192:SW9uHF4V3vWOJWsV3f+86KQQB9dei1gFOnuytgQoxB5mubKQ4LK70MguZiAjbdCh:SIuaNWOJWaiE9dRvtylm+4MTac
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19E82B75237E8D4E3E09F07786DA283564FB2F964CE38811B25C4A28F4DAC7558E2E771
sha3_384: 45ee92e350e2aa1ba64dc4c53bec31d9ec88d7090d8b2f6c07da4006cc5d326d4c5e9ef227b0386895dca85a90dae15f
ep_bytes: 8bff558beca10430010085c0b940bb00
timestamp: 2008-12-05 04:44:45

Version Info:

0: [No Data]

Rootkit.Win32.Small.kr also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Small.4!c
MicroWorld-eScanTrojan.GenericKD.64939037
FireEyeTrojan.GenericKD.64939037
McAfeeRDN/Generic.dx
ZillyaRootkit.Small.Win32.462
SangforTrojan.Win32.Save.a
AlibabaRootkit:Win32/Genome.da47a9fd
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Small.AVY
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyRootkit.Win32.Small.kr
BitDefenderTrojan.GenericKD.64939037
TencentWin32.Rootkit.Small.Unkl
SophosMal/Generic-S
DrWebTrojan.NtRootKit.12921
VIPRETrojan.GenericKD.64939037
McAfee-GW-EditionRDN/Generic.dx
EmsisoftTrojan.GenericKD.64939037 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.64939037
JiangminRootkit.Small.ux
Antiy-AVLTrojan[Rootkit]/Win32.Small
ArcabitTrojan.Generic.D3DEE41D
ZoneAlarmRootkit.Win32.Small.kr
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
Acronissuspicious
ALYacTrojan.GenericKD.64939037
MAXmalware (ai score=87)
Cylanceunsafe
PandaTrj/Chgt.AD
RisingMalware.Undefined!8.C (TFE:4:MeeKkOGqmwC)
YandexRootkit.Small!secIwsYevbI
IkarusTrojan.Win32.Genome
MaxSecureTrojan.Malware.813926.susgen
DeepInstinctMALICIOUS

How to remove Rootkit.Win32.Small.kr?

Rootkit.Win32.Small.kr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment