Rootkit Trojan

Trojan:Win32/RootkitDrv!MSR removal guide

Malware Removal

The Trojan:Win32/RootkitDrv!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RootkitDrv!MSR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Loads a driver
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Created a service that was not started

How to determine Trojan:Win32/RootkitDrv!MSR?


File Info:

name: 00DDAE1A6735AA16E192.mlw
path: /opt/CAPEv2/storage/binaries/800fcbc79d99a5f12a29f65eb668f2cc101119b22ea4c40470caa2c6eb460c19
crc32: 275BA984
md5: 00ddae1a6735aa16e1921e50a0b84379
sha1: 07d35f04e2319b248176303f7c5fb47a4e8dd964
sha256: 800fcbc79d99a5f12a29f65eb668f2cc101119b22ea4c40470caa2c6eb460c19
sha512: 1dc832e9389f391c93c24aae8768a7577c77894be0e878435f12b95c9f962f55945db68336c0dec37af05a2dd86796670eb74525d28872bc2bdd2d390a81de7f
ssdeep: 3072:PR1ql9RVNoLuifFJ/rR7jkdfaouZ88jU:qlfVNoyi9J/r50fi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DF37D257AC09875C04945302AF78BB2D779FD201F60680BF7A436192EF33B69FA5B49
sha3_384: a1b85eab74348789d91c0ae590e01ed90bcfe03a2a746942b329ce2f0d6bdb688f8d7e34f2d214e4c6c2f7a2e7026fa6
ep_bytes: 6a00e871f20000a370ee4100e837f200
timestamp: 2014-06-23 12:40:16

Version Info:

0: [No Data]

Trojan:Win32/RootkitDrv!MSR also known as:

MicroWorld-eScanGen:Variant.Fugrafa.4774
FireEyeGen:Variant.Fugrafa.4774
ALYacGen:Variant.Fugrafa.4774
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Fugrafa.4774
K7AntiVirusTrojan ( 0053af701 )
AlibabaTrojan:Win32/RootkitDrv.8687824c
K7GWTrojan ( 0053af701 )
Cybereasonmalicious.a6735a
BitDefenderThetaGen:NN.ZexaCO.34294.jqW@au1kUXgc
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.Atsiv.A
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Fugrafa.4774
NANO-AntivirusTrojan.Win32.Atsiv.gudlop
Ad-AwareGen:Variant.Fugrafa.4774
EmsisoftGen:Variant.Fugrafa.4774 (B)
ZillyaTool.Atsiv.Win32.1
McAfee-GW-EditionBehavesLike.Win32.PUP.ch
SophosGeneric PUA AH (PUA)
AviraTR/Agent.vgfxy
Antiy-AVLTrojan/Generic.ASMalwS.300D5FF
MicrosoftTrojan:Win32/RootkitDrv!MSR
GDataGen:Variant.Fugrafa.4774
CynetMalicious (score: 99)
McAfeeGenericRXAA-FA!00DDAE1A6735
MalwarebytesMalware.AI.3384566732
YandexTrojan.GenAsa!+Zfk9ftdzcM
IkarusTrojan-Spy.Win32.Zbot
eGambitUnsafe.AI_Score_99%

How to remove Trojan:Win32/RootkitDrv!MSR?

Trojan:Win32/RootkitDrv!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment