Categories: RootkitTrojan

Trojan:Win32/RootkitDrv!MSR removal guide

The Trojan:Win32/RootkitDrv!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/RootkitDrv!MSR virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Loads a driver
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Created a service that was not started

How to determine Trojan:Win32/RootkitDrv!MSR?


File Info:

name: 00DDAE1A6735AA16E192.mlwpath: /opt/CAPEv2/storage/binaries/800fcbc79d99a5f12a29f65eb668f2cc101119b22ea4c40470caa2c6eb460c19crc32: 275BA984md5: 00ddae1a6735aa16e1921e50a0b84379sha1: 07d35f04e2319b248176303f7c5fb47a4e8dd964sha256: 800fcbc79d99a5f12a29f65eb668f2cc101119b22ea4c40470caa2c6eb460c19sha512: 1dc832e9389f391c93c24aae8768a7577c77894be0e878435f12b95c9f962f55945db68336c0dec37af05a2dd86796670eb74525d28872bc2bdd2d390a81de7fssdeep: 3072:PR1ql9RVNoLuifFJ/rR7jkdfaouZ88jU:qlfVNoyi9J/r50fitype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T18DF37D257AC09875C04945302AF78BB2D779FD201F60680BF7A436192EF33B69FA5B49sha3_384: a1b85eab74348789d91c0ae590e01ed90bcfe03a2a746942b329ce2f0d6bdb688f8d7e34f2d214e4c6c2f7a2e7026fa6ep_bytes: 6a00e871f20000a370ee4100e837f200timestamp: 2014-06-23 12:40:16

Version Info:

0: [No Data]

Trojan:Win32/RootkitDrv!MSR also known as:

MicroWorld-eScan Gen:Variant.Fugrafa.4774
FireEye Gen:Variant.Fugrafa.4774
ALYac Gen:Variant.Fugrafa.4774
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Suspicious.Win32.Fugrafa.4774
K7AntiVirus Trojan ( 0053af701 )
Alibaba Trojan:Win32/RootkitDrv.8687824c
K7GW Trojan ( 0053af701 )
Cybereason malicious.a6735a
BitDefenderTheta Gen:NN.ZexaCO.34294.jqW@au1kUXgc
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/RiskWare.Atsiv.A
APEX Malicious
Paloalto generic.ml
BitDefender Gen:Variant.Fugrafa.4774
NANO-Antivirus Trojan.Win32.Atsiv.gudlop
Ad-Aware Gen:Variant.Fugrafa.4774
Emsisoft Gen:Variant.Fugrafa.4774 (B)
Zillya Tool.Atsiv.Win32.1
McAfee-GW-Edition BehavesLike.Win32.PUP.ch
Sophos Generic PUA AH (PUA)
Avira TR/Agent.vgfxy
Antiy-AVL Trojan/Generic.ASMalwS.300D5FF
Microsoft Trojan:Win32/RootkitDrv!MSR
GData Gen:Variant.Fugrafa.4774
Cynet Malicious (score: 99)
McAfee GenericRXAA-FA!00DDAE1A6735
Malwarebytes Malware.AI.3384566732
Yandex Trojan.GenAsa!+Zfk9ftdzcM
Ikarus Trojan-Spy.Win32.Zbot
eGambit Unsafe.AI_Score_99%

How to remove Trojan:Win32/RootkitDrv!MSR?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Barys.456554 information

The Barys.456554 is considered dangerous by lots of security experts. When this infection is active,…

7 mins ago

Midie.66060 (file analysis)

The Midie.66060 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Should I remove “Symmi.6017 (B)”?

The Symmi.6017 (B) is considered dangerous by lots of security experts. When this infection is…

32 mins ago

Zusy.540971 removal tips

The Zusy.540971 is considered dangerous by lots of security experts. When this infection is active,…

33 mins ago

Should I remove “Win32:VB-VBS [Wrm]”?

The Win32:VB-VBS [Wrm] is considered dangerous by lots of security experts. When this infection is…

37 mins ago

AdClicker.Trojan.Clicker.DDS malicious file

The AdClicker.Trojan.Clicker.DDS is considered dangerous by lots of security experts. When this infection is active,…

37 mins ago