Rootkit

VirTool:WinNT/Rootkitdrv.HK malicious file

Malware Removal

The VirTool:WinNT/Rootkitdrv.HK is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:WinNT/Rootkitdrv.HK virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Loads a driver
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine VirTool:WinNT/Rootkitdrv.HK?


File Info:

name: DCB81BB5E8B14F8B606E.mlw
path: /opt/CAPEv2/storage/binaries/4baa2a31d74e77251811dad6ac9e0865b6e7d97828a80e2423798edd4693cc98
crc32: 75512552
md5: dcb81bb5e8b14f8b606e4e8b73d094b5
sha1: b738926a62658d54857bdd741d80f68c3fb384a7
sha256: 4baa2a31d74e77251811dad6ac9e0865b6e7d97828a80e2423798edd4693cc98
sha512: e4a83429dddf413786784b687fd84f32f7014c7476deee682d24ec7ba5e9daa1c4655cbebde0be61d48b57ef4eca610ce4748edb262e73832d03267214b99525
ssdeep: 98304:NDzBi9fetmfe2i9fe5tmfe2i9fU5tmfmfetmfe2i9fe5tmfe2i9fgmfUetmfe2io:NWBgZgfOBgZgTSgZgfOB6gZgTSa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13B86233E7720C4B8E9E95F35F58AAD721518A045E45D6BC32E08CAAC8D775E04BC07BB
sha3_384: 97f213202648863f57efa76c75429b0db17d7d2f5b68bd14007b15aebcc416529cb2b2a9c01f50c09b624c7a4980eff0
ep_bytes: 60be00e045008dbe0030faffc787a4d0
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

VirTool:WinNT/Rootkitdrv.HK also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanRootkit.48669
FireEyeGeneric.mg.dcb81bb5e8b14f8b
ALYacRootkit.48669
CylanceUnsafe
VIPRERootkit.Win32.Xanfpezes.br (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaMalware:Win32/km_2806ec1.None
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_70% (W)
VirITTrojan.Win32.Banker5.BHMC
CyrenW32/Backdoor.NMLQ-4408
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/HideProc.O potentially unsafe
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.74532-1
KasperskyRootkit.Win32.Xanfpezes.brv
BitDefenderRootkit.48669
NANO-AntivirusTrojan.Win32.Xanfpezes.dsnrra
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10b0d8b3
Ad-AwareRootkit.48669
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanSpy.Agent.~ABN@1gpzyv
DrWebTrojan.MulDrop4.33532
ZillyaDownloader.Banload.Win32.2034
TrendMicroTROJ_HIDEPROC.AZ
McAfee-GW-EditionBehavesLike.Win32.PUP.wc
EmsisoftRootkit.48669 (B)
Ikarusnot-a-virus:RiskTool.Win32.HideProc
GDataRootkit.48669
JiangminTrojanDownloader.Banload.afgw
AviraTR/Rootkit.Gen
Antiy-AVLTrojan/Generic.ASMalwS.4E3DB0
ViRobotTrojan.Win32.Downloader.649728.B
ZoneAlarmRootkit.Win32.Xanfpezes.brv
MicrosoftVirTool:WinNT/Rootkitdrv.HK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Banload.C69168
McAfeeGeneric Dropper.jf
MAXmalware (ai score=88)
VBA32TrojanDownloader.Banload
TrendMicro-HouseCallTROJ_HIDEPROC.AZ
RisingRootKit.Win32.HideProc.l (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.500016.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZelphiF.34212.@pJfaq24fnpb
AVGFileRepMalware
Cybereasonmalicious.5e8b14
PandaTrj/Genetic.gen

How to remove VirTool:WinNT/Rootkitdrv.HK?

VirTool:WinNT/Rootkitdrv.HK removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment