Rootkit

VirTool:WinNT/Rootkitdrv!FX removal

Malware Removal

The VirTool:WinNT/Rootkitdrv!FX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What VirTool:WinNT/Rootkitdrv!FX virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.

How to determine VirTool:WinNT/Rootkitdrv!FX?


File Info:

crc32: E5FD7889
md5: b66e330e87996b8fc0966770137bc0a6
name: B66E330E87996B8FC0966770137BC0A6.mlw
sha1: df7483d7750c1963fa04238246b08b09fe0495e4
sha256: 6295012a8d898a160870db3ebbf7ed4b4c089a27e0bad3108ccef0e8948e2852
sha512: 83cd4840acae93a27e5b37a75b4720de92a2cbc35c53f73b64200d0e81821a343a85f3235d8c757db906552f5ee4580ff7949f7b5b3243dfd1e7b55b542be7ed
ssdeep: 49152:uupbUqIS6lpvlG4tV4k+s8KuqGaX0ToIBAUZLY1:BelpvlG4T+JBAUZLW
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2019 - 2021 SuperMic.All Rights Reserved.
FileVersion: 1.4.0.1
CompanyName: SuperMic
Comments: YTClient Installer
ProductName: YTClient Installer
ProductVersion: 1.4.0.1
FileDescription: YTClient Installer
Translation: 0x0804 0x04b0

VirTool:WinNT/Rootkitdrv!FX also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.Generic.lwTx
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Wsgame.35243
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.37934421
CylanceUnsafe
SangforRootkit.Win32.HideProc.bj
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaRootkit:Win32/HideProc.76396689
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.7750c1
BaiduWin32.Rootkit.HideProc.b
CyrenW32/Trojan.CLL.gen!Eldorado
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:GenMaliciousA-BNL [Trj]
ClamAVWin.Trojan.Rootkit-6027
KasperskyUDS:Rootkit.Win32.HideProc.bj
BitDefenderTrojan.GenericKD.37934421
MicroWorld-eScanTrojan.GenericKD.37934421
TencentWin32.Trojan.Agent.Pezm
Ad-AwareTrojan.GenericKD.37934421
SophosGeneric PUA NP (PUA)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
BitDefenderThetaGen:NN.ZexaF.34266.gs0@aCdwn5eb
TrendMicroTROJ_GEN.R002C0DK321
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGeneric.mg.b66e330e87996b8f
EmsisoftTrojan.GenericKD.37934421 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Rootkitdrv.xlnte
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftVirTool:WinNT/Rootkitdrv.gen!FX
ArcabitTrojan.Generic.D242D555
GDataWin32.Trojan.PSE.19Q2126
AhnLab-V3Trojan/Win.GenMaliciousA.C4748817
Acronissuspicious
McAfeeArtemis!B66E330E8799
MAXmalware (ai score=81)
VBA32BScope.Trojan.Tiggre
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002C0DK321
RisingTrojan.Generic@ML.93 (RDMK:TKIjNLoG7j24n8jwT6EXAw)
IkarusTrojan.Win32.Disabler
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:GenMaliciousA-BNL [Trj]
Paloaltogeneric.ml

How to remove VirTool:WinNT/Rootkitdrv!FX?

VirTool:WinNT/Rootkitdrv!FX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment