Rootkit

Win32:Rootkit-FP [Trj] removal guide

Malware Removal

The Win32:Rootkit-FP [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Rootkit-FP [Trj] virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Win32:Rootkit-FP [Trj]?


File Info:

name: 6CBFBF94869492536A34.mlw
path: /opt/CAPEv2/storage/binaries/bc894a66744203eb3956e42b143c2caf9cd89bb2bd2e9ad25cce60fbdb36dcf0
crc32: E8F8F111
md5: 6cbfbf94869492536a34b2c2c78abe7e
sha1: 1dbb748f7ea396fe066593c652340588fb7d082e
sha256: bc894a66744203eb3956e42b143c2caf9cd89bb2bd2e9ad25cce60fbdb36dcf0
sha512: b5ed65d7cb4fdb941e2d1330f0fb920a3f2f085affb800f588969c3df6df320d8db99dfe6818cca8940cfe31261eabe07f911d7ced0d2f2455ec3b47c1149795
ssdeep: 12288:lvYi3BcLBHLnLVDJ2Gie9wquYHLrgeGv7n9J2XayMuxG3xCGR5nWFpPoSOCxbwsG:lvY4cJLnLpJDiUu4LoqXaxabRxbwOQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9459E13F19380F2D618193015F67B3AAE3597670E22CAD79B98DD782C32660F63B25D
sha3_384: 0fcb9f05264fb2ab1e81e128124debc15b9b15cc3d7af04e819cbf8e868b265eb4cc31755824801f3984c445345bf719
ep_bytes: 558bec6aff6890484f006848464a0064
timestamp: 2021-10-30 12:57:48

Version Info:

FileVersion: 1.0.1.0
FileDescription: CF助手
ProductName: CF助手
ProductVersion: 1.0.1.0
CompanyName: 羊小小
LegalCopyright: 羊小小CF助手
Comments: CF助手
Translation: 0x0804 0x04b0

Win32:Rootkit-FP [Trj] also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47579055
FireEyeGeneric.mg.6cbfbf9486949253
CAT-QuickHealTrojanpws.Qqpass.16554
ALYacTrojan.GenericKD.47579055
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
AlibabaBackdoor:Win32/Poison.d9839dab
K7GWTrojan ( 005886601 )
Cybereasonmalicious.f7ea39
BitDefenderThetaGen:NN.ZexaF.34062.hr0@a8Jzdsfb
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.OMK
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9820446-0
KasperskyHEUR:Backdoor.Win32.Poison.gen
BitDefenderTrojan.GenericKD.47579055
AvastWin32:Rootkit-FP [Trj]
Ad-AwareTrojan.GenericKD.47579055
EmsisoftTrojan.GenericKD.47579055 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
BaiduWin32.Trojan.Agent.fu
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/QiangWei
Antiy-AVLTrojan/Generic.ASCommon.FA
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Tiggre!rfn
GDataTrojan.GenericKD.47579055
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!6CBFBF948694
MAXmalware (ai score=83)
VBA32BScope.Trojan.Fuerboos
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CL621
RisingMalware.ELang!1.64EA (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Rootkit-FP [Trj]
PandaTrj/GdSda.A

How to remove Win32:Rootkit-FP [Trj]?

Win32:Rootkit-FP [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment