Threat Database Malware VirTool:WinNT/Rootkitdrv.HS


By Domesticus in Malware

Threat Scorecard

Ranking: 16,284
Threat Level: 80 % (High)
Infected Computers: 1,716
First Seen: December 21, 2010
Last Seen: September 14, 2023
OS(es) Affected: Windows

VirTool:WinNT/Rootkitdrv.HS is dangerous malware with rootkit functionality. VirTool:WinNT/Rootkitdrv.HS may enter a system bundled with other malware or internet downloads. VirTool:WinNT/Rootkitdrv.HS uses stealth tactics to operate without being detected. When inside a system, it will make changes to the Windows registry and drop malicious files onto the system. VirTool:WinNT/Rootkitdrv.HS may also slow down the operations of a system and cause it to crash. VirTool:WinNT/Rootkitdrv.HS is a security risk that should be extinguished from a compromised machine immediately after it is detected.


15 security vendors flagged this file as malicious.

Anti-Virus Software Detection
Fortinet W32/Tiny.A!tr.rkit
eSafe Win32.Tiny.A.Rkit
McAfee Artemis!68857466541B
Fortinet W32/Agent.GGYM!tr
AhnLab-V3 Malware/Win32.Inno
AntiVir DR/StartPage.agyh.5
DrWeb Trojan.Siggen2.12629
McAfee Artemis!BE8EA443C780
Panda Generic Rootkit
Fortinet W32/ZAccess.C!tr.rkit
AhnLab-V3 Backdoor/Win32.ZAccess
McAfee-GW-Edition Heuristic.BehavesLike.Win32.Suspicious.A
Comodo TrojWare.Win32.Rootkit.ZAccess.A
Kaspersky Rootkit.Win32.ZAccess.c
eSafe Win32.TRRootkit

SpyHunter Detects & Remove VirTool:WinNT/Rootkitdrv.HS

File System Details

VirTool:WinNT/Rootkitdrv.HS may create the following file(s):
# File Name MD5 Detections
1. nc.exe ab41b1e2db77cebd9e2779110ee3915d 743
2. SecuROM.dll 0f176c410f05cd8f7c1268674a21d262 131
3. SoftwareProtection.exe 8ac110d9eea01b33a7cbf614f7f3d2c8 16
4. gloom.sys 68857466541bb1b800d48caf3a79ae83 9
5. L2.exe 40d767b25a2433cb34371740ecee2ad7 9
6. ag02.sys 241b9318dfe7f887da2bb6a1304db829 8
7. update.sys b4f334ee63329e31f5f5a106f1274468 4
8. `.vbe 1ee104ec7956ec629513fab340cdc876 3
9. VVisit.exe 9ac1a518343130e14b0994efcba9f737 3
10. msngserv.exe 00c2be29de6d10ca331890e971621a93 2
11. netbios.sys cc760b29d88869a51d9b7fc3c08e1a3c 2
12. redbook.sys 9ed828b092be4a6df3fa6140c3c1496c 2
13. RegCtrlwow.exe 303f047429d5344c78759eb38ea8a345 2
14. mscms32.dll 6d1c7ccdc56f4c27272ccf6fb7bdcb67 2
15. authz32.dll 36e411823194c0e1fe91b8f75d3a6b4d 2
16. SkyShield.sys 30cbd19534aed6fc0611b3146f7722a2 1
17. ndiswan.sys d618eedfdbe3c753c9bf82611427fad5 1
18. i8042prt.sys 77022784e8da14515d1f09fe38f5e8f9 1
19. api-ms-win-core-handle-l1-1-032.dll 83a2806d43cdd608df238cd802481f2e 1
20. pctuto_353.exe be8ea443c78032bb9ebc8c27d7b195b0 1


Most Viewed