Home Malware Programs Rootkits TR/Rootkit.Gen2

TR/Rootkit.Gen2

Posted: December 28, 2011

Threat Metric

Threat Level: 8/10
Infected PCs: 1,052
First Seen: December 28, 2011
Last Seen: December 31, 2020
OS(es) Affected: Windows

TR/Rootkit.Gen2 is a dangerous rootkit parasite for the PC that utilizes methods that modify a system's Master Boot Record (MBR) allowing the infection to take over the system. A system infected with TR/Rootkit.Gen2 is susceptible to being compromised while other malware may be loaded all without the interaction of the computer user. Generally TR/Rootkit.Gen2 is nearly impossible to remove manually which is why an updated antispyware program must be utilized to successfully delete the TR/Rootkit.Gen2 parasite.

Aliases

Trj/OCJ.C [Panda]Hider.STP [AVG]W32/Rootkit_Kryptik.RU [Fortinet]Artemis!DC441FC394D2 [McAfee]Agent3.AWLG [AVG]Mal/ZAccess-C [Sophos]Generic BackDoor!d2o [McAfee-GW-Edition]Trojan.Rootkit-3753 [ClamAV]Win32:Zeroot [Rtk] [Avast]Win32/Sirefef.DM [NOD32]ZeroAccess.r [McAfee]Hider.USU [AVG]BackDoor.Maxplus [DrWeb]Mal/Generic-S [Sophos]Win32:Sirefef-AYM [Rtk] [Avast]
More aliases (286)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\drivers\dfsc.sys File name: dfsc.sys
Size: 75.26 KB (75264 bytes)
MD5: f7f11e66abf5c225437cb8bf219564a4
Detection count: 75
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: July 30, 2013
%WINDIR%\abasee.sys File name: abasee.sys
Size: 8.7 KB (8704 bytes)
MD5: 8b8bfe4a0668e827528a772413ff58d1
Detection count: 52
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%
Group: Malware file
Last Updated: July 30, 2012
%WINDIR%\System32\drivers\tdx.sys File name: tdx.sys
Size: 72.19 KB (72192 bytes)
MD5: 597e080592f0128623d21c0ad071f280
Detection count: 43
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 10, 2012
%WINDIR%\System32\drivers\ipsec.sys File name: ipsec.sys
Size: 75.26 KB (75264 bytes)
MD5: 4eb0d03142d98d9145d834fc32ab91b9
Detection count: 30
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 1, 2012
%WINDIR%\system32\drivers\18102.sys File name: 18102.sys
Size: 61.56 KB (61568 bytes)
MD5: dc441fc394d28d0aaf897412a3c2cad5
Detection count: 24
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\drivers
Group: Malware file
Last Updated: April 29, 2013
%WINDIR%\System32\drivers\netbt.sys File name: netbt.sys
Size: 162.81 KB (162816 bytes)
MD5: 8c90505c642dfd8d63236cd7e59c111e
Detection count: 19
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 26, 2012
%WINDIR%\System32\drivers\afd.sys File name: afd.sys
Size: 138.49 KB (138496 bytes)
MD5: 019e4406ea95f682d601b4180de098b6
Detection count: 19
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: March 26, 2012
%WINDIR%\System32\drivers\dfsc.sys File name: dfsc.sys
Size: 78.33 KB (78336 bytes)
MD5: 38523be01eb6165df02199af46a6c04a
Detection count: 19
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 17, 2012
%WINDIR%\System32\drivers\cdrom.sys File name: cdrom.sys
Size: 108.54 KB (108544 bytes)
MD5: 386f5af2eb9ed07dfe58a6550293db8c
Detection count: 19
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: May 4, 2012
%WINDIR%\System32\drivers\smb.sys File name: smb.sys
Size: 66.56 KB (66560 bytes)
MD5: 95e9030e4d9f28e92f2915f47b4859a1
Detection count: 16
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: November 19, 2012
%WINDIR%\System32\drivers\netbt.sys File name: netbt.sys
Size: 162.81 KB (162816 bytes)
MD5: acc367db6058f3fae97201fd6b553b51
Detection count: 12
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: May 30, 2014
%WINDIR%\System32\drivers\mrxsmb.sys File name: mrxsmb.sys
Size: 454.01 KB (454016 bytes)
MD5: 4938666bd0af200025aba945047d1c52
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: February 13, 2012
%WINDIR%\System32\drivers\afd.sys File name: afd.sys
Size: 273.4 KB (273408 bytes)
MD5: 7c98aa643eab5a0eabc786239db07993
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 19, 2012
%WINDIR%\System32\drivers\cdrom.sys File name: cdrom.sys
Size: 49.53 KB (49536 bytes)
MD5: 608876dd82ed880c6e65f146c9c7a6ec
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 1, 2012
%WINDIR%\System32\DRIVERS\i8042prt.sys File name: i8042prt.sys
Size: 53.5 KB (53504 bytes)
MD5: 7b187f8fd0f8be0c59d5726213fa5552
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: April 17, 2013
%WINDIR%\system32\Drivers\bsbxdefc.sys File name: bsbxdefc.sys
Size: 91.64 KB (91648 bytes)
MD5: 1042058c8549bdaba98eb54e4c8ef41c
Detection count: 5
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\system32\Drivers
Group: Malware file
Last Updated: March 1, 2013
%Documents and Settings%\All Users\Application Data iosejgfse.dll File name: %Documents and Settings%\All Users\Application Data iosejgfse.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
%Temp%\mswinsck.exe File name: %Temp%\mswinsck.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

More files

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_CLASSES_ROOT\secfile
Loading...