Crack

HackTool:Win32/Mimikatz.F removal instruction

Malware Removal

The HackTool:Win32/Mimikatz.F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What HackTool:Win32/Mimikatz.F virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Loads a driver
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ref.tbfull.com

How to determine HackTool:Win32/Mimikatz.F?


File Info:

crc32: CC750B6F
md5: 9c85cfa3f4b38a2d779c3b7804f373f3
name: Server.exe
sha1: 39c705c36f9810363ea385b7fce6c0db2a2a447e
sha256: 0ba424ac6a190bd1dbd5553491e3c8e0b65afbf775691d12ed20966898339383
sha512: 6b537b26ac7451615b0e3a6bd90a5110799b146906b42007546a4850602d9ce7046ab00fb312ca26607cd016dc4b353b4cf064cc7f76aad695b08476fd5204ed
ssdeep: 12288:WXt5s2qGRDipiae2L3I8i03OJ3FPElwo:WXtTyiae+Y8iT1PSwo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

HackTool:Win32/Mimikatz.F also known as:

MicroWorld-eScanDeepScan:Generic.Keylogger.2.441582D6
FireEyeGeneric.mg.9c85cfa3f4b38a2d
McAfeeGenericR-RFJ!9C85CFA3F4B3
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.34367
SangforMalware
BitDefenderDeepScan:Generic.Keylogger.2.441582D6
Cybereasonmalicious.3f4b38
F-ProtW32/Farfli.BI.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
GDataDeepScan:Generic.Keylogger.2.441582D6
KasperskyTrojan.Win32.Cossta.anaq
NANO-AntivirusTrojan.Win32.Farfli.gzeqoe
TencentMalware.Win32.Gencirc.10b84df0
Endgamemalicious (high confidence)
EmsisoftDeepScan:Generic.Keylogger.2.441582D6 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Rootkit.22030
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.MultiPlug.gc
Trapminemalicious.high.ml.score
IkarusPacked.Win32.Hrup
CyrenW32/Farfli.BI.gen!Eldorado
JiangminHeur:TrojanDropper.TDSS
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Cossta
MicrosoftHackTool:Win32/Mimikatz.F
ArcabitDeepScan:Generic.Keylogger.2.441582D6
ZoneAlarmTrojan.Win32.Cossta.anaq
AhnLab-V3Malware/Win32.Generic.C3550084
Acronissuspicious
ALYacDeepScan:Generic.Keylogger.2.441582D6
Ad-AwareDeepScan:Generic.Keylogger.2.441582D6
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Farfli.CTT
RisingBackdoor.Zegost!8.177 (TFE:5:wgNUpI8LvxV)
YandexTrojan.Farfli!MiTK4UWcdlU
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic.AP.34ACC4!tr
BitDefenderThetaAI:Packer.DC9FF45A1F
AVGWin32:BackdoorX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360HEUR/QVM07.1.0C33.Malware.Gen

How to remove HackTool:Win32/Mimikatz.F?

HackTool:Win32/Mimikatz.F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment