Categories: Risk

RiskTool.Win32.BitCoinMiner.hzmk removal instruction

The RiskTool.Win32.BitCoinMiner.hzmk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.BitCoinMiner.hzmk virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine RiskTool.Win32.BitCoinMiner.hzmk?


File Info:

name: 6D2044A5DB651D39CB0C.mlwpath: /opt/CAPEv2/storage/binaries/41953a96f90035f5dc36a26307f3547571409c856e73d3c412b6ec8e124740d1crc32: ABA04984md5: 6d2044a5db651d39cb0c7c8c426ed7b9sha1: 03ecadc8933d0a96b3442bc0e86e74f51e454ac7sha256: 41953a96f90035f5dc36a26307f3547571409c856e73d3c412b6ec8e124740d1sha512: 730909385f09e111c76fb17fa8d84464fdd8ddbc4f2a854806d0ffad0c68c8ea72faada9d2a11ffb27d7ab7b21464c2558176881426e8bd76c22d77c81a1a01cssdeep: 24576:KmybldIbRNIj4lg3uxWvM56r2UHGf58H3LAHdEjJD73/bS/I:gp4RNIAxt6rVHk8HbAHix73/bbtype: PE32 executable (console) Intel 80386, for MS Windowstlsh: T148755B4BF9161AAFCE1257F08CE7F37B9328327991238F6EDD144C28A737B46551620Asha3_384: 3c7a0af24e4192e5ca341d5e2a673084f3e81c9cb2be79b17bf4c49d1c2a38fa0211f494006e4f56603b2e00773e3a39ep_bytes: 83ec1cc7042401000000ff15aca74900timestamp: 2013-09-19 04:39:34

Version Info:

0: [No Data]

RiskTool.Win32.BitCoinMiner.hzmk also known as:

Lionic Riskware.Win32.BitCoinMiner.1!c
Elastic malicious (high confidence)
ALYac Adware.GenericKD.48080648
Cylance Unsafe
VIPRE VirTool.Win32.Obfuscator.hg!b1 (v)
Sangfor CoinMiner.Win32.BitCoinMiner.JV
K7AntiVirus Unwanted-Program ( 004d38111 )
BitDefender Adware.GenericKD.48080648
K7GW Unwanted-Program ( 004d38111 )
Cybereason malicious.5db651
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/CoinMiner.BW potentially unwanted
Avast Win32:BitCoinMiner-JV [Trj]
Kaspersky not-a-virus:RiskTool.Win32.BitCoinMiner.hzmk
Alibaba RiskWare:Win32/Miners.281f0c34
NANO-Antivirus Riskware.Win32.BitCoinMiner.faokte
ViRobot Adware.Bitcoinminer.1688723
MicroWorld-eScan Adware.GenericKD.48080648
Emsisoft Adware.GenericKD.48080648 (B)
Comodo Malware@#1ug1sd3661uho
DrWeb Tool.BtcMine.144
Zillya Adware.BitCoinMiner.Win32.1
TrendMicro TROJ_GEN.R002C0WAR22
FireEye Generic.mg.6d2044a5db651d39
Sophos Bitcoin Miner (PUA)
Jiangmin RiskTool.BitCoinMiner.gyb
Webroot W32.Bitcoinminer.Gen
Avira PUA/CoinMiner.Gen
MAX malware (ai score=61)
Antiy-AVL Trojan/Generic.ASMalwS.1C772FF
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
ZoneAlarm not-a-virus:HEUR:RiskTool.Win32.CoinMiner.gen
GData Adware.GenericKD.48080648
AhnLab-V3 Trojan/Win32.BitCoinMiner.R94289
McAfee GenericRXAA-AA!6D2044A5DB65
VBA32 BScope.Trojan.Zpevdo
Malwarebytes RiskWare.BitCoinMiner
TrendMicro-HouseCall TROJ_GEN.R002C0WAR22
Yandex Riskware.Agent!BTIiHHwrVsE
Ikarus not-a-virus:RiskTool.Win32
eGambit Unsafe.AI_Score_100%
Fortinet Riskware/CoinMiner
AVG Win32:BitCoinMiner-JV [Trj]
MaxSecure Trojan.Malware.1517434.susgen

How to remove RiskTool.Win32.BitCoinMiner.hzmk?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

What is “MSIL/TrojanDropper.Agent.BVT”?

The MSIL/TrojanDropper.Agent.BVT is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Should I remove “Generic.Dacic.94CCEEA9.A.A4A6DA47”?

The Generic.Dacic.94CCEEA9.A.A4A6DA47 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Malware.AI.524217860 removal tips

The Malware.AI.524217860 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Trojan:Win32/Koutodoor.F removal tips

The Trojan:Win32/Koutodoor.F is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

How to remove “Malware.AI.1412460714”?

The Malware.AI.1412460714 is considered dangerous by lots of security experts. When this infection is active,…

1 day ago

Generic.Dacic.8952383F.A.5EC8C34B removal instruction

The Generic.Dacic.8952383F.A.5EC8C34B is considered dangerous by lots of security experts. When this infection is active,…

1 day ago