Risk

RiskTool.Win32.BitCoinMiner.ojln information

Malware Removal

The RiskTool.Win32.BitCoinMiner.ojln is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.BitCoinMiner.ojln virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner02 malware family

How to determine RiskTool.Win32.BitCoinMiner.ojln?


File Info:

name: 5D40C909C0ACB33DF51D.mlw
path: /opt/CAPEv2/storage/binaries/cd2e6bb932c0e6ee3bf721db74fb2ace59e08a2df5c4d8675488da156ebaddf1
crc32: CF71312F
md5: 5d40c909c0acb33df51d9855ff055fd9
sha1: e4b4252263b7c87e4b2eb2c6b9f7f8f2bedb81bb
sha256: cd2e6bb932c0e6ee3bf721db74fb2ace59e08a2df5c4d8675488da156ebaddf1
sha512: 1fea71e544704ed1928dbcb81167b89c5b0e8b099734201563b1959a0dc3139d1c9a157b894038fc6aaa2e8f2d20a4678fae30e23bc70fa6ff357b30b29b79e6
ssdeep: 49152:HDX63h1gaIVab7DnWgd5KFbwTuq9vc9ettxE:TAgfV2n3MA9vc4ttxE
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1F17533088F27D71BF47DA93503B95F093D7CF9D0588A398F966490D0C2AA54287ABF6C
sha3_384: 9443c87d1650370b4abfb764d819a3d91848916a30ccfd8cf540721302aa302bbda5bce3ce56583cc9fa71963a4acc01
ep_bytes: 53565755488d35c5b6e6ff488dbe00f0
timestamp: 2021-11-26 12:05:39

Version Info:

0: [No Data]

RiskTool.Win32.BitCoinMiner.ojln also known as:

LionicRiskware.Win32.BitCoinMiner.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Miner.24
FireEyeGeneric.mg.5d40c909c0acb33d
ALYacGen:Variant.Application.Miner.24
CylanceUnsafe
K7AntiVirusAdware ( 0055f7d61 )
AlibabaRiskWare:Win64/BitCoinMiner.d0ffcb7b
K7GWAdware ( 0055f7d61 )
Cybereasonmalicious.9c0acb
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.QG potentially unwanted
APEXMalicious
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.ojln
BitDefenderGen:Variant.Application.Miner.24
AvastFileRepMalware
TencentWin32.Risk.Bitcoinminer.Sxem
Ad-AwareGen:Variant.Application.Miner.24
SophosXMRig Miner (PUA)
McAfee-GW-EditionBehavesLike.Win64.Trickbot.tc
EmsisoftGen:Variant.Application.Miner.24 (B)
IkarusTrojan.Win64.CoinMiner
GDataGen:Variant.Application.Miner.24
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1140227
GridinsoftRansom.Win64.Gen.sa
ArcabitTrojan.Application.Miner.24
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Miner3.Exp
Acronissuspicious
McAfeeArtemis!5D40C909C0AC
MAXmalware (ai score=74)
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallTROJ_GEN.R002H0CKT21
RisingHackTool.XMRMiner!1.C2EC (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Miner
AVGFileRepMalware
PandaTrj/CI.A

How to remove RiskTool.Win32.BitCoinMiner.ojln?

RiskTool.Win32.BitCoinMiner.ojln removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment