Risk

What is “RiskTool.Win32.BitCoinMiner.vho”?

Malware Removal

The RiskTool.Win32.BitCoinMiner.vho is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.BitCoinMiner.vho virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Anomalous binary characteristics

How to determine RiskTool.Win32.BitCoinMiner.vho?


File Info:

crc32: C976F0B6
md5: 62bfb416893b576b8081f275e6be9ab9
name: cpu64.exe
sha1: 6e9491222f0b515e97121ea160d8623c3ff4b97f
sha256: fdb3e437c3852632356e56fe5630eb81bd1e3ebd019115280dbd497f5a946167
sha512: 81028b718fe982943ce9a0650a9527d8d82fd9d179b08414bcaf04745a47c4397abf9f2cdfaace964f23362895095acbfabb4108409eeb3644f98a70dce23a7c
ssdeep: 12288:blek7VIjqS/AttnfMznf81aW56jmi4EAEKw46Ye/WOw6iuex082+ueN3R7:1fKE8WHEm6Yjjduex082+VNh
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: alipay.com. All rights reserved.
MIMEType: application/npalicdo
InternalName: npalicdo
FileVersion: 1, 0, 0, 4
CompanyName: alipay.com
FileOpenName: npalicdo
FileExtents: dll
ProductName: npalicdo plugin
ProductVersion: 1, 0, 0, 4
FileDescription: npalicdo
OriginalFilename: npalicdo.dll
Translation: 0x0409 0x04e4

RiskTool.Win32.BitCoinMiner.vho also known as:

MicroWorld-eScanTrojan.GenericKDZ.65744
FireEyeGeneric.mg.62bfb416893b576b
CAT-QuickHealPUA.WacatacRI.S9539263
McAfeeRDN/Generic PUP.z
SangforMalware
BitDefenderTrojan.GenericKDZ.65744
F-ProtW64/S-f46b57c9!Eldorado
APEXMalicious
AvastWin64:CoinminerX-gen [Trj]
GDataTrojan.GenericKDZ.65744
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
TencentMalware.Win32.Gencirc.10b9ed02
Ad-AwareTrojan.GenericKDZ.65744
SophosTroj/Agent-BCPO
DrWebTool.BtcMine.2239
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win64.Trojan.cc
Trapminemalicious.high.ml.score
EmsisoftApplication.Generic (A)
IkarusTrojan.Win64.CoinMiner
CyrenW64/S-f46b57c9!Eldorado
JiangminRiskTool.Generic.pkx
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (moderate confidence)
ArcabitTrojan.Generic.D100D0
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
MicrosoftPUA:Win32/CoinMiner
AhnLab-V3Unwanted/Win64.RL_CoinMiner.R304048
Acronissuspicious
ALYacTrojan.GenericKDZ.65744
MAXmalware (ai score=85)
MalwarebytesRiskWare.BitCoinMiner
ESET-NOD32a variant of Win64/CoinMiner.PQ potentially unwanted
RisingTrojan.Win32/64.XMR-Miner!1.ADCC (TFE:dGZlOgVsTxqL129xAg)
SentinelOneDFI – Suspicious PE
FortinetW64/CoinMiner.X!tr
AVGWin64:CoinminerX-gen [Trj]

How to remove RiskTool.Win32.BitCoinMiner.vho?

RiskTool.Win32.BitCoinMiner.vho removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment