Risk

RiskTool.Win64.XMRigMiner.kh malicious file

Malware Removal

The RiskTool.Win64.XMRigMiner.kh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win64.XMRigMiner.kh virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the CoinMiner02 malware family

How to determine RiskTool.Win64.XMRigMiner.kh?


File Info:

name: AF7A8BB6AC7C550998F1.mlw
path: /opt/CAPEv2/storage/binaries/15de8992eeac6cad15a17b31a929bc9b7414a315e7315250dcfa04965623a661
crc32: 5A96DF62
md5: af7a8bb6ac7c550998f1d1c76c209690
sha1: c541b74de7820cb3b7c83df62b5c1c23103376a5
sha256: 15de8992eeac6cad15a17b31a929bc9b7414a315e7315250dcfa04965623a661
sha512: ccceef9cfcaa7752944e3969b2f9a41d108977d5d8d809090039e4e1f62f1a4368a459848daf1893581453489312dd0f15c5c62222e15a593b9cdf9b299b7397
ssdeep: 24576:by+jMkaTDtuF6kYK2MS6+wxaD21EtYlsVVRylcOJLrTkHurKg:byFkaTDtuMkxrU3t9icaLMur
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T138452342E6E4EC32E93F93765105AF6EDE54B52687CE833CFA7C406E8F7461210467A2
sha3_384: 05f28f8051a0170b7bf6b6dfbeeccda475883f641748cce81c0b1e3df242836c1ade4a3ba24d6fb01f9266dbca20dca9
ep_bytes: 53565755488d351acaedff488dbedb7f
timestamp: 2020-08-20 06:12:10

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectX Setup
FileVersion: 4.9.0.0904
InternalName: dxsetup.exe
LegalCopyright: Copyright (C) Microsoft Corporation. All rights reserved.
OriginalFilename: dxsetup.exe
ProductName: Microsoft(R) DirectX for Windows(R)
ProductVersion: 4.9.0.0904
Translation: 0x0411 0x04b0

RiskTool.Win64.XMRigMiner.kh also known as:

MicroWorld-eScanTrojan.GenericKDZ.71553
FireEyeGeneric.mg.af7a8bb6ac7c5509
ALYacTrojan.GenericKDZ.71553
CylanceUnsafe
ZillyaTrojan.Miner.Win32.15865
SangforTrojan.Win32.Save.a
K7AntiVirusCryptoMiner ( 0057f1d61 )
K7GWCryptoMiner ( 0057f1d61 )
Cybereasonmalicious.6ac7c5
CyrenW64/CoinMiner.GS.gen!Eldorado
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win64/CoinMiner.PO potentially unwanted
ClamAVWin.Dropper.Miner-9943640-0
Kasperskynot-a-virus:RiskTool.Win64.XMRigMiner.kh
BitDefenderTrojan.GenericKDZ.71553
CynetMalicious (score: 100)
AvastWin64:Malware-gen
TencentTrojan.Win32.Miner.pa
Ad-AwareTrojan.GenericKDZ.71553
EmsisoftApplication.Generic (A)
DrWebTool.BtcMine.2639
VIPRETrojan.GenericKDZ.71553
McAfee-GW-EditionBehavesLike.Win64.CoinMiner.tc
SentinelOneStatic AI – Malicious PE
Trapminemalicious.moderate.ml.score
SophosTroj/Miner-AEN
APEXMalicious
GDataTrojan.GenericKDZ.71553
JiangminTrojan.Miner.nca
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASCommon.203
MicrosoftTrojan:Win32/Sabsik.TE.A!ml
GoogleDetected
AhnLab-V3Trojan/Win.CoinMiner.R494707
Acronissuspicious
McAfeeCoinMiner-FEK!AF7A8BB6AC7C
MalwarebytesRiskWare.BitCoinMiner
RisingHackTool.CoinMiner!1.CB20 (CLASSIC)
IkarusPUA.CoinMiner
MaxSecureTrojan.Malware.121218.susgen
FortinetRiskware/CoinMiner
AVGWin64:Malware-gen

How to remove RiskTool.Win64.XMRigMiner.kh?

RiskTool.Win64.XMRigMiner.kh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment