Trojan

Trojan-Downloader.Win32.Miner.rrh (file analysis)

Malware Removal

The Trojan-Downloader.Win32.Miner.rrh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Downloader.Win32.Miner.rrh virus can do?

  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to interact with an Alternate Data Stream (ADS)

Related domains:

soft.srsroot.com

How to determine Trojan-Downloader.Win32.Miner.rrh?


File Info:

crc32: D68B1294
md5: d8312eacf609bbd86dc270fd2e108348
name: D8312EACF609BBD86DC270FD2E108348.mlw
sha1: 9556af75bba9ddcbc7eddbb477ce2ade6ffcf7c7
sha256: 248b9a0e57ed631beb671ca928daf0efc2a5327097a9eddf09ef6c2701be08ec
sha512: b60d253de8596ab4f5a2f933882caba9aa2883bd1bf1fedb7f4a9378786d2361a7b3ef908165e80abca809570bb1af70e31b07d37ab0ab63f3a375aa0bd14789
ssdeep: 24576:DejDKKiDkY2+AhEcy1BirYZqXMrDjUm84QeP3CqkkkkkkkCC:DeUDeyLZqcn3C9
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Downloader.Win32.Miner.rrh also known as:

K7AntiVirusTrojan-Downloader ( 0053ab491 )
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.2961
CynetMalicious (score: 100)
CAT-QuickHealTrojan.CoinMiner.S3433757
ALYacApplication.BitCoinMiner.AFQ
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanDownloader:Win32/Miner.f081ddc9
K7GWTrojan-Downloader ( 0053ab491 )
Cybereasonmalicious.cf609b
CyrenW32/S-28704938!Eldorado
SymantecTrojan Horse
ESET-NOD32Win32/TrojanDownloader.Agent.EDF
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Miner.rrh
BitDefenderApplication.BitCoinMiner.AFQ
NANO-AntivirusTrojan.Win32.BtcMine.fhluwp
MicroWorld-eScanApplication.BitCoinMiner.AFQ
TencentMalware.Win32.Gencirc.10b0d21d
Ad-AwareApplication.BitCoinMiner.AFQ
SophosGeneric ML PUA (PUA)
ComodoApplication.Win32.CoinMiner.EDF@7ui0as
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.th
FireEyeGeneric.mg.d8312eacf609bbd8
EmsisoftApplication.BitCoinMiner.AFQ (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Script.Gen
AviraHEUR/AGEN.1117929
MicrosoftTrojan:Win32/CoinMiner!rfn
GDataApplication.BitCoinMiner.AFQ
AhnLab-V3Unwanted/Win32.Miner.R233755
Acronissuspicious
McAfeePUP-HCW
MAXmalware (ai score=99)
VBA32TrojanDownloader.Miner
MalwarebytesRiskWare.BitCoinMiner.Generic
PandaTrj/CI.A
YandexTrojan.BtcMine!ozq75uzOWo8
IkarusTrojan.Win32.CoinMiner
FortinetW32/Agent.EDF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Downloader.Win32.Miner.rrh?

Trojan-Downloader.Win32.Miner.rrh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment