Trojan

TrojanPSW.Win64.Mimikatz removal instruction

Malware Removal

The TrojanPSW.Win64.Mimikatz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPSW.Win64.Mimikatz virus can do?

    How to determine TrojanPSW.Win64.Mimikatz?

    
    

    File Info:

    crc32: 54253559
    md5: 40b58a204a87d7792fd699fcc0f87c8d
    name: 40B58A204A87D7792FD699FCC0F87C8D.mlw
    sha1: 115067d0464e05e5d8ec643d276d8a39d67adbac
    sha256: 236cc62c5314bda30f4081db3ca37d758680801e1905150e400e422025d3a22a
    sha512: 8d8203390b4dcd00177d870b0fa8398f11ce2e62f67f61c646aafae06097086fa4c1360e6cedcbcc31df521ac4ed2cf83507286337056ad9a8ffaf8028bc69a7
    ssdeep: 24576:bD/uknRqe0rKq0s+2NmZLtIzRpC6tvwAK0zqTCWfS:UfQEqMRpBtvwgGT
    type: PE32+ executable (console) x86-64, for MS Windows

    Version Info:

    LegalCopyright: Copyright (c) 2007 - 2020 gentilkiwi (Benjamin DELPY)
    InternalName: mimikatz
    FileVersion: 2.2.0.0
    CompanyName: gentilkiwi (Benjamin DELPY)
    PrivateBuild: Build with love for POC only
    ProductName: mimikatz
    SpecialBuild: :)
    ProductVersion: 2.2.0.0
    FileDescription: mimikatz for Windows
    OriginalFilename: mimikatz.exe
    Translation: 0x0409 0x04b0

    TrojanPSW.Win64.Mimikatz also known as:

    K7AntiVirusHacktool ( 0043c1591 )
    Elasticmalicious (high confidence)
    DrWebTool.Mimikatz.1015
    CynetMalicious (score: 100)
    ALYacGen:Heur.Mimikatz.1
    CylanceUnsafe
    SangforHacktool.Win32.Mimikatz.D
    CrowdStrikewin/malicious_confidence_100% (W)
    AlibabaHackTool:Win32/Mimikatz.47b2595f
    K7GWHacktool ( 0043c1591 )
    Cybereasonmalicious.04a87d
    CyrenW64/S-b61adc75!Eldorado
    SymantecHacktool.Mimikatz
    ESET-NOD32a variant of Win64/Riskware.Mimikatz.D
    APEXMalicious
    AvastWin64:Malware-gen
    ClamAVWin.Trojan.Mimikatz-6466236-0
    KasperskyHEUR:Trojan-PSW.Win64.Mimikatz.gen
    BitDefenderGen:Heur.Mimikatz.1
    MicroWorld-eScanGen:Heur.Mimikatz.1
    TencentTrojan.Win64.Mimikatz.a
    Ad-AwareGen:Heur.Mimikatz.1
    SophosTroj/Mimkatz-AE
    VIPRETrojan.Win32.Generic!BT
    TrendMicroHKTL_MIMIKATZ64
    McAfee-GW-EditionBehavesLike.Win64.Rootkit.th
    FireEyeGeneric.mg.40b58a204a87d779
    EmsisoftGen:Heur.Mimikatz.1 (B)
    SentinelOneStatic AI – Malicious PE
    JiangminTrojan.PSW.Mimikatz.cna
    WebrootW32.Hacktool.Gen
    AviraHEUR/AGEN.1141388
    eGambithacktool.mimikatz
    Antiy-AVLTrojan/Generic.ASMalwS.324AE35
    MicrosoftHackTool:Win32/Mimikatz.D
    GridinsoftRisk.Win64.Gen.dd!i
    ArcabitTrojan.Mimikatz.1
    AegisLabTrojan.Win64.Mimikatz.i!c
    ZoneAlarmHEUR:Trojan-PSW.Win64.Mimikatz.gen
    GDataGen:Heur.Mimikatz.1
    AhnLab-V3Trojan/Win64.Mimikatz.R285461
    Acronissuspicious
    McAfeeHTool-MimiKatz!40B58A204A87
    MAXmalware (ai score=89)
    VBA32TrojanPSW.Win64.Mimikatz
    MalwarebytesGeneric.Trojan.Malicious.DDS
    PandaHackingTool/Mimikatz
    TrendMicro-HouseCallHKTL_MIMIKATZ64
    RisingTrojan.Tiggre!8.ED98 (CLOUD)
    IkarusHackTool.Mimikatz
    FortinetRiskware/Mimikatz
    AVGWin64:Malware-gen
    Paloaltogeneric.ml

    How to remove TrojanPSW.Win64.Mimikatz?

    TrojanPSW.Win64.Mimikatz removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment