Trojan

Trojan:Win64/DisguisedXMRigMiner malicious file

Malware Removal

The Trojan:Win64/DisguisedXMRigMiner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win64/DisguisedXMRigMiner virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Trojan:Win64/DisguisedXMRigMiner?


File Info:

crc32: 97F259EA
md5: 38c43f741dc69d30780e0b4b2e88adc1
name: 38C43F741DC69D30780E0B4B2E88ADC1.mlw
sha1: b6bb8fef8119b1216b02e716e58cd42c68cdb501
sha256: 4e90d96e739fb06f3c7738ab74f3c4567925a418dcf8429d2002b1571ce266a6
sha512: eadac4a49209fd74a1ec9626df9891532ecd7e28f94552e796be3198269e1092a83e55b0d7b5deef442632246b91527d3a548ffe168a9dcbc43efb803a55fbb6
ssdeep: 6144:h5Wj/bK5hZneFnzOLm1zPqq64/t3fA2KXzV4FMi1+rkR10efUK:XW7bKxIzQUbDFaV4eg+Qztf
type: PE32+ executable (console) x86-64, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: SearchIndexer.exe
FileVersion: 7.0.19041.34 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Windowsxae Search
ProductVersion: 7.0.19041.34
FileDescription: Microsoft Windows Search Indexer
OriginalFilename: SearchIndexer.exe
Translation: 0x0409 0x04b0

Trojan:Win64/DisguisedXMRigMiner also known as:

LionicTrojan.Win32.Miner.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacTrojan.GenericKDZ.73199
CylanceUnsafe
SangforCoinMiner.Win32.Miner.gen
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win64/Miners.82cf5ad5
Cybereasonmalicious.41dc69
CyrenW64/Trojan.HYFP-1547
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/CoinMiner.CY potentially unwanted
APEXMalicious
AvastWin64:CoinminerX-gen [Trj]
ClamAVWin.Trojan.Miner-9835754-0
KasperskyHEUR:Trojan.Win32.Miner.gen
BitDefenderTrojan.GenericKDZ.73199
NANO-AntivirusTrojan.Win64.Miner.iuzmfc
MicroWorld-eScanTrojan.GenericKDZ.73199
TencentWin32.Trojan.Miner.Lmky
Ad-AwareTrojan.GenericKDZ.73199
SophosGeneric PUA LG (PUA)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WK321
McAfee-GW-EditionBehavesLike.Win64.Fake.gc
FireEyeGeneric.mg.38c43f741dc69d30
EmsisoftTrojan.GenericKDZ.73199 (B)
JiangminTrojan.Miner.odb
AviraHEUR/AGEN.1137162
Antiy-AVLTrojan/Generic.ASBOL.C5E3
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win64/DisguisedXMRigMiner
GDataTrojan.GenericKDZ.73199
AhnLab-V3Trojan/Win64.CoinMiner.C4344951
McAfeeGenericRXAA-AA!38C43F741DC6
MAXmalware (ai score=83)
VBA32Trojan.Miner
MalwarebytesTrojan.BitCoinMiner
PandaTrj/CI.A
YandexTrojan.GenAsa!hNDKU9hr3EM
IkarusTrojan.Win64.CoinMiner
MaxSecureTrojan.Malware.11387115.susgen
FortinetAdware/Miner
AVGWin64:CoinminerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win64/Miner.Coinminer.H8oANncA

How to remove Trojan:Win64/DisguisedXMRigMiner?

Trojan:Win64/DisguisedXMRigMiner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment