Risk

About “UDS:RiskTool.MSIL.BitMiner” infection

Malware Removal

The UDS:RiskTool.MSIL.BitMiner is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:RiskTool.MSIL.BitMiner virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Installs OpenCL library, probably to mine Bitcoins
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine UDS:RiskTool.MSIL.BitMiner?


File Info:

name: D8083F8637BFA852E75A.mlw
path: /opt/CAPEv2/storage/binaries/318f726374f3d17307a28b5f2676fdb94e3122374446324d9c39192a7bbcfed1
crc32: 3DB5D920
md5: d8083f8637bfa852e75a560133f86281
sha1: 9c2e9ead7dd593a67a22744044ca929ec0fcca5c
sha256: 318f726374f3d17307a28b5f2676fdb94e3122374446324d9c39192a7bbcfed1
sha512: abdd2f4295b20e9251ff65f138358b078d2db1591d09d3abca3277a4b0bf38496ae5931bc6837f19cd6c2a2dff27284376e1318930210bb3326906313340b786
ssdeep: 98304:vgwRC+TbgBheTGU5ImoPC+m4dXTHVLbXfhtfFL+MolVGGLjR8WhztuEIc2YZWyyS:vg5++hq95OPC6VV/PLFC1G8R8WV8mUS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1115633E1BAF33DB4F554203274581AAC2BFB5D59171C04A3AF4AFE8A64646C142F8E87
sha3_384: 77396cf154fc15c21b01c046176b635849130544f1cf09bb9f427c2627a7035533280b85d5358b22e9fc80d91a8452fb
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

UDS:RiskTool.MSIL.BitMiner also known as:

FireEyeTrojan.GenericKD.35717386
CAT-QuickHealTrojan.IGENERIC
ALYacTrojan.GenericKD.44957617
CylanceUnsafe
K7AntiVirusAdware ( 005749d21 )
AlibabaRiskWare:MSIL/Miners.b92a8079
K7GWAdware ( 005749d21 )
CyrenW64/Trojan.OFQZ-3117
SymantecPUA.Gen.2
ESET-NOD32a variant of MSIL/CoinMiner.AA potentially unwanted
APEXMalicious
Kasperskynot-a-virus:UDS:RiskTool.MSIL.BitMiner.gen
BitDefenderTrojan.GenericKD.35717386
NANO-AntivirusRiskware.Win32.BtcMine.iohxit
AvastWin32:Malware-gen
SophosGeneric Reputation PUA (PUA)
DrWebTool.BtcMineNET.2
VIPRETrojan.Win32.Generic!BT
TrendMicroPUA.Win64.NiceHashMiner.I.component
McAfee-GW-EditionCoinMiner-FBG
EmsisoftTrojan.GenericKD.35717386 (B)
GDataMSIL.Application.NiceHashMiner.A (43x)
Antiy-AVLTrojan/Generic.ASMalwFH.5682BB6
MicrosoftPUA:Win32/Vigua.A
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4198781
McAfeeArtemis!D8083F8637BF
MAXmalware (ai score=85)
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallPUA.Win64.NiceHashMiner.I.component
RisingHackTool.CoinMiner!1.D742 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.117109451.susgen
FortinetW32/BtcMineNET.2!tr
AVGWin32:Malware-gen
Cybereasonmalicious.637bfa
PandaTrj/CI.A

How to remove UDS:RiskTool.MSIL.BitMiner?

UDS:RiskTool.MSIL.BitMiner removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment