Risk

Win64/Riskware.Mimikatz.I malicious file

Malware Removal

The Win64/Riskware.Mimikatz.I is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win64/Riskware.Mimikatz.I virus can do?

  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs

How to determine Win64/Riskware.Mimikatz.I?


File Info:

crc32: 55A89E4B
md5: 5cdd3d17670836a08d54afa1d61881d7
name: zipa.exe
sha1: 965a5b93280f77fe44b400b4bf05935a3d065694
sha256: 743369a9c08970d1c7f7b4162c335984ac9073526f66be6d3480479dd802d3a5
sha512: b15fecab2534e4b14eb30b1ceed6b68cefaf8b42b2ceb75d7cfc5d518fd3b1097260571a027bdf2473522abc80eb26a0ac4df4c80ccd92c169059e5e00372a71
ssdeep: 49152:OwrAQoL1Uhjcx2iRmzNOaB7nBhY9tV8nrnMl9Ms3zz7cLD1OY2ZNUx+o03CIi6s:OoAQy1UhjAx4zUa7nBi78rMl9Ms/ALM
type: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win64/Riskware.Mimikatz.I also known as:

FireEyeGeneric.mg.5cdd3d17670836a0
McAfeeArtemis!5CDD3D176708
CylanceUnsafe
AegisLabTrojan.BAT.Agent.b!c
SangforMalware
K7AntiVirusTrojan ( 0051918e1 )
BitDefenderTrojan.GenericKD.33279321
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.3280f7
APEXMalicious
ClamAVWin.Malware.Winlock-6913733-0
KasperskyTrojan-Dropper.BAT.Agent.eb
AlibabaTrojanDropper:BAT/Mimikatz.134204f8
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqHcFXbRlV75nKR42N8+ZCK)
Ad-AwareTrojan.GenericKD.33279321
EmsisoftTrojan.GenericKD.33279321 (B)
F-SecureMalware.BAT/Disabler.iwwix
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosMimikatz Exploit Utility (PUA)
AviraBAT/Disabler.iwwix
Endgamemalicious (moderate confidence)
ZoneAlarmTrojan-Dropper.BAT.Agent.eb
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34090.!oGfaObkKvm
MalwarebytesTrojan.Injector
ESET-NOD32a variant of Win64/Riskware.Mimikatz.I
TencentMalware.Win32.Gencirc.10b44ca8
IkarusPUA.Generic
eGambitUnsafe.AI_Score_99%
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.Dropper.95c

How to remove Win64/Riskware.Mimikatz.I?

Win64/Riskware.Mimikatz.I removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment