Worm

Should I remove “Worm.Win32.Rikihaki.fh”?

Malware Removal

The Worm.Win32.Rikihaki.fh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Rikihaki.fh virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Worm.Win32.Rikihaki.fh?


File Info:

name: 36FD175C19E470C74F04.mlw
path: /opt/CAPEv2/storage/binaries/266ec8bec2be70c498a60c651c2e3fe7d359734922e6c8dc21720a62791a9603
crc32: 51387ED4
md5: 36fd175c19e470c74f04848f209d025f
sha1: e702f6eaa8f6a93be825be86be4d8cd12e9e6211
sha256: 266ec8bec2be70c498a60c651c2e3fe7d359734922e6c8dc21720a62791a9603
sha512: 426103a515161f38d8cd66d5c4adee7fe8a7d0aca5990d3261b2a837372b3249662afff1701118b9839345975fe59f07e836c5e1b677da9b5dde27a68f1c3a5f
ssdeep: 6144:SNy6C9RVW0WRvZLAVAbehLQq2UM7Je4kv0HO883Si5/0G:u0GAHhLR2UM7A4S0S3S0/0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178A47D10F662D035F0B302F68BBAC2F4A9347A70077984C777D469AE6B686E4AD35713
sha3_384: b61a8f5bfeb6570845bb37a580ca96b7aa6f3e3bca107d549764106951c3e193219fe5a444ec52b6c751c95374be2fab
ep_bytes: 558bece8d82a0100e8030000005dc3cc
timestamp: 2014-06-16 11:09:27

Version Info:

0: [No Data]

Worm.Win32.Rikihaki.fh also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Backdoor.ShadowWali.1
FireEyeGeneric.mg.36fd175c19e470c7
CAT-QuickHealWorm.Rikihaki.A4
ALYacGen:Variant.Backdoor.ShadowWali.1
CylanceUnsafe
ZillyaWorm.Agent.Win32.28025
K7AntiVirusTrojan ( 00023ea01 )
BitDefenderGen:Variant.Backdoor.ShadowWali.1
K7GWTrojan ( 00023ea01 )
Cybereasonmalicious.c19e47
BitDefenderThetaAI:Packer.0585414E1F
VirITTrojan.Win32.Agent4.BXTR
CyrenW32/S-4112289e!Eldorado
SymantecTrojan.Tinba
ESET-NOD32Win32/Agent.NPZ
BaiduWin32.Worm.Agent.fw
TrendMicro-HouseCallWORM_RIKIHAKI.SM
KasperskyWorm.Win32.Rikihaki.fh
NANO-AntivirusTrojan.Win32.KillFiles.didhhl
RisingWorm.Rikihaki!1.A2F0 (RDMK:cmRtazoGft/pxGxnLZDFNUfRmQen)
SophosML/PE-A + Mal/Zusy-A
ComodoWorm.Win32.Rikihaki.A@5sbndo
DrWebTrojan.KillFiles.14550
TrendMicroWORM_RIKIHAKI.SM
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Backdoor.ShadowWali.1 (B)
APEXMalicious
AviraHEUR/AGEN.1119489
Antiy-AVLTrojan/Generic.ASMalwS.AAB6CF
MicrosoftWorm:Win32/Rikihaki.A
GDataGen:Variant.Backdoor.ShadowWali.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R148972
McAfeeW32/Worm-FYO!36FD175C19E4
MAXmalware (ai score=86)
VBA32BScope.Trojan.KillFiles
MalwarebytesWorm.Agent
PandaTrj/Genetic.gen
IkarusWorm.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NQD!worm
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Worm.Win32.Rikihaki.fh?

Worm.Win32.Rikihaki.fh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment