Worm

How to remove “Worm.Win32.Rikihaki.lk”?

Malware Removal

The Worm.Win32.Rikihaki.lk is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm.Win32.Rikihaki.lk virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Worm.Win32.Rikihaki.lk?


File Info:

name: 23602E9F5A13DE19D212.mlw
path: /opt/CAPEv2/storage/binaries/38b7c94f332ebfdf62bc02b1d0398eec42afd3f25c2590f3d056a51c352803c3
crc32: 30B4DA7F
md5: 23602e9f5a13de19d21220ad8836bf50
sha1: dbe818098de5f32318ddf7d5a4c396d7311b11d6
sha256: 38b7c94f332ebfdf62bc02b1d0398eec42afd3f25c2590f3d056a51c352803c3
sha512: b3c1fb63257da5be48e7e5d7c3424f85fe4b09f6c5d15e59c571b0f4ad2dfdf428292e7952dc3a382e3380b94aa8febdf55d698e0b72ad5d0511051c52ec14ef
ssdeep: 6144:SNy6C9RqJFy4+3qAbehLQq2UM7Je4kv0HO883Si5/0pu:cR5hLR2UM7A4S0S3S0/0p
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3A47D10F661D035F0A302FA8AB682F4A8347A704779D4C777D469AE6B786E4ED35B03
sha3_384: d4d2c0a85cf9154398a68174e6ccb67229fe9856cd2d652eb662a3d23de6e031b73725ee14953b9583bcd80a5c452d92
ep_bytes: 558bece8d82a0100e8030000005dc3cc
timestamp: 2014-06-16 11:09:27

Version Info:

0: [No Data]

Worm.Win32.Rikihaki.lk also known as:

DrWebTrojan.KillFiles.14550
MicroWorld-eScanDropped:Trojan.GenericKD.38807079
FireEyeGeneric.mg.23602e9f5a13de19
CAT-QuickHealWorm.Rikihaki.A4
McAfeeW32/Worm-FYO!23602E9F5A13
CylanceUnsafe
K7AntiVirusTrojan ( 00023ea01 )
BitDefenderDropped:Trojan.GenericKD.38807079
K7GWTrojan ( 00023ea01 )
Cybereasonmalicious.f5a13d
BitDefenderThetaAI:Packer.0585414E1F
VirITTrojan.Win32.Agent4.BXTR
CyrenW32/S-4112289e!Eldorado
SymantecTrojan.Tinba
ESET-NOD32Win32/Agent.NPZ
TrendMicro-HouseCallWORM_RIKIHAKI.SM
KasperskyWorm.Win32.Rikihaki.lk
NANO-AntivirusTrojan.Win32.KillFiles.didhhl
RisingWorm.Rikihaki!1.A2F0 (RDMK:cmRtazoGft/pxGxnLZDFNUfRmQen)
EmsisoftDropped:Trojan.GenericKD.38807079 (B)
ComodoWorm.Win32.Rikihaki.A@5sbndo
BaiduWin32.Worm.Agent.fw
ZillyaWorm.Agent.Win32.28025
TrendMicroWORM_RIKIHAKI.SM
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gh
SophosML/PE-A + Mal/Zusy-A
IkarusWorm.Win32.Agent
AviraHEUR/AGEN.1119489
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftWorm:Win32/Rikihaki.A
ZoneAlarmWorm.Win32.Rikihaki.lk
GDataDropped:Trojan.GenericKD.38807079
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R148972
VBA32BScope.Trojan.KillFiles
ALYacDropped:Trojan.GenericKD.38807079
MAXmalware (ai score=86)
MalwarebytesWorm.Agent
PandaTrj/Genetic.gen
APEXMalicious
YandexWorm.Agent!cazTjFK00UQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NQD!worm
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Worm.Win32.Rikihaki.lk?

Worm.Win32.Rikihaki.lk removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment