One of my rigs stopped mining earlier today. Turned out it was Windows Defender that moved the PhoenixMiner.exe into the quarantine categorised as "Trojan:Win32/Tilken.B!cl"
Did restore the .exe and disabled Windows Defender. The threat in my opinion is Windows Defender, not the miner.
Windows Defender Details:
Trojan:Win32/Tilken.B!cl
Alert level: Severe
Status: Active
Date: 02/05/2018
Recommended action: Remove threat now.
Category: Trojan
Details: This program is dangerous and executes commands from an attacker.
Affected items:
file: C:\dev\Ethereum\PhoenixMiner_2.9e\PhoenixMiner.exe
process: pid:10100,ProcessStart:131683638871312779