Malware

Application.BitCoinMiner.GO removal

Malware Removal

The Application.BitCoinMiner.GO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.BitCoinMiner.GO virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Installs OpenCL library, probably to mine Bitcoins
  • Installs a browser addon or extension
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup

How to determine Application.BitCoinMiner.GO?


File Info:

name: 91E0355D60CB5868616C.mlw
path: /opt/CAPEv2/storage/binaries/0929394df198382c6f531322b8b7a4f4f20cbe40ec4b8351f1c8cf2ecf12f42e
crc32: D6A49174
md5: 91e0355d60cb5868616c9de3d7db78bc
sha1: 181275ed0b560aa397e617d0e4bfd287ea2281e7
sha256: 0929394df198382c6f531322b8b7a4f4f20cbe40ec4b8351f1c8cf2ecf12f42e
sha512: 8e6d42036e26835d82e8de0a86042935787a92c0a7bde13e58ce464cdfb08344a8d89aaf5e54d191f7e90ed669df7fef50363dd60f69f36188f6f918435d7490
ssdeep: 98304:MTbis6QW3BCKfq2TEy8Purs+L7yOftd4Q4UKw9UOgHoAFInN32iFhSAMLVSAz:ibiTbRFlYWglOVd4Qt1fg1FINPFIpV1z
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121663327AD954170F010C5760E6AE379BB762E748C3900A2991EB88DBF74167FE1BB07
sha3_384: d20a62333b26402f134528dedb12ebe12328e7f849d06c5f68253a033193885b79ce9f655fa110f91b0b103418e9d583
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: WinRAR 3.93 pln verze CZ x86 a x64 + CRACK Setup
FileVersion:
LegalCopyright:
ProductName: WinRAR 3.93 pln verze CZ x86 a x64 + CRACK
ProductVersion: for Windows
Translation: 0x0000 0x04b0

Application.BitCoinMiner.GO also known as:

DrWebTrojan.BtcMine.115
FireEyeApplication.BitCoinMiner.GO
ALYacTrojan.Downloader.JQED
CylanceUnsafe
K7AntiVirusTrojan ( 0044c9a01 )
K7GWTrojan ( 0044c9a01 )
SymantecSecurityRisk.BL
ESET-NOD32multiple detections
APEXMalicious
Kasperskynot-a-virus:RiskTool.Win32.BitCoinMiner.dhq
BitDefenderApplication.BitCoinMiner.GO
NANO-AntivirusRiskware.Win32.BitCoinMiner.fofioe
AvastInno:BitCoinMiner-C [Drp]
RisingHackTool.CoinMiner!1.CA68 (CLASSIC)
EmsisoftApplication.BitCoinMiner.GO (B)
ComodoMalware@#13r3muzrrz9xd
BaiduVBS.Trojan.CoinMiner.ak
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.29FR13
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
SophosBitcoin Miner (PUA)
GDataTrojan.Downloader.JQED
eGambitUnsafe.AI_Score_100%
AviraTR/Agent.naedh
Antiy-AVLTrojan/Generic.ASMalwS.35501D
MicrosoftTrojan:Win32/Vigorf.A
McAfeeArtemis!91E0355D60CB
MAXmalware (ai score=81)
VBA32Win32.BitCoinMiner
TrendMicro-HouseCallTROJ_SPNR.29FR13
FortinetRiskware/CoinMiner
AVGInno:BitCoinMiner-C [Drp]
Cybereasonmalicious.d60cb5
PandaTrj/CI.A

How to remove Application.BitCoinMiner.GO?

Application.BitCoinMiner.GO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment