Malware

What is “BV:Miner-DG [Trj]”?

Malware Removal

The BV:Miner-DG [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BV:Miner-DG [Trj] virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine BV:Miner-DG [Trj]?


File Info:

name: 2D0E00CFCBEAE79E1844.mlw
path: /opt/CAPEv2/storage/binaries/81611d9cedb94363143b931d7b32aa86b7302e4b597e747ff2a8b98779b12018
crc32: 21226248
md5: 2d0e00cfcbeae79e184408cc403674d1
sha1: 3c308ccde966c5b5166f0bff50c68e22ebff60fa
sha256: 81611d9cedb94363143b931d7b32aa86b7302e4b597e747ff2a8b98779b12018
sha512: 80b00d2e2c121c4918bc95479f65c9054f5c5bb287d0da40b46a4200dc1f6d66170b227807373d41029119276378fff7fca6eaeae3cda959b3b609c698b4271d
ssdeep: 196608:vgmWa/hT5g3ceNwqe7+Ss26RKGGw2J92eYfHEpmLsWbAytIBBVP1nbQ3+j:vgGJhaTe7+qpGGwUnAEnPBfPGQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DAB633F22FF0F474D421117A3229723D2FEEBE2DAF5144A7A74B950D29360D884F91A6
sha3_384: bb64b135697c45515c3f32d084efe697f916113860530d2a7273dcd34334ad17161fe3bc4a907c28038a552ac87ec7ed
ep_bytes: 558bec6aff6870c4410068c095410064
timestamp: 2012-12-31 00:38:51

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.6.0.2712
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2012 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: December 30, 2012
ProductName: 7-Zip SFX
ProductVersion: 1.6.0.2712
Translation: 0x0000 0x04b0

BV:Miner-DG [Trj] also known as:

LionicTrojan.Win64.Miner.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanAdware.GenericKD.47067575
FireEyeAdware.GenericKD.47067575
McAfeeArtemis!2D0E00CFCBEA
CylanceUnsafe
SangforCoinMiner.Win64.Miner.anql
K7AntiVirusAdware ( 0057a9961 )
AlibabaTrojan:Win64/Miner.e86013ea
K7GWAdware ( 0057a9961 )
CyrenApplication.EAME
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win64.Miner.antc
BitDefenderAdware.GenericKD.47067575
AvastBV:Miner-DG [Trj]
TencentBat.Trojan.Coinminer.Hqvu
Ad-AwareAdware.GenericKD.47067575
TrendMicroCoinminer.BAT.MALXMR.TIAOODBV
McAfee-GW-EditionTrojan-NBMiner
EmsisoftAdware.GenericKD.47067575 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/CoinMiner.cxiwb
Antiy-AVLTrojan/Generic.ASSuf.2A440
KingsoftWin32.Troj.Win64.an.(kcloud)
GridinsoftRansom.Win32.Gen.sa
GDataWin64.Trojan.Agent.RNN6PT
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.Generic.C4198781
ALYacAdware.GenericKD.47067575
MAXmalware (ai score=68)
MalwarebytesRiskWare.BitCoinMiner
TrendMicro-HouseCallCoinminer.BAT.MALXMR.TIAOODBV
RisingTrojan.MalCert!1.D0A0 (CLASSIC)
YandexTrojan.Miner!rJS8vwTy5ME
FortinetW32/BtcMineNET.2!tr
AVGBV:Miner-DG [Trj]
Cybereasonmalicious.fcbeae
PandaTrj/CI.A

How to remove BV:Miner-DG [Trj]?

BV:Miner-DG [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment