Malware

MSIL/MultiMiner.B potentially unsafe malicious file

Malware Removal

The MSIL/MultiMiner.B potentially unsafe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MSIL/MultiMiner.B potentially unsafe virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (15 unique times)
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

www.bing.com
assets.onestore.ms
statics-marketingsites-wcus-ms-com.akamaized.net
ajax.aspnetcdn.com
mem.gfx.ms
az725175.vo.msecnd.net
ocsp.digicert.com
img-prod-cms-rt-microsoft-com.akamaized.net

How to determine MSIL/MultiMiner.B potentially unsafe?


File Info:

crc32: 36F59EFA
md5: 86f318bfbf48180956c1d65411a198ce
name: MultiMiner-4.3.1.exe
sha1: 5e7fb4e859f37a0a76a9f0687346f7a169eb4cd6
sha256: 605003d50ab9468473ab3a24c6462be3cf02a5bb83e23cd6d7ed8238dd2ccb69
sha512: 82b8df6ab46dde277a04740440cfa82dbb157444ba6fb61924ec2bb6870ecfe8264ff1f8aba37e7fa3ad1647c8c591a868a77369f1b3da0dd084ae4a5ae68c8c
ssdeep: 24576:z7bliCVmyAss1dqKzALBoJZ3sS0lS6xf67aRq8Imj4Y3:z75P19suKULE8St6xi+sm8Y3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName: Nate Woolls
Comments: This installation was built with Inno Setup.
ProductName: MultiMiner
ProductVersion: 4.3.1
FileDescription: MultiMiner Setup
Translation: 0x0000 0x04b0

MSIL/MultiMiner.B potentially unsafe also known as:

MicroWorld-eScanTrojan.GenericKD.43100723
FireEyeTrojan.GenericKD.43100723
McAfeeArtemis!86F318BFBF48
CylanceUnsafe
SangforMalware
BitDefenderTrojan.GenericKD.43100723
K7GWUnwanted-Program ( 004bf75d1 )
K7AntiVirusUnwanted-Program ( 004bf75d1 )
SymantecTrojan.Gen.2
ESET-NOD32a variant of MSIL/MultiMiner.B potentially unsafe
APEXMalicious
Paloaltogeneric.ml
GDataMSIL.Application.CoinMiner.V@gen (4x)
KasperskyTrojan.Win32.CoinMiner.amhj
AlibabaTrojan:Win32/CoinMiner.6d9f2634
NANO-AntivirusTrojan.Win32.CoinMiner.hliowy
RisingTrojan.Detplock!8.4A0D (CLOUD)
SophosMultiMiner (PUA)
ComodoMalware@#1f5ljulu8t86r
F-SecurePotentialRisk.PUA/CoinMiner.Gen
ZillyaTrojan.CoinMiner.Win32.25273
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.43100723 (B)
CyrenW32/Application.ZQSG-0937
WebrootW32.Trojan.Miner
AviraappMultiMiner.Win.exe
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Detplock
MicrosoftTrojan:Win32/Occamy.C60
ArcabitTrojan.Generic.D291AA33
SUPERAntiSpywareHack.Tool/Gen-BitCoinMiner
ZoneAlarmTrojan.Win32.CoinMiner.amhj
CynetMalicious (score: 85)
VBA32Trojan.CoinMiner
ALYacTrojan.GenericKD.43100723
Ad-AwareTrojan.GenericKD.43100723
PandaTrj/CI.A
TencentWin32.Trojan.Coinminer.Ednv
FortinetRiskware/MultiMiner
AVGWin32:MultiMiner-E [Miner]
Cybereasonmalicious.859f37
AvastWin32:MultiMiner-E [Miner]
Qihoo-360Win32/Trojan.ebe

How to remove MSIL/MultiMiner.B potentially unsafe?

MSIL/MultiMiner.B potentially unsafe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment