Trojan

How to remove “Trojan.BitCoinMiner.BAT”?

Malware Removal

The Trojan.BitCoinMiner.BAT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.BitCoinMiner.BAT virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Spanish (Modern)
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • A cryptomining command was executed
  • Binary compilation timestomping detected
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan.BitCoinMiner.BAT?


File Info:

name: 96933C89CAB5962BEFB0.mlw
path: /opt/CAPEv2/storage/binaries/01f77ef32cd3ca8f250d7d4fc8263a619b479e0848e1585a34be0bd785cd6bee
crc32: E3BEB677
md5: 96933c89cab5962befb0d6c3b55756ff
sha1: 24f657ed561ad2f628c1a859fdaf4d6791ad0463
sha256: 01f77ef32cd3ca8f250d7d4fc8263a619b479e0848e1585a34be0bd785cd6bee
sha512: 37e5aee1e6dadffeb2618901cca4613ca292c1b2919ad1795a409bd591c4a5a25f8065d1eb25f2d62e9dc366b67183ccad2a71c44534a6954f50ff00d5d640d1
ssdeep: 3072:MOhX097+C1FyO5GWp1icKAArDZz4N9GhbkrNEkieiZPbz:BhE97+mLp0yN90QEfz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163F35C52A7E88132F9F72B7068FA02930E3ABCA19D78875E2745595E0C72A84D931737
sha3_384: 4854802bc53b66d854d39972710de1ff9970c6c10e0996dc6f5d5e303618a395a27a9bfab41da52d4bfdf3680b89c6e8
ep_bytes: e800070000e9000000006a5868687240
timestamp: 2068-06-21 06:07:02

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Archivo autoextractor de archivos CAB de Win32
FileVersion: 11.00.18362.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Todos los derechos reservados.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.18362.1
Translation: 0x0c0a 0x04b0

Trojan.BitCoinMiner.BAT also known as:

LionicTrojan.BAT.Miner.4!c
MicroWorld-eScanApplication.Generic.3080552
FireEyeGeneric.mg.96933c89cab5962b
ALYacApplication.Generic.3080552
MalwarebytesTrojan.BitCoinMiner.BAT
K7AntiVirusTrojan ( 00581e2f1 )
AlibabaTrojan:BAT/Miner.3060696b
K7GWTrojan ( 00581e2f1 )
Cybereasonmalicious.d561ad
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/CoinMiner.ATM
BitDefenderApplication.Generic.3080552
Ad-AwareApplication.Generic.3080552
EmsisoftApplication.Generic.3080552 (B)
SophosMal/Generic-S
AviraTR/CoinMiner.lnjee
GridinsoftRansom.Win32.Gen.sa
GDataBAT.Trojan.Agent.1DYVF1
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R452918
MAXmalware (ai score=77)
TencentBat.Trojan.Miner.Hufj
FortinetAdware/Miner

How to remove Trojan.BitCoinMiner.BAT?

Trojan.BitCoinMiner.BAT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment