Trojan

Trojan.CoinminerRI.S13812980 removal instruction

Malware Removal

The Trojan.CoinminerRI.S13812980 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.CoinminerRI.S13812980 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Trojan.CoinminerRI.S13812980?


File Info:

crc32: DF69E792
md5: 4576444646a449e267fdf76dffdead3c
name: 4576444646A449E267FDF76DFFDEAD3C.mlw
sha1: 6447c1e799b492f822b24d086160ba6d31627b9b
sha256: ba56dfa1f60dab22f8a7c3a1abe8d06c7e9b17757b379cbcf30e21ec7e15ccc1
sha512: 8e93fbfdc3ae5d650afe68dfaa38e46ce63c9b90622c9bf56cf5caa95d9b0d8bbc03cbe18c62266b01e3d1b6b7431e5796b27fadd26a269dfe3678e6909f31eb
ssdeep: 24576:wLFQaDwryBkjnYOvsltwui2pJInhUD5oQnWNwpR9lWPsjV7:+TkWBQTslzvD5ZnDXGY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.CoinminerRI.S13812980 also known as:

BkavW32.SagonaireNTB.Trojan
K7AntiVirusTrojan ( 0052b9d31 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.BtcMine.3457
CynetMalicious (score: 100)
CAT-QuickHealTrojan.CoinminerRI.S13812980
ALYacGen:Heur.Mint.Zard.25
CylanceUnsafe
ZillyaTrojan.CoinMiner.Win32.24406
SangforMiner.Win32.Mint_46.se2
AlibabaTrojan:Win32/CoinMiner.e683d0b3
K7GWTrojan ( 0052b9d31 )
Cybereasonmalicious.646a44
CyrenW32/S-e12d2ca0!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.BEX
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
ClamAVWin.Trojan.Coinminer-9873260-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Mint.Zard.25
NANO-AntivirusTrojan.Win32.CoinMiner.gkomzp
MicroWorld-eScanGen:Heur.Mint.Zard.25
TencentMalware.Win32.Gencirc.10b80147
Ad-AwareGen:Heur.Mint.Zard.25
SophosMal/Generic-S
ComodoApplication.Win32.CoinMiner.BEX@7pt9re
BitDefenderThetaAI:Packer.005436841D
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.4576444646a449e2
EmsisoftGen:Heur.Mint.Zard.25 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ejbst
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2D37230
MicrosoftTrojan:Win32/CoinMiner.BW!bit
GDataGen:Heur.Mint.Zard.25
TACHYONTrojan/W32.Agent.1565696.YM
AhnLab-V3Win-Trojan/Malpacked3.Gen
Acronissuspicious
McAfeeGenericRXNE-HV!4576444646A4
MAXmalware (ai score=89)
VBA32BScope.Trojan.BtcMine
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/Genetic.gen
RisingTrojan.CoinMiner!1.C747 (CLASSIC)
YandexTrojan.GenAsa!bNe2xAxJt+s
IkarusTrojan.Win32.CoinMiner
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Generic
AVGWin32:CoinminerX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan.CoinminerRI.S13812980?

Trojan.CoinminerRI.S13812980 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment