Trojan

What is “Trojan-PSW.Win32.Coins.knb”?

Malware Removal

The Trojan-PSW.Win32.Coins.knb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Coins.knb virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-PSW.Win32.Coins.knb?


File Info:

crc32: 983ACF5A
md5: 184683db0a11d4195cf383c2222eeeb4
name: 184683DB0A11D4195CF383C2222EEEB4.mlw
sha1: 13b6e2f1dfcad8a76a5472b4eb0f2b8b49a095eb
sha256: a8b3a1ae60fbe866b586929a082b49957d78b6c5e74d700af1f1937641c55fc9
sha512: b9877aedec08998810c9c2d3b4dd46aa1bc8776f28f6ef025e6a391ba7d0f68e98583cb48fca1be1efea2e16175a79d9aafd69599740a99eab485dada956967a
ssdeep: 3072:Sfmu9XvCQ1Qfl6h+m0cP8aUM7/2Z/pxe7ZadcCE2g8TGy/WsNhde:nu5vCQ1TIcMxegdcz58SSRVe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: dfogdofgb.exe
FileVersion: 1.0.0.2
Translation: 0x0809 0x04b0

Trojan-PSW.Win32.Coins.knb also known as:

K7AntiVirusTrojan ( 0053c86a1 )
DrWebTrojan.Encoder.3953
MicroWorld-eScanTrojan.GenericKDZ.47309
ALYacTrojan.GenericKDZ.47309
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/Coins.86315709
K7GWTrojan ( 0053c86a1 )
Cybereasonmalicious.b0a11d
CyrenW32/GandCrab.Z.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKUD
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Coins.knb
BitDefenderTrojan.GenericKDZ.47309
NANO-AntivirusTrojan.Win32.Coins.fhysfb
ViRobotTrojan.Win32.U.GandCrab.172544
TencentWin32.Trojan-qqpass.Qqrob.Dxna
Ad-AwareTrojan.GenericKDZ.47309
SophosMal/Generic-R + Mal/GandCrab-B
ComodoTrojWare.Win32.TrojanSpy.Ursnif.EM@7vyz23
BitDefenderThetaGen:NN.ZexaF.34722.ku0@ay2hTJiG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Emotet.cc
FireEyeGeneric.mg.184683db0a11d419
EmsisoftTrojan.GenericKDZ.47309 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.GandCrypt.ms
AviraHEUR/AGEN.1106537
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.2813ABC
AegisLabTrojan.Win32.Coins.4!c
ZoneAlarmTrojan-PSW.Win32.Coins.knb
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Win-Trojan/MalPe36.Suspicious.X2037
Acronissuspicious
McAfeePacked-FLX!184683DB0A11
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesRansom.GandCrab
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_HPGen-50
RisingTrojan.Generic@ML.100 (RDML:3mVctX4HSduFIXcIoOSluQ)
YandexTrojan.GenAsa!jWMnuIRmV+k
IkarusTrojan.Win32.Ranumbot
FortinetW32/Kryptik.GMSM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Trojan-PSW.Win32.Coins.knb?

Trojan-PSW.Win32.Coins.knb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment