Trojan

About “Trojan-PSW.Win32.Coins.vca” infection

Malware Removal

The Trojan-PSW.Win32.Coins.vca is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Coins.vca virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: vpnpro.exe
  • Writes a potential ransom message to disk
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

iplogger.org
bitbucket.org

How to determine Trojan-PSW.Win32.Coins.vca?


File Info:

crc32: 523A0156
md5: bd63da250077fe1ad9f7ce2ef86b91b9
name: intervpnmix3.exe
sha1: 38a3c8d6f5f941389fa4ce0a16cdc1afb795a886
sha256: ddc46c30f029cdb6d332811afadae0a06ca646bde9cad4345bb0b5eb75e87548
sha512: b8e25ecbb179c6b0eaf6dac4e230e357cafa9479f8137d9c03dd6be6064fa9a90df01e5e362067fd9719b7cc688653acc400fe85813213df76dec94d425ab1b6
ssdeep: 196608:f5G3oFXzSHflKvlz/1tcko57xBTJu7sbsSFQI/cDJ2Gn+WDx8tnSmgd:fA3oFXzGflK9z17stllGlMGn+Aghgd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: inter ltd.
ProductVersion: 1.88.0.0
FileVersion: 1.88.0.0
FileDescription:
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Coins.vca also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.42338156
Qihoo-360Win32/Trojan.PSW.69c
McAfeeArtemis!BD63DA250077
CylanceUnsafe
K7AntiVirusTrojan ( 0055bc301 )
BitDefenderTrojan.GenericKD.42338156
SymantecML.Attribute.HighConfidence
GDataWin32.Trojan.Ilgergop.T7N6JV
KasperskyTrojan-PSW.Win32.Coins.vca
AlibabaPacked:Win32/Themida.195f7128
APEXMalicious
RisingTrojan.Generic@ML.99 (RDML:KrQHbAemxQfND8W6o/D/zQ)
Ad-AwareTrojan.GenericKD.42338156
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1038489
DrWebProgram.Unwanted.2892
ZillyaTrojan.GenericKD.Win32.30057
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeTrojan.GenericKD.42338156
EmsisoftTrojan.GenericKD.42338156 (B)
AviraTR/AD.AHKInfoSteal.nwhir
MAXmalware (ai score=82)
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D286076C
ZoneAlarmTrojan-PSW.Win32.Coins.vca
MicrosoftTrojan:Win32/Occamy.C
MalwarebytesTrojan.Downloader.AHK.Themida
ESET-NOD32a variant of Win32/Packed.Themida.HFL
IkarusTrojan-Downloader.Win32.Autohk
eGambitUnsafe.AI_Score_99%
FortinetW32/PossibleThreat
AVGFileRepMalware

How to remove Trojan-PSW.Win32.Coins.vca?

Trojan-PSW.Win32.Coins.vca removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment