Trojan

Trojan-PSW.Win32.Coins.vnw information

Malware Removal

The Trojan-PSW.Win32.Coins.vnw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Coins.vnw virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • The following process appear to have been packed with Themida: 3.exe
  • Attempts to identify installed AV products by installation directory
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

ip-api.com

How to determine Trojan-PSW.Win32.Coins.vnw?


File Info:

crc32: 469C2A19
md5: 574cba6310b956d370db9354e706676f
name: 3.exe
sha1: dbb409351c46478816f8cc09ffe1c0a823fec346
sha256: fd35af05084d47f5522d58b8f73c6da59a1ccb7b29e18532faf049a11b7d3996
sha512: c0d85dd47476e2a0a23a8e0e0b3ee7997e05e7ad6b0fd28745faae09133003cdc79a35bf32c215b41456519e9263fa598ca1fa548ad415fe34b19a0b8ff2b119
ssdeep: 49152:2SQZ81HZiIhaLK102iOmoafmuHrzmrazhHWZAk3E:2SQIH8YSdfmuHrzmr4h2X
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-PSW.Win32.Coins.vnw also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanTrojan.GenericKD.33441248
FireEyeGeneric.mg.574cba6310b956d3
Qihoo-360Generic/Trojan.PSW.c3c
McAfeeArtemis!574CBA6310B9
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 0040f4ef1 )
BitDefenderTrojan.GenericKD.33441248
K7GWTrojan ( 0040f4ef1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_FRS.VSNTBR20
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
GDataTrojan.GenericKD.33441248
KasperskyTrojan-PSW.Win32.Coins.vnw
AlibabaTrojanPSW:Win32/Coins.501771b4
NANO-AntivirusTrojan.Win32.Coins.hcpslr
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareTrojan.GenericKD.33441248
SophosMal/Generic-S
ComodoMalware@#7ck6z7wiynil
F-SecureTrojan.TR/PSW.Coins.rrfdc
DrWebTrojan.Siggen9.15979
ZillyaTrojan.Coins.Win32.3811
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Backdoor.vc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.33441248 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.QGDJ-0278
WebrootW32.Malware.Gen
AviraTR/PSW.Coins.rrfdc
Antiy-AVLTrojan[PSW]/Win32.Coins
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1FE45E0
ZoneAlarmTrojan-PSW.Win32.Coins.vnw
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34096.aAWaaC7ELUli
ALYacTrojan.GenericKD.33394316
MAXmalware (ai score=84)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesSpyware.CryptBot
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.HIQ
TrendMicro-HouseCallTROJ_FRS.VSNTBR20
TencentWin32.Trojan-qqpass.Qqrob.Suxw
YandexTrojan.Themida!
IkarusTrojan.Win32.Themida
eGambitUnsafe.AI_Score_100%
FortinetW32/Themida.HIO!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.51c464
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-PSW.Win32.Coins.vnw?

Trojan-PSW.Win32.Coins.vnw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment