Trojan

Trojan-PSW.Win32.Coins.vsp removal

Malware Removal

The Trojan-PSW.Win32.Coins.vsp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Coins.vsp virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: intervpnmix.exe
  • Writes a potential ransom message to disk
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

iplogger.org
jjload02.top

How to determine Trojan-PSW.Win32.Coins.vsp?


File Info:

crc32: 5CB3B598
md5: 9a87572577ca9d36b89eea4a862a6ecb
name: intervpnmix.exe
sha1: e013acf3caff81783a77175b7f0e6e3db6d89b18
sha256: 3d3e5fad70ad50dc885615892bd7f888c1a570f667897a452b954270af8e7595
sha512: d43cbfc666901644ddecc3db3f523c75cbb23daf14ed5227b7002b4a686fc079be9b256a49944df8abd390a28c7e9e40bf1d81e0bf7cd138c2cdf4443dda67f9
ssdeep: 196608:J5G3oFXzSHflKvlz/1tcko57xBTJu7sbsngqmsuvVZ218tnSmgU:JA3oFXzGflK9z17stlyqVMghgU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Inter VPN SOFT Inc.
ProductVersion: 2.2.3.0
FileVersion: 2.2.3.0
FileDescription:
Translation: 0x0000 0x04b0

Trojan-PSW.Win32.Coins.vsp also known as:

DrWebTrojan.DownLoad4.13651
MicroWorld-eScanTrojan.GenericKD.33549440
FireEyeGeneric.mg.9a87572577ca9d36
McAfeeArtemis!9A87572577CA
CylanceUnsafe
AegisLabTrojan.Win32.Stralo.a!c
SangforMalware
K7AntiVirusTrojan ( 00559ab31 )
BitDefenderTrojan.GenericKD.33549440
K7GWTrojan ( 00559ab31 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Stralo-7590910-0
GDataWin32.Trojan.Ilgergop.XVJ55Y
KasperskyTrojan-PSW.Win32.Coins.vsp
AlibabaTrojanPSW:Win32/Coins.7f56c76d
ViRobotTrojan.Win32.Z.Wacatac.8905310
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.33549440 (B)
F-SecureHeuristic.HEUR/AGEN.1038489
ZillyaTrojan.GenericKD.Win32.30057
TrendMicroTROJ_GEN.R01FC0WCI20
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Autohk
CyrenW32/Trojan.XHAK-2652
AviraTR/RedCap.asnil
MAXmalware (ai score=100)
ArcabitTrojan.Generic.D1FFEC80
ZoneAlarmHEUR:Trojan-Downloader.Win32.Stralo.gen
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
ALYacTrojan.GenericKD.33549440
VBA32TrojanDownloader.Stralo
MalwarebytesTrojan.Downloader.AHK.Themida
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Packed.Themida.GZV
TrendMicro-HouseCallTROJ_GEN.R01FC0WCI20
RisingTrojan.Generic@ML.99 (RDML:ZYtkDSns+FvMdi6uMcZn1A)
YandexRiskware.Unwanted!
eGambitUnsafe.AI_Score_99%
FortinetW32/Stralo!tr.dldr
Ad-AwareTrojan.GenericKD.33549440
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.PSW.3c2

How to remove Trojan-PSW.Win32.Coins.vsp?

Trojan-PSW.Win32.Coins.vsp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment